<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Security Pie &#187; Security Business</title>
	<atom:link href="http://securitypie.com/category/security-business/feed/" rel="self" type="application/rss+xml" />
	<link>http://securitypie.com</link>
	<description>The ramblings of three security curmudgeons</description>
	<lastBuildDate>Sun, 04 Jul 2010 07:31:59 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0</generator>
		<item>
		<title>Are We There Yet?</title>
		<link>http://securitypie.com/are-we-there-yet/</link>
		<comments>http://securitypie.com/are-we-there-yet/#comments</comments>
		<pubDate>Tue, 09 Feb 2010 23:59:48 +0000</pubDate>
		<dc:creator>sharon</dc:creator>
				<category><![CDATA[Risk Management]]></category>
		<category><![CDATA[Security Business]]></category>
		<category><![CDATA[Strategy]]></category>
		<category><![CDATA[theory]]></category>
		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://securitypie.com/?p=740</guid>
		<description><![CDATA[RSA Conference, the biggest security event of the year will take place next month. IMO now is a good time to review how we are doing as an industry, fulfilling our destination (that is, securing). On Jone 2003, Gartner declared that IDS are dead and &#8220;recommends that enterprises redirect the money they would have spent on IDS [...]]]></description>
			<content:encoded><![CDATA[<p>RSA Conference, the biggest security event of the year will take place next month.</p>
<p>IMO now is a good time to review how we are doing as an industry, fulfilling our destination (that is, securing).</p>
<p>On Jone 2003, Gartner declared that IDS are dead and &#8220;recommends that enterprises redirect the money they would have spent on IDS toward defense applications such as those offered by thought-leading firewall vendors that offer both network-level and application-level firewall capabilities in an integrated product.&#8221;</p>
<p>6.5  years later, are we there yet?</p>
]]></content:encoded>
			<wfw:commentRss>http://securitypie.com/are-we-there-yet/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Israel Information Technology Report Q4 2009</title>
		<link>http://securitypie.com/israel-information-technology-report-q4-2009/</link>
		<comments>http://securitypie.com/israel-information-technology-report-q4-2009/#comments</comments>
		<pubDate>Sun, 22 Nov 2009 08:23:11 +0000</pubDate>
		<dc:creator>sharon</dc:creator>
				<category><![CDATA[Security Business]]></category>
		<category><![CDATA[marketing]]></category>
		<category><![CDATA[IT]]></category>
		<category><![CDATA[STKI]]></category>

		<guid isPermaLink="false">http://securitypie.com/?p=673</guid>
		<description><![CDATA[I came across a document that was published few months ago describing Israel&#8217;s IT market in 2009.  I&#8217;ll let the readers decide if they accept the analysism but as a service I would like to point you to another source of information based on STKI&#8217;s summit presentation which is quite detailed. I&#8217;m interested to hear your feedback on opinion. STKI [...]]]></description>
			<content:encoded><![CDATA[<p>I came across a <a href="http://www.companiesandmarkets.com/Summary-Market-Report/israel-information-technology-report-q4-2009-169561.asp" target="_blank">document </a>that was published few months ago describing Israel&#8217;s IT market in 2009.  I&#8217;ll let the readers decide if they accept the analysism but as a service I would like to point you to another source of information based on STKI&#8217;s summit presentation which is quite detailed.</p>
<p>I&#8217;m interested to hear your feedback on opinion.</p>
<div id="__ss_1195498" style="width: 425px; text-align: left;"><a style="font:14px Helvetica,Arial,Sans-serif;display:block;margin:12px 0 3px 0;text-decoration:underline;" title="STKI Summit 2009 -Infrastructure Services Trends" href="http://www.slideshare.net/shaharmaor/stki-summit-2009-infrastructure-services-trends">STKI Summit 2009 -Infrastructure Services Trends</a><object style="margin:0px" classid="clsid:d27cdb6e-ae6d-11cf-96b8-444553540000" width="425" height="355" codebase="http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab#version=6,0,40,0"><param name="allowFullScreen" value="true" /><param name="allowScriptAccess" value="always" /><param name="src" value="http://static.slidesharecdn.com/swf/ssplayer2.swf?doc=infrastructureservices-summit2009-forpresentationv2-090325081107-phpapp02&amp;stripped_title=stki-summit-2009-infrastructure-services-trends" /><param name="allowfullscreen" value="true" /><embed style="margin:0px" type="application/x-shockwave-flash" width="425" height="355" src="http://static.slidesharecdn.com/swf/ssplayer2.swf?doc=infrastructureservices-summit2009-forpresentationv2-090325081107-phpapp02&amp;stripped_title=stki-summit-2009-infrastructure-services-trends" allowscriptaccess="always" allowfullscreen="true"></embed></object></p>
<div style="font-size: 11px; font-family: tahoma,arial; height: 26px; padding-top: 2px;">View more <a style="text-decoration:underline;" href="http://www.slideshare.net/">documents</a> from <a style="text-decoration:underline;" href="http://www.slideshare.net/shaharmaor">shaharmaor</a>.</div>
<div style="font-size: 11px; font-family: tahoma,arial; height: 26px; padding-top: 2px;"></div>
</div>
]]></content:encoded>
			<wfw:commentRss>http://securitypie.com/israel-information-technology-report-q4-2009/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>No Recovery Without Entrepreneurs&#8217; Help?</title>
		<link>http://securitypie.com/no-recovery-without-entrepreneurs-help/</link>
		<comments>http://securitypie.com/no-recovery-without-entrepreneurs-help/#comments</comments>
		<pubDate>Thu, 15 Oct 2009 06:18:26 +0000</pubDate>
		<dc:creator>sharon</dc:creator>
				<category><![CDATA[Security Business]]></category>
		<category><![CDATA[entrepreneurs]]></category>
		<category><![CDATA[H1]]></category>
		<category><![CDATA[redtape]]></category>

		<guid isPermaLink="false">http://securitypie.com/?p=641</guid>
		<description><![CDATA[According to HBP statistics, quoting the Kauffman Foundation, entrepreneurs have been key drivers of economic recovery in past recessions. In fact, since 1980, companies less than five years old have accounted for virtually all net new-job creation in the U.S. Considering myself as an entrepreneur I read the Entrepreneurs&#8217; Gloom Contradicts Wall Street Optimism. The Foundation&#8217;s [...]]]></description>
			<content:encoded><![CDATA[<p>According to <a href="http://harvardbusiness.org/?cm_mmc=npv-_-DAILY_STAT-_-OCT_2009-_-STAT1014" target="_blank">HBP </a>statistics, quoting the Kauffman Foundation, entrepreneurs have been key drivers of economic recovery in past recessions. In fact, since 1980, companies less than five years old have accounted for virtually all net new-job creation in the U.S.</p>
<p>Considering myself as an entrepreneur I read the <a href="http://www.kauffman.org/newsroom/entrepreneurs-gloom-contradicts-wall-street-optimism.aspx" target="_blank">Entrepreneurs&#8217; Gloom Contradicts Wall Street Optimism</a>.</p>
<p>The Foundation&#8217;s September 2009 study of more than 400 entrepreneurs and would-be entrepreneurs shows that 75% think the United States cannot have a sustained economic recovery without another burst of entrepreneurial activity.</p>
<p>Duh. Isn&#8217;t that clear? Elementary&#8230;</p>
<p>The following statistic tidbit got my attention:</p>
<blockquote><p>75 percent think the United States cannot have a sustained economic recovery without another burst of entrepreneurial activity.</p></blockquote>
<p>Duh. Isn&#8217;t that clear? Elementary&#8230;</p>
<p>Reading the survey summary  (<a href="http://www.kauffman.org/uploadedFiles/entrepreneurs_survey_results_9-22-09.pdf" target="_blank">pdf</a>) the following slide was not surprising:</p>
<div id="attachment_642" class="wp-caption aligncenter" style="width: 310px"><img class="size-medium wp-image-642" title="Kauffman Foundation Survey of Entrepreneurs" src="http://securitypie.com/wp-content/uploads/2009/10/Kauffman-Foundation-Survey-of-Entrepreneurs-300x159.png" alt="The US is not doing enough" width="300" height="159" /><p class="wp-caption-text">The US is not doing enough</p></div>
<p>I found out that many successful, talented entrepreneur that are currently in the US with  H1 visa are unable to start a business in the US, even if they willing to go through this difficult process.</p>
<p>The vast majority of entrepreneurs think it should be easier to start a business:</p>
<div id="attachment_645" class="wp-caption aligncenter" style="width: 310px"><img class="size-medium wp-image-645" title="Kauffman Foundation Survey of Entrepreneurs - starting a business in the US" src="http://securitypie.com/wp-content/uploads/2009/10/Kauffman-Foundation-Survey-of-Entrepreneurs-starting-a-business-in-the-US-300x207.png" alt="Starting a business in the US" width="300" height="207" /><p class="wp-caption-text">Starting a business in the US</p></div>
<p>For many entrepreneurs, starting a business in THE US, is NOT an option. You don&#8217;t need a <a href="http://www.marketwatch.com/story/obama-fails-to-win-nobel-prize-in-economics-2009-10-12" target="_blank">Nobel Prize in economy</a> to understand why the US economy need to make it easier to H1 visa holders to start a business in the US and help boost economy.</p>
]]></content:encoded>
			<wfw:commentRss>http://securitypie.com/no-recovery-without-entrepreneurs-help/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>Ending The Drought</title>
		<link>http://securitypie.com/ending-the-drought/</link>
		<comments>http://securitypie.com/ending-the-drought/#comments</comments>
		<pubDate>Tue, 11 Aug 2009 08:36:54 +0000</pubDate>
		<dc:creator>sharon</dc:creator>
				<category><![CDATA[Security Business]]></category>
		<category><![CDATA[fortinet]]></category>
		<category><![CDATA[IPO]]></category>

		<guid isPermaLink="false">http://securitypie.com/?p=596</guid>
		<description><![CDATA[So the good news arrives from Sunnyvale CA: Fortinet, Inc., a provider of network security appliances and unified threat management (UTM) solutions, announced that it has filed a registration statement on Form S-1 with the Securities and Exchange Commission relating to a proposed initial public offering of its common stock. This is great news. For [...]]]></description>
			<content:encoded><![CDATA[<div id="attachment_597" class="wp-caption alignleft" style="width: 310px"><img class="size-medium wp-image-597" title="ending the Drought with fortinet IPO" src="http://securitypie.com/wp-content/uploads/2009/08/ending-the-Drought-with-fortinet-IPO-300x199.jpg" alt="Fortinet will end the Drought " width="300" height="199" /><p class="wp-caption-text">Fortinet will end the Drought </p></div>
<p>So the good news arrives from Sunnyvale CA:<a href="http://www.fortinet.com/" target="_blank"> Fortinet, Inc</a>., a provider of network security appliances and unified threat management (UTM) solutions, <a href="http://www.fortinet.com/press_releases/090810.html" target="_blank">announced </a>that it has filed a registration statement on Form S-1 with the Securities and Exchange Commission relating to a proposed initial public offering of its common stock.</p>
<p>This is great news. For our <a href="http://www.fortinet.com/aboutus/management.html" target="_blank">friends </a>working at Fortinet, partners, security vars, <a href="http://www.meritechcapital.com/" target="_blank">VC </a>and anyone who cares about the economy and of course security.</p>
<p>Fortinet is a profitable security vendor. The IPO filling is very encouraging as it represents the first US venture-backed company to submit an IPO filing in more than six months.</p>
<p>I believe that Fortinet&#8217;s S-1 filing represents the start of quality security companies IPO filings wave in the coming months which is extremely important in order  to improve the overall sentiment for security companies. I believe that since Websense (<a href="http://www.google.com/finance?client=ob&amp;q=NASDAQ:WBSN" target="_blank">WBSN</a>) <a href="http://investor.websense.com/releasedetail.cfm?ReleaseID=285065" target="_blank">acquisition </a>of PortAuthority Technologies, our industry financiers (ok, the Venture Capitalists) did not see a good return on their investment&#8230;</p>
<p>Go get em&#8217;</p>
]]></content:encoded>
			<wfw:commentRss>http://securitypie.com/ending-the-drought/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Small is The New Big</title>
		<link>http://securitypie.com/small-is-the-new-big/</link>
		<comments>http://securitypie.com/small-is-the-new-big/#comments</comments>
		<pubDate>Wed, 27 May 2009 09:02:36 +0000</pubDate>
		<dc:creator>sharon</dc:creator>
				<category><![CDATA[Security Business]]></category>
		<category><![CDATA[sales]]></category>
		<category><![CDATA[passlogix]]></category>
		<category><![CDATA[trust]]></category>

		<guid isPermaLink="false">http://securitypie.com/?p=527</guid>
		<description><![CDATA[My friend Zvika (all names are fictional to protect the innocent) drew my attention to Peter Bregman post on Harvard Business blog Why Small Companies Will Win in This Economy. Peter is the CEO of Bregman Partners, Inc., a global management consulting firm, and advises CEOs and their leadership teams. My friend Zvika is an executive in a [...]]]></description>
			<content:encoded><![CDATA[<p><span>My friend Zvika (all names are fictional to protect the innocent) drew my attention to Peter Bregman post on Harvard Business blog <a href="http://blogs.harvardbusiness.org/bregman/2009/03/why-small-companies-will-win-i.html" target="_blank">Why Small Companies Will Win in This Econom</a>y. Peter is the CEO of Bregman Partners, Inc., a global management consulting firm, and advises CEOs and their leadership teams. My friend Zvika is an executive in a small company and knows one or two things about selling &#8220;against the big guys&#8221;.</span></p>
<p><span>I read this article and find it to be interesting for multiple reasons:</span></p>
<ol type="1">
<li class="MsoNormal"><span>Peter      tells a nice story about<span> </span><a href="http://www.passlogix.com/" target="_blank">Passlogix</a>. I like stories. </span></li>
<li class="MsoNormal"><span>I      second Peter&#8217;s thoughts. Customers buy from someone they trust. It does not      matter if you work in a big company or a small company. In order to sell,      you should gain your customers trust.</span></li>
<li class="MsoNormal">I was amused that Peter found the mentioned phenomenon interesting. </li>
</ol>
<p> </p>
<p><span><span>Did you ever think why customers buy? why do YOU buy? I always find it awkward when I hear experts talk<span> </span><span><strike>teach</strike></span><span> </span></span>about the art (or science) of selling, but they do not teach why customers buy.  IMO, a customer or a prospect will trust their sales rep if he and the company that he represents are professional, reliable, accurate and will be there when needed. Day or night.  Sun or rain. </span></p>
<p> </p>
<p><span>Many years ago, when I sold our<span> </span><span><strong><strong>first</strong></strong></span><span><strong> </strong></span></span>major (at the time) project, I looked at my prospect eyes and told him something along the following lines:</p>
<blockquote><p> Believe me&#8230; we know what we are doing, you are not the second or third customer for this kind of project</p></blockquote>
<p>He knew that he was the first, but he trusted us..</p>
<p><span> <a href="http://www.passlogix.com/company/executivebios/" target="_blank">Marc Boroditsky is the president, CEO and a co-founder of Passlogi</a>x . He is passionate about his company and will always answer the phone. Companies should have passionate executives at all levels. I wish Mr. Boroditsky (I do not know him) all the best. Such success stories make my day. Learning from my own experience, one day he could not answer the phone for every customer. But then, he must have other executives with the same level of passion that will.</span></p>
<p><span> </span></p>
<p><span>Assaf  adds:  He concludes with “small is the new big”. Maybe the correct line is “Big is the new small?”.</span></p>
]]></content:encoded>
			<wfw:commentRss>http://securitypie.com/small-is-the-new-big/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Slicing The Security Pie</title>
		<link>http://securitypie.com/slicing-the-security-pie/</link>
		<comments>http://securitypie.com/slicing-the-security-pie/#comments</comments>
		<pubDate>Wed, 19 Nov 2008 20:04:22 +0000</pubDate>
		<dc:creator>sharon</dc:creator>
				<category><![CDATA[Security Business]]></category>
		<category><![CDATA[cisco]]></category>
		<category><![CDATA[ipso]]></category>
		<category><![CDATA[nokia]]></category>

		<guid isPermaLink="false">http://securitypie.com/?p=294</guid>
		<description><![CDATA[    Network World published an interesting story about Cisco’s attempts to keep the number 1 spot in sales of network security gear. (note that I emphasise the words sales). The article includes several security pies, the kind I like. it also include an analysis of best of breed versus good enough sales. In my opinion the article [...]]]></description>
			<content:encoded><![CDATA[<p> </p>
<p class="MsoNormal"> </p>
<div id="attachment_296" class="wp-caption alignleft" style="width: 221px"><a href="http://securitypie.com/wp-content/uploads/2008/11/network-security-leaders.png"><img class="size-medium wp-image-296" title="network-security-leaders" src="http://securitypie.com/wp-content/uploads/2008/11/network-security-leaders-211x300.png" alt="Cisco is #1 in appliance sales" width="211" height="300" /></a><p class="wp-caption-text">Cisco is #1 in appliance sales</p></div>
<p>Network World<span> </span>published an <a href="http://www.networkworld.com/news/2008/111708-cisco-sec.html?nlhtsec=ts_111808&amp;nladname=111808securityal" target="_blank">interesting story</a> about Cisco’s attempts to keep the number 1 spot in sales of network security gear. (note that I emphasise the words sales).</p>
<p>The article includes several security pies, the kind I like. it also include an analysis of best of breed versus good enough sales.</p>
<p>In my opinion the article is missing one important factors: The departure of Nokia from the network security appliance market.</p>
<p>Cisco is indeed the undisputed leader in sales for the security appliances market. It’s retired PIX firewall was all times best seller. People simply liked the way it worked. The more recent acquisition of IronPort gave it a powerful weapon in the e-mail security market and it also allows Cisco to claim some DLP capabilities. Cisco is also #1 in sales of IPS gear. Take a look at the left pie. While there&#8217;s a huge market share belongs to the &#8220;other&#8221; vendors, Cisco&#8217;s slice is bigger than the combined slices of Juniper, Check Point, Nokia and Microsoft!</p>
<p> </p>
<p>The other pies show how Cisco rules the network security market (again, in sales).  While the article does not mention emerging market it focus on the main.</p>
<p> </p>
<p class="MsoNormal"> </p>
<div id="attachment_295" class="wp-caption aligncenter" style="width: 310px"><a href="http://securitypie.com/wp-content/uploads/2008/11/the-security-pie.png"><img class="size-medium wp-image-295" title="the-security-pie" src="http://securitypie.com/wp-content/uploads/2008/11/the-security-pie-300x101.png" alt="The Security Pie" width="300" height="101" /></a><p class="wp-caption-text">The Security Pie</p></div>
<p> </p>
<p> </p>
<p class="MsoNormal"><span id="more-294"></span></p>
<p class="MsoNormal">The pies that were provided by Network world also include large slices for Nokia and it also list Check Point. In my opinion, part of the reason Check Point has maintained its marketplace position was Nokia, more specifically , the Nokia appliances. While Check Point partners with other appliance makers, such as Crossbeam Systems, Nokia systems (which used to come from the successful Ipsilon Networks acquisition) was always favored (it probably <span style="text-decoration: line-through;">requires </span>deserves a separate post on how to build appliances).</p>
<p class="MsoNormal">In my opinion, the pie will be changed: On 29 September 2008, the mobile communications provider Nokia <a href="http://www.reuters.com/article/mergersNews/idUSLT54500020080929" target="_blank">announced</a> that it is negotiating to sell its network security appliance business unit to an unnamed financial investment firm. The plan is part of an overall Nokia move away from enterprise IT channels. (See also Gartner: Nokia&#8217;s Planned Security Sale Will Not Benefit Customers. PDF available <a href="http://gartner.com/resources/162000/162021/nokias_planned_security_sale_162021.pdf" target="_blank">here</a>).</p>
<p class="MsoNormal">My prediction: next year&#8217;s pie will look different but not very different. I expect that the vendors that can execute well (i.e. Cisco) will be able to increase their market share.</p>
]]></content:encoded>
			<wfw:commentRss>http://securitypie.com/slicing-the-security-pie/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>How to Negotiate &#8211; Tips for Yahoo!</title>
		<link>http://securitypie.com/how-to-negotiate-tips-for-yahoo/</link>
		<comments>http://securitypie.com/how-to-negotiate-tips-for-yahoo/#comments</comments>
		<pubDate>Wed, 19 Nov 2008 03:10:02 +0000</pubDate>
		<dc:creator>sharon</dc:creator>
				<category><![CDATA[Security Business]]></category>
		<category><![CDATA[yahoo!]]></category>

		<guid isPermaLink="false">http://securitypie.com/?p=289</guid>
		<description><![CDATA[I guess that I’m writing this few months later than I should. As a Yahoo share holder I should have taken a more proactive approach. Unfortunately, I have this habit of buying stocks at their highest price just to watch them falling almost as fast as I’m falling during ski (I blame Assaf, he thought me how [...]]]></description>
			<content:encoded><![CDATA[<p><span>I guess that I’m writing this few months later than I should. As a Yahoo<span> <a href="http://finance.google.com/finance?q=NASDAQ:YHOO" target="_blank">share holder </a></span>I should have taken a more proactive approach. Unfortunately, I have this habit of buying stocks at their highest price just to watch them falling almost as fast as I’m falling during ski (I blame Assaf, he thought me how to ski <img src='http://securitypie.com/wp-includes/images/smilies/icon_smile.gif' alt=':-)' class='wp-smiley' /> .</span></p>
<p><span>As a service to the new CEO, here is an important lesson from Shpigler the Shark:</span></p>
<div style="text-align:center"><object classid="clsid:d27cdb6e-ae6d-11cf-96b8-444553540000" width="480" height="401" codebase="http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab#version=6,0,40,0"><param name="id" value="FiveminPlayer" /><param name="allowfullscreen" value="true" /><param name="allowScriptAccess" value="always" /><param name="src" value="http://www.5min.com/Embeded/5794173/" /><embed id="FiveminPlayer" type="application/x-shockwave-flash" width="480" height="401" src="http://www.5min.com/Embeded/5794173/" allowscriptaccess="always" allowfullscreen="true"></embed></object><br />
<span style="font-size: 10px; font-family: Verdana;">    </p>
<p> </p>
<p></span></div>
]]></content:encoded>
			<wfw:commentRss>http://securitypie.com/how-to-negotiate-tips-for-yahoo/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Clear Passwords</title>
		<link>http://securitypie.com/clear-passwords/</link>
		<comments>http://securitypie.com/clear-passwords/#comments</comments>
		<pubDate>Fri, 07 Nov 2008 01:06:48 +0000</pubDate>
		<dc:creator>sharon</dc:creator>
				<category><![CDATA[Security Business]]></category>
		<category><![CDATA[Snafu]]></category>
		<category><![CDATA[email]]></category>
		<category><![CDATA[privacy]]></category>
		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://securitypie.com/?p=237</guid>
		<description><![CDATA[2008 is almost over but still there are respectable and notable companies that act like security is non of their business. I find it very irritating that some companies that promote security as a product and company differentiators act in a non secure fashion.  Following the &#8220;no one want to see an obese promotes healthy [...]]]></description>
			<content:encoded><![CDATA[<p>2008 is almost over but still there are respectable and notable companies that act like security is non of their business. I find it very irritating that some companies that promote security as a product and company differentiators act in a non secure fashion.  Following the &#8220;no one want to see an obese promotes healthy food&#8221; analogy, I would expect companies nowadays to act in a secure fashion.  Most of the web sites will send you a thank you letter after registering at their web site, but as I discovered today, some will send you an email confirming your registration alongside your username and password in cleartext.</p>
<p>As a service for those who forgot, here&#8217;s <a href="http://en.wikipedia.org/wiki/E-mail_privacy">how email privacy works</a>:</p>
<div id="attachment_238" class="wp-caption aligncenter" style="width: 310px"><a href="http://securitypie.com/wp-content/uploads/2008/11/how_e-mail_works.png"><img class="size-medium wp-image-238" title="how_e-mail_works" src="http://securitypie.com/wp-content/uploads/2008/11/how_e-mail_works-300x218.png" alt="How email works" width="300" height="218" /></a><p class="wp-caption-text">How email works</p></div>
<p>And here&#8217;s the message that turned me mad (Identifiable elements deleted to protect the innocent):</p>
<p><a href="http://securitypie.com/wp-content/uploads/2008/11/password-in-the-clear-in-2008.png"><img class="aligncenter size-medium wp-image-239" title="password-in-the-clear-in-2008" src="http://securitypie.com/wp-content/uploads/2008/11/password-in-the-clear-in-2008-300x129.png" alt="" width="300" height="129" /></a></p>
]]></content:encoded>
			<wfw:commentRss>http://securitypie.com/clear-passwords/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>101 Uses for Data Leak Prevention</title>
		<link>http://securitypie.com/101-uses-for-data-leak-prevention/</link>
		<comments>http://securitypie.com/101-uses-for-data-leak-prevention/#comments</comments>
		<pubDate>Tue, 21 Oct 2008 22:45:56 +0000</pubDate>
		<dc:creator>assafl</dc:creator>
				<category><![CDATA[Risk Management]]></category>
		<category><![CDATA[Security Business]]></category>
		<category><![CDATA[theory]]></category>
		<category><![CDATA[plagurize]]></category>
		<category><![CDATA[school]]></category>

		<guid isPermaLink="false">http://securitypie.com/?p=226</guid>
		<description><![CDATA[Ok &#8211; So I have a vested interest in DLP. Sue me. But here is a real cool use of DLP to detect plagurizing of dissertations: http://ondlp.com/?p=9#respond Notes: 1. Really cool use of the fingerprinting technology 2. I did not know that Dave&#8217;s wife was a professor /al]]></description>
			<content:encoded><![CDATA[<p>Ok &#8211; So I have a vested interest in DLP. Sue me.</p>
<p>But here is a real cool use of DLP to detect plagurizing of dissertations:<br />
<a href="http://ondlp.com/?p=9#respond">http://ondlp.com/?p=9#respond</a></p>
<p>Notes:<br />
1. Really cool use of the fingerprinting technology<br />
2. I did not know that Dave&#8217;s wife was a professor <img src='http://securitypie.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
<p>/al</p>
]]></content:encoded>
			<wfw:commentRss>http://securitypie.com/101-uses-for-data-leak-prevention/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Cisco&#8217;s Greatest Hit</title>
		<link>http://securitypie.com/ciscos-greatest-hit/</link>
		<comments>http://securitypie.com/ciscos-greatest-hit/#comments</comments>
		<pubDate>Fri, 17 Oct 2008 17:40:24 +0000</pubDate>
		<dc:creator>sharon</dc:creator>
				<category><![CDATA[Risk Management]]></category>
		<category><![CDATA[Security Business]]></category>
		<category><![CDATA[Snafu]]></category>
		<category><![CDATA[cisco]]></category>
		<category><![CDATA[Diego Rivas]]></category>
		<category><![CDATA[music]]></category>
		<category><![CDATA[paranoia]]></category>
		<category><![CDATA[software]]></category>

		<guid isPermaLink="false">http://securitypie.com/?p=215</guid>
		<description><![CDATA[  Dave, a developer from Melbourne, Australia brings an interesting story . He was installing a newly purchased VPN product. When he loaded the VPN client software, he discovered that in the place of the usual boring software was an audio disk with 12 tracks of Spanish music (see Cisco\&#8217;s Hit). A lively discussion on Dave&#8217;s blog tried [...]]]></description>
			<content:encoded><![CDATA[<div id="attachment_216" class="wp-caption alignleft" style="width: 310px"><a href="http://securitypie.com/wp-content/uploads/2008/10/diego-rivas.jpg"><img class="size-medium wp-image-216" title="diego-rivas" src="http://securitypie.com/wp-content/uploads/2008/10/diego-rivas-300x293.jpg" alt="Cisco is promoting Diego Rivas" width="300" height="293" /></a> </p>
<p> </p>
<p><p class="wp-caption-text">Cisco is promoting Diego Rivas</p></div>
<p> </p>
<p>Dave, a developer from Melbourne, Australia brings an interesting <a href="http://dave.fumberger.com/2008/10/08/cisco-networks-new-album/" target="_blank">story </a>. He was installing a newly purchased VPN product. When he loaded the VPN client software, he discovered that in the place of the usual boring software was an audio disk with 12 tracks of Spanish music (see <a href="http://sites.google.com/a/collect3.com.au/files/Home/cisco.mp3?attredirects=0">Cisco\&#8217;s Hit</a>). A lively discussion on Dave&#8217;s blog tried and successfully managed to identify the musician.  You can watch the video below.</p>
<p>Beyond the anecdotal story there are few things that we can learn from this incident. I&#8217;m not picking on Cisco specifically: In the past, one of the products that I was managing was built by very large OEM partner that was responsible for building the appliance, packaging, forwarding etc. Though it was very rare, we had few incidents when customer X received parts of a printer with his order (inside the appliance package), while another customer received  the wrong CDs etc. Errors do occur and I believe that Cisco will do everything it can to learn from this manufacturing snafu and improve its quality assurance process. However from a security risk management point of view , this incident is a reminder to trust no one:</p>
<p>Every CD should be considered suspicious, even if it arrived inside a box that has the Cisco logo. Due to the popularity of Cisco&#8217;s gear there&#8217;s a second hand market and also some <a href="http://www.networkworld.com/news/2006/102306counterfeit.html" target="_blank">fake </a>devices. <a href="http://news.softpedia.com/news/FBI-039-s-Own-Offices--Infected-with-Counterfeit-Cisco-Hardware-85312.shtml" target="_blank">Softpedia tells </a>that even the United States government is reportedly using some 3500 fake Cisco-branded network devices, including routers, network switches and hubs. &#8220;According to the investigation results, the fake devices are worth up to $3.5 million.&#8221; </p>
<p> </p>
<p>Trust no one is the moral of this story.  On a side note, this story also explains why the DOD is investing so much money looking for the <a href="http://blog.imperva.com/2008/05/the-hunt-for-the-kill-switch.html" target="_blank">kill switch</a>. </p>
<p>Enjoy the music!</p>
<p>(Arik, What&#8217;s going on down there in Australia?, we&#8217;re getting a steady stream of weird reports recently <img src='http://securitypie.com/wp-includes/images/smilies/icon_smile.gif' alt=':-)' class='wp-smiley' />  </p>
<p><object classid="clsid:d27cdb6e-ae6d-11cf-96b8-444553540000" width="425" height="344" codebase="http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab#version=6,0,40,0"><param name="allowFullScreen" value="true" /><param name="src" value="http://www.youtube.com/v/JTXBCvAzM5o&amp;hl=en&amp;fs=1" /><embed type="application/x-shockwave-flash" width="425" height="344" src="http://www.youtube.com/v/JTXBCvAzM5o&amp;hl=en&amp;fs=1" allowfullscreen="true"></embed></object></p>
]]></content:encoded>
			<wfw:commentRss>http://securitypie.com/ciscos-greatest-hit/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
