Tuesday, January 12, 2010

Security in the Swamp

I just read a great article published by MIT called “Security in the Ether”. You really should read it, too. This five page article has a lot of great information in it. In the “what’s in this for me” reason to read the article I was immediately captivated by this comment:
When thousands of different clients use the same hardware at large scale, which is the key to the efficiency that cloud computing provides, any breakdowns or hacks could prove devastating to many.
This means security is key. One breach and instead of a company being affected you have the potential for multiple companies to be affected. I remember a marketing focus group I did about federation a few years ago and one CIO said to me: “Are you kidding? I can’t trust my own end-users and their passwords when they access my systems let alone a federated system.” The cloud is simply going to magnify these problems – security or otherwise.

Monday, January 11, 2010

Common Criteria = Common Crock

The Common Criteria certification is a crock in my opinion. Same goes for FIPS and many other software certifications. I completely agree with Bruce Schneier's comment that "no one really understands what a certification means". (You can follow the original post and ensuing debate here: http://www.google.com/sidewiki/entry/jackson.shaw/id/phlOFw-lA4N3-4D29Irgve-yH_c)

These certifications are extremely costly. The ones I have been involved in end up exceeding $100,000 and the certification is valid only for that particular version. In this day and age most software companies are releasing new software versions every 6-8 months. I can't afford to re-certify for every major and minor release.

One of the benefits to software companies was that government agencies were supposedly required to only purchase Common Criteria or FIPS certified products. Guess what? They don't. They get around those requirements pretty easily with all kinds of excuses. So, why should a software company bother?

Sunday, January 10, 2010

Hello, Steve Riley!

Awesome to see the preeminent Steve Riley, ex-Microsoft security guru, over at Amazon working in the Amazon Web Services evangelism team.

Definitely a blog I will follow for Steve's insights into Federation, AWS, ADFS, etc. You should too!

in reference to: Amazon Web Services Blog: Hello, world! (view on Google Sidewiki)

Technorati Tags:
, , , , , ,




Friday, January 08, 2010

The (Craig) Burton Group

I owe a debt of gratitude to Craig Burton who founded The Burton Group. I really should say "we" owe a debt of gratitude to Craig because if it wasn't for Craig I'm not sure we'd be where we are today. The "we" is my old company Zoomit and all of my colleagues there, including Kim Cameron. I think I could even say the "we" is identity today because it's pretty hard to imagine being where we are today without Kim's contributions. (Kim is the chief architect of identity at Microsoft)

When we first developed Zoomit VIA - the world's first metadirectory product - Craig was especially influential but there was one decision he made for us that changed our direction forever. We first developed Zoomit VIA on Novell's UnixWare platform back in the late 1990's. However, not long after we finished development Novell sold off their UnixWare platform. We had sold Zoomit VIA to three customers before Novell made their announcement. While we were considering which Unix platform to move Zoomit VIA to next Craig simply stated: "The future is Windows. You need to move to the Microsoft platform." This was no easy decision back in 1998. And, as they say "the rest is history". Thanks for that one, Craig.

So in many ways I agree with what Craig's recent blog post. I'll be sorry to see The (Craig) Burton Group disappear. Craig, lots of people owe you thanks for your vision and efforts!

Technorati Tags:
, , , , ,