I have just re-discovered this article by Marcus Ranum - long time security guru and developer of one of the world's first network firewalls.
I see similar issues all the time in the course of my work - there is frequently not time or budget to do a thorough job of securing a system but often both are needed to fix it downstream. There is one customer of mine who pulled an application release shortly before go live day after we looked at the risks they would be exposed to. It will be deployed but in a different framework and with only strictly required network connectivity.
Sunday, July 6. 2008
Heavy weather
I love the seasons as they go by.
The weather in Wellington over the last 24 hours has been pretty wintery. Went out last night and the temperature was down to 3C before 7pm and it was raining quite heavily. By the time we were on our way home about 1.30am it had warmed up to 8 degrees and was blowing a strong gale. My weather station reported 23 knots in its somewhat sheltered position - I believe the winds were over 60knots in places. The wind continued until mid-afternoon today.
Jo and I went for a walk down to Island Bay and watched the big swells rolling in from the south. I heard that they had been up to 10 metres in Cook Strait but the Wellington marine forecast was talking about 4 metres. There was a bit of snow on the Orongorongos and ferries were cancelled overnight.
The weather in Wellington over the last 24 hours has been pretty wintery. Went out last night and the temperature was down to 3C before 7pm and it was raining quite heavily. By the time we were on our way home about 1.30am it had warmed up to 8 degrees and was blowing a strong gale. My weather station reported 23 knots in its somewhat sheltered position - I believe the winds were over 60knots in places. The wind continued until mid-afternoon today.
Jo and I went for a walk down to Island Bay and watched the big swells rolling in from the south. I heard that they had been up to 10 metres in Cook Strait but the Wellington marine forecast was talking about 4 metres. There was a bit of snow on the Orongorongos and ferries were cancelled overnight.
Saturday, July 5. 2008
Mountain biking in Bolivia
Well Dave and Anna have been in La Paz, Bolivia for about 5 months now and are loving it. Dave gets to guide keen tourists down the "world's most dangerous road" 3-4 days a week. He is working for Gravity Assisted Mountain bike Tours. On days off he and other guides seem to be keen to do even more biking or get out partying if there is a local fiesta on.
Anna was working in the Gravity office for a bit but found a much better role working with the animals in an animal sanctuary near the bottom of 'the road'. They see each other when Dave makes it down the road with tour groups and at weekends.

Take a look over their blog with photos, stories etc.
Anna was working in the Gravity office for a bit but found a much better role working with the animals in an animal sanctuary near the bottom of 'the road'. They see each other when Dave makes it down the road with tour groups and at weekends.
Take a look over their blog with photos, stories etc.
Friday, July 4. 2008
Another hacked biometric security system
Computerworld has this this article on how a researcher made a rubber fingerprint copy and made a retail purchase at a store trialling a new payment system. It's not a great recommendation.
Wednesday, July 2. 2008
Intrusion detection etc
Some years ago I was involved in the design of a managed security service. For a variety of reasons it was less successful than I (and the company) expected and it was a very hard sell to customers who couldn't see the point for the most part - or at least the cost-benefits.
I just found this blog quoting some really interesting research pointing out the time that most vulnerabilities exist before compromise, detection and mitigation, and showing where IDS and managed security services may still have a useful place.
I just found this blog quoting some really interesting research pointing out the time that most vulnerabilities exist before compromise, detection and mitigation, and showing where IDS and managed security services may still have a useful place.
(Page 1 of 1, totaling 5 entries)



