<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Security Pie &#187; Snafu</title>
	<atom:link href="http://securitypie.com/category/snafu/feed/" rel="self" type="application/rss+xml" />
	<link>http://securitypie.com</link>
	<description>The ramblings of three security curmudgeons</description>
	<lastBuildDate>Thu, 30 Dec 2010 23:25:54 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.2.1</generator>
		<item>
		<title>Google: Do What You Say</title>
		<link>http://securitypie.com/do-what-you-say/</link>
		<comments>http://securitypie.com/do-what-you-say/#comments</comments>
		<pubDate>Thu, 14 Jan 2010 07:51:32 +0000</pubDate>
		<dc:creator>sharon</dc:creator>
				<category><![CDATA[Data protection]]></category>
		<category><![CDATA[Snafu]]></category>
		<category><![CDATA[google]]></category>
		<category><![CDATA[SSL]]></category>

		<guid isPermaLink="false">http://securitypie.com/?p=711</guid>
		<description><![CDATA[First, let me start stating that this is NOT a security issue with Google, even though it might be presented this way. Unless you were hiding in a cave in the past hours you know that Google is taking some serious steps to protect its customers (you, me, all of us) after it was attacked [...]]]></description>
			<content:encoded><![CDATA[<p>First, let me start stating that this is NOT a security issue with Google, even though it might be presented this way.</p>
<p>Unless you were hiding in a cave in the past hours you know that Google is taking some serious steps to protect its customers (you, me, all of us) after it was attacked one more time (see  &#8221;<a href="http://government.zdnet.com/?p=6837" target="_blank">Google on the defensive, vulnerable; China risks international and U.S. response</a>&#8220;). Among other things, &#8220;<a href="http://www.prnewswire.com/news-releases/google-finally-improves-security-of-gmail-connections-as-consumer-watchdog-urged-81375657.html" target="_blank">Google Finally Improves Security of Gmail Connections as Consumer Watchdog Urged</a>&#8221; which is great:</p>
<blockquote>
<div id="_mcePaste">Consumer Watchdog said Google should use encryption for connections to all its Internet-based services, not just Gmail.The new security measures would not have prevented the sort of cyber attack that targeted Google from China. It does increase security to prevent third parties from snooping as information moves from a computer over a network to Google&#8217;s servers. Google has offered SSL encryption using the https protocol as an option since 2008</div>
</blockquote>
<p>But if you look on the  the screenshot you can see that NOT all the traffic is encrypted&#8230; While this might be OK for static pages, who knows what other pages are not protected with SSL? Why can&#8217;t you turn it on for the entire site? It will add more credibility and assurance&#8230;</p>
<div id="attachment_713" class="wp-caption aligncenter" style="width: 662px"><a href="http://securitypie.com/wp-content/uploads/2010/01/HTTPS-by-default-not-so-sure1.tiff"><img class="size-full wp-image-713  " title="HTTPS by default - not so sure" src="http://securitypie.com/wp-content/uploads/2010/01/HTTPS-by-default-not-so-sure1.tiff" alt="" width="652" height="171" /></a><p class="wp-caption-text">HTTPS by default - not so sure</p></div>
]]></content:encoded>
			<wfw:commentRss>http://securitypie.com/do-what-you-say/feed/</wfw:commentRss>
		<slash:comments>5</slash:comments>
		</item>
		<item>
		<title>This is Not A Good Time For Outage</title>
		<link>http://securitypie.com/this-is-not-a-good-time-for-outage/</link>
		<comments>http://securitypie.com/this-is-not-a-good-time-for-outage/#comments</comments>
		<pubDate>Wed, 23 Dec 2009 05:56:39 +0000</pubDate>
		<dc:creator>sharon</dc:creator>
				<category><![CDATA[Snafu]]></category>
		<category><![CDATA[outage]]></category>
		<category><![CDATA[rim]]></category>

		<guid isPermaLink="false">http://securitypie.com/?p=703</guid>
		<description><![CDATA[At the end of every quarter, there&#8217;s this magical moment: its best time. If you are working in a sales or sales support position, you are probably connected to your mobile email device working 24&#215;7 on getting this next deal&#8230; Lots of adrenalin in the air. It&#8217;s fun time. Unfortunately, RIM&#8217;s Blackberry network is down. [...]]]></description>
			<content:encoded><![CDATA[<p>At the end of every quarter, there&#8217;s this magical moment: <a href="http://securitypie.com/its-the-best-time/" target="_blank">its best time</a>. If you are working in a sales or sales support position, you are probably connected to your mobile email device working 24&#215;7 on getting this next deal&#8230; Lots of adrenalin in the air. It&#8217;s fun time. Unfortunately, RIM&#8217;s Blackberry network is down. In other words, no-mail-for-you&#8230;</p>
<blockquote><p>Some BlackBerry customers in the Americas are experiencing delays in message delivery,&#8221; RIM said in a statement. &#8220;Technical teams are actively working to resolve the issue for those impacted. RIM apologizes for any inconvenience experienced by customers.&#8221;</p>
<p>The outage is the second for RIM in that past five days. For several hours on Thursday, users were once again <a href="http://www.pcmag.com/article2/0,2817,2357282,00.asp">not able to receive or send e-mail messages</a>. RIM did not provide any details on what caused the outages on Thursday or Tuesday night.</p></blockquote>
<p>Googling around, you&#8217;ll <a href="http://www.google.com/search?rlz=1C1CHME_enUS353US354&amp;sourceid=chrome&amp;ie=UTF-8&amp;q=rim+outage" target="_blank">find</a> several outage reports. Few are during this time&#8230; while it&#8217;s clear that it is only a coincidence it proves again that there&#8217;s never a good time for an outage&#8230;</p>
]]></content:encoded>
			<wfw:commentRss>http://securitypie.com/this-is-not-a-good-time-for-outage/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Swine, Pistachios, Alfalfa</title>
		<link>http://securitypie.com/swine-pistachios-alfalfa/</link>
		<comments>http://securitypie.com/swine-pistachios-alfalfa/#comments</comments>
		<pubDate>Mon, 27 Apr 2009 23:39:17 +0000</pubDate>
		<dc:creator>sharon</dc:creator>
				<category><![CDATA[FDC]]></category>
		<category><![CDATA[Food]]></category>
		<category><![CDATA[Risk Management]]></category>
		<category><![CDATA[Snafu]]></category>
		<category><![CDATA[Alfalfa]]></category>
		<category><![CDATA[Salmonella]]></category>

		<guid isPermaLink="false">http://securitypie.com/?p=494</guid>
		<description><![CDATA[The government is now asking people to avoid eating raw alfalfa sprouts, including sprout blends that contain alfalfa sprouts, because of possible salmonella contamination.  According to the FDC press release,  Initial investigation results trace the contaminated raw alfalfa sprouts to multiple sprout growers in multiple states. This suggests a potential problem with the seeds used, as [...]]]></description>
			<content:encoded><![CDATA[<p>The government is now asking people to <a title="http://www.fda.gov/bbs/topics/NEWS/2009/NEW02001.html" href="http://www.fda.gov/bbs/topics/NEWS/2009/NEW02001.html" target="_blank">avoid eating raw alfalfa sprouts</a>, including sprout blends that contain alfalfa sprouts, because of possible salmonella contamination.  According to the FDC press release, </p>
<blockquote><p>Initial investigation results trace the contaminated raw alfalfa sprouts to multiple sprout growers in multiple states. This suggests a potential problem with the seeds used, as well as the possible failure of the sprout growers involved to appropriately and consistently follow the FDA Sprout Guidance<a href="http://www.cfsan.fda.gov/~dms/sprougd1.html" target="_blank"> issued in 1999</a> . The guidance recommends an effective seed disinfection treatment immediately before the start of sprouting.</p></blockquote>
<p class="MsoNormal"><span><span>To me, this whole issue sounds like a classic case of malfunction with the risk management process: I&#8217;m not an expert in food safety, but I know few things about risk management. From reading the last reports, it looks like someone in the FDA should start to enforce better controls on food manufacturers.  We can&#8217;t change our diet because someone forgot to read a manual from 1999. </span></span></p>
]]></content:encoded>
			<wfw:commentRss>http://securitypie.com/swine-pistachios-alfalfa/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Enemy at The Watercooler</title>
		<link>http://securitypie.com/enemy-at-the-watercooler/</link>
		<comments>http://securitypie.com/enemy-at-the-watercooler/#comments</comments>
		<pubDate>Tue, 13 Jan 2009 08:24:01 +0000</pubDate>
		<dc:creator>sharon</dc:creator>
				<category><![CDATA[Snafu]]></category>
		<category><![CDATA[Add new tag]]></category>

		<guid isPermaLink="false">http://securitypie.com/?p=419</guid>
		<description><![CDATA[  January &#8211; It&#8217;s this time of the year. Sales Kick Off. SKO. Many high technology companies are having their annual or bi annual sales meeting this week.  Flights to the Silicon Valley are fully booked, hotels are crowded and the bartenders are busy.  The company I&#8217;m working for is not different. We&#8217;ll have our [...]]]></description>
			<content:encoded><![CDATA[<p> </p>
<p class="MsoNormal"><span><span>January &#8211; It&#8217;s this time of the year. Sales Kick Off. SKO. Many high technology companies are having their annual or bi annual sales meeting this week.  Flights to the Silicon Valley are fully booked, hotels are crowded and the bartenders are busy.  The company I&#8217;m working for is not different. We&#8217;ll have our bi annual meeting event in one of the Silicon Valley&#8217;s finest hotel later this week.  Some of us gathered together at the hotel to have more in depth discussion before the entire sales and marketing force will arrive. </span> </span></p>
<p><span><span>This hotel was chosen by a different company as their SKO launch pad. Apparently, this company competes with one of our products. At the same time, we are also very synergetic. (Think about PCI 6.6 WAF + VA synergy).  Keeping the <a href="http://www.amazon.com/Enemy-Water-Cooler-Enterprise-Countermeasures/dp/1597491292">insider threat and the real enemy in mind, t</a>hose who run sales for this company should take a look at Brian&#8217;s book (link to</span></span><span><span> </span></span><span><span><a href="http://www.amazon.com/Enemy-Water-Cooler-Enterprise-Countermeasures/dp/1597491292" target="_blank">Amazon</a>) </span></span></p>
<p><span id="more-419"></span></p>
<div id="attachment_420" class="wp-caption aligncenter" style="width: 307px"><a href="http://www.amazon.com/Enemy-Water-Cooler-Enterprise-Countermeasures/dp/1597491292" target="_blank"><img class="size-medium wp-image-420" title="enemy-at-the-water-cooler" src="http://securitypie.com/wp-content/uploads/2009/01/enemy-at-the-water-cooler-297x300.png" alt="enemy at the water cooler" width="297" height="300" /></a><p class="wp-caption-text">enemy at the water cooler</p></div>
<p> </p>
<p>I&#8217;ve unintentionaly learned so many things about this company&#8230; All I had to do was &#8211; nothing.</p>
<p>Jsut stand at the bar, smile, nod when other people say hello and listen&#8230;..</p>
]]></content:encoded>
			<wfw:commentRss>http://securitypie.com/enemy-at-the-watercooler/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>I Didn&#8217;t Do It!</title>
		<link>http://securitypie.com/i-didnt-do-it/</link>
		<comments>http://securitypie.com/i-didnt-do-it/#comments</comments>
		<pubDate>Wed, 19 Nov 2008 02:54:24 +0000</pubDate>
		<dc:creator>sharon</dc:creator>
				<category><![CDATA[Risk Management]]></category>
		<category><![CDATA[Snafu]]></category>
		<category><![CDATA[error]]></category>
		<category><![CDATA[risk]]></category>

		<guid isPermaLink="false">http://securitypie.com/?p=271</guid>
		<description><![CDATA[The below is a true story. Some of the names were changed to protect the innocent. Yes, there is a moral to this true story, but you&#8217;ll have to read all the way&#8230; It was a typical day. Jose Arcadio was at his office in Los Gatos CA, probably planning the next perfect restaurant visit.  Consuela Martinez [...]]]></description>
			<content:encoded><![CDATA[<p><span>The below is a true story. Some of the names were changed to protect the innocent. Yes, there is a moral to this true story, but you&#8217;ll have to read all the way&#8230;</span></p>
<p><span>It was a typical day. Jose Arcadio was at his office in Los Gatos CA, probably planning the next perfect restaurant visit.  Consuela Martinez was (as always) at a random hotel. This time it was in Manila, the Philippines, just before bedtime. In Sunnyvale CA Porky Leibowitz was Blackberry-ing . </span></p>
<p> </p>
<p style="padding-left: 30px;"><span>9:34 AM| Los Gatos CA|<strong>Jose</strong>: What the heck is wrong with Security Pie &#8211; It came up all jumbled.</span></p>
<p style="padding-left: 30px;"><span>1:46 AM+1 day | Manila, Philippines |<strong>Consuela</strong>: Looks fine to me. What exactly do you see, Jose?</span></p>
<p style="padding-left: 30px;"><span>9:48 AM |Sunnyvale CA|<strong>Porky </strong>: See how we see it here in the US: Chrome and FF (screen shoot added )</span></p>
<p style="padding-left: 30px;"><span>1:50 AM +1 day |Manila, Philippines |<strong>Consuela</strong>: Did anyone touch the style or the sidebar plugin recently?</span></p>
<p style="padding-left: 30px;"><span>10:51 AM |Sunnyvale CA|<strong>Porky </strong>: Not me…</span></p>
<p style="padding-left: 30px;"><span>10:52: AM |Los Gatos CA|<strong>Jose</strong>: Ok. So this morning it looked okay. But then I posted my post as a page (by mistake). I then reposted it as a post. It happened somewhere there. But I did not knowingly make any changes anywhere. Just wrote a blog item. But I can hear Silvester saying &#8220;did you touch it&#8221;? So it was probably me…</span></p>
<p style="padding-left: 30px;"><span>1:55 AM +1 day|Manila, Philippines|<strong>Consuela </strong>: Okay let&#8217;s backtrack. What is the sequence of operations that you did, precisely?</span></p>
<p style="padding-left: 30px;"><span>10:52: AM |Los Gatos CA|<strong>Jose</strong>: I think I did the following:</span></p>
<p style="padding-left: 30px;"><span><span>1.<span> </span></span></span><span>Clicked new page.</span></p>
<p style="padding-left: 30px;"><span><span>2.<span> </span></span></span><span>Wrote.</span></p>
<p style="padding-left: 30px;"><span><span>3.<span> </span></span></span><span>Clicked save and then post.</span></p>
<p style="padding-left: 30px;"><span><span>4.<span> </span></span></span><span>Couldn&#8217;t find it on front page.</span></p>
<p style="padding-left: 30px;"><span><span>5.<span> </span></span></span><span>Went back, looked around, found Hong Sin&#8217;s remark under moderation and allowed it, and then figured out it was a page and not post.</span></p>
<p style="padding-left: 30px;"><span><span>6.<span> </span></span></span><span>Copied the page to a post, named it the same and posted it. It posted corruptly.</span></p>
<p style="padding-left: 30px;"><span><span>7.<span> </span></span></span><span>Deleted the page (but not the post).</span></p>
<p style="padding-left: 30px;"><span>2:10 AM +1 day |  Manila, Philippines|<strong>Consuela</strong>: Okay fixed. The culprit was a &lt;div class=&#8221;main&#8221;&gt; tag that was somehow transferred with your post when you cut and pasted it. It isn&#8217;t visible in the &#8220;visual&#8221; view, only when you switch to &#8220;HTML&#8221; view. I suggest you style-edit your post, it contains this ugly link in the middle; I think you can have some text instead where the link is just the target.</span></p>
<p class="MsoNormal">
<p class="MsoNormal"><span><strong>What&#8217;s the moral? </strong></span></p>
<p class="MsoNormal"><span>There is always more one bug. There is always something that can go wrong and you can bet your pie that it would.  Paraphrasing Assaf, I have interest in PCI section 6.6 (don&#8217;t sue me).  <a href="http://blog.imperva.com/2008/10/pci-scanning-after-any-change.html" target="_blank"><span>As I wrote in another place</span></a>, things will go wrong. The above example takes place every day in different places. Innocent mistakes that can go wrong. This time, nothing serious happened and our man in Manila was able to take care and fix the problem. Is your organization is as lucky as Securitypie ?</span></p>
]]></content:encoded>
			<wfw:commentRss>http://securitypie.com/i-didnt-do-it/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>Clear Passwords</title>
		<link>http://securitypie.com/clear-passwords/</link>
		<comments>http://securitypie.com/clear-passwords/#comments</comments>
		<pubDate>Fri, 07 Nov 2008 01:06:48 +0000</pubDate>
		<dc:creator>sharon</dc:creator>
				<category><![CDATA[Security Business]]></category>
		<category><![CDATA[Snafu]]></category>
		<category><![CDATA[email]]></category>
		<category><![CDATA[privacy]]></category>
		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://securitypie.com/?p=237</guid>
		<description><![CDATA[2008 is almost over but still there are respectable and notable companies that act like security is non of their business. I find it very irritating that some companies that promote security as a product and company differentiators act in a non secure fashion.  Following the &#8220;no one want to see an obese promotes healthy [...]]]></description>
			<content:encoded><![CDATA[<p>2008 is almost over but still there are respectable and notable companies that act like security is non of their business. I find it very irritating that some companies that promote security as a product and company differentiators act in a non secure fashion.  Following the &#8220;no one want to see an obese promotes healthy food&#8221; analogy, I would expect companies nowadays to act in a secure fashion.  Most of the web sites will send you a thank you letter after registering at their web site, but as I discovered today, some will send you an email confirming your registration alongside your username and password in cleartext.</p>
<p>As a service for those who forgot, here&#8217;s <a href="http://en.wikipedia.org/wiki/E-mail_privacy">how email privacy works</a>:</p>
<div id="attachment_238" class="wp-caption aligncenter" style="width: 310px"><a href="http://securitypie.com/wp-content/uploads/2008/11/how_e-mail_works.png"><img class="size-medium wp-image-238" title="how_e-mail_works" src="http://securitypie.com/wp-content/uploads/2008/11/how_e-mail_works-300x218.png" alt="How email works" width="300" height="218" /></a><p class="wp-caption-text">How email works</p></div>
<p>And here&#8217;s the message that turned me mad (Identifiable elements deleted to protect the innocent):</p>
<p><a href="http://securitypie.com/wp-content/uploads/2008/11/password-in-the-clear-in-2008.png"><img class="aligncenter size-medium wp-image-239" title="password-in-the-clear-in-2008" src="http://securitypie.com/wp-content/uploads/2008/11/password-in-the-clear-in-2008-300x129.png" alt="" width="300" height="129" /></a></p>
]]></content:encoded>
			<wfw:commentRss>http://securitypie.com/clear-passwords/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Cisco&#8217;s Greatest Hit</title>
		<link>http://securitypie.com/ciscos-greatest-hit/</link>
		<comments>http://securitypie.com/ciscos-greatest-hit/#comments</comments>
		<pubDate>Fri, 17 Oct 2008 17:40:24 +0000</pubDate>
		<dc:creator>sharon</dc:creator>
				<category><![CDATA[Risk Management]]></category>
		<category><![CDATA[Security Business]]></category>
		<category><![CDATA[Snafu]]></category>
		<category><![CDATA[cisco]]></category>
		<category><![CDATA[Diego Rivas]]></category>
		<category><![CDATA[music]]></category>
		<category><![CDATA[paranoia]]></category>
		<category><![CDATA[software]]></category>

		<guid isPermaLink="false">http://securitypie.com/?p=215</guid>
		<description><![CDATA[  Dave, a developer from Melbourne, Australia brings an interesting story . He was installing a newly purchased VPN product. When he loaded the VPN client software, he discovered that in the place of the usual boring software was an audio disk with 12 tracks of Spanish music (see Cisco\&#8217;s Hit). A lively discussion on Dave&#8217;s blog tried [...]]]></description>
			<content:encoded><![CDATA[<div id="attachment_216" class="wp-caption alignleft" style="width: 310px"><a href="http://securitypie.com/wp-content/uploads/2008/10/diego-rivas.jpg"><img class="size-medium wp-image-216" title="diego-rivas" src="http://securitypie.com/wp-content/uploads/2008/10/diego-rivas-300x293.jpg" alt="Cisco is promoting Diego Rivas" width="300" height="293" /></a> </p>
<p> </p>
<p><p class="wp-caption-text">Cisco is promoting Diego Rivas</p></div>
<p> </p>
<p>Dave, a developer from Melbourne, Australia brings an interesting <a href="http://dave.fumberger.com/2008/10/08/cisco-networks-new-album/" target="_blank">story </a>. He was installing a newly purchased VPN product. When he loaded the VPN client software, he discovered that in the place of the usual boring software was an audio disk with 12 tracks of Spanish music (see <a href="http://sites.google.com/a/collect3.com.au/files/Home/cisco.mp3?attredirects=0">Cisco\&#8217;s Hit</a>). A lively discussion on Dave&#8217;s blog tried and successfully managed to identify the musician.  You can watch the video below.</p>
<p>Beyond the anecdotal story there are few things that we can learn from this incident. I&#8217;m not picking on Cisco specifically: In the past, one of the products that I was managing was built by very large OEM partner that was responsible for building the appliance, packaging, forwarding etc. Though it was very rare, we had few incidents when customer X received parts of a printer with his order (inside the appliance package), while another customer received  the wrong CDs etc. Errors do occur and I believe that Cisco will do everything it can to learn from this manufacturing snafu and improve its quality assurance process. However from a security risk management point of view , this incident is a reminder to trust no one:</p>
<p>Every CD should be considered suspicious, even if it arrived inside a box that has the Cisco logo. Due to the popularity of Cisco&#8217;s gear there&#8217;s a second hand market and also some <a href="http://www.networkworld.com/news/2006/102306counterfeit.html" target="_blank">fake </a>devices. <a href="http://news.softpedia.com/news/FBI-039-s-Own-Offices--Infected-with-Counterfeit-Cisco-Hardware-85312.shtml" target="_blank">Softpedia tells </a>that even the United States government is reportedly using some 3500 fake Cisco-branded network devices, including routers, network switches and hubs. &#8220;According to the investigation results, the fake devices are worth up to $3.5 million.&#8221; </p>
<p> </p>
<p>Trust no one is the moral of this story.  On a side note, this story also explains why the DOD is investing so much money looking for the <a href="http://blog.imperva.com/2008/05/the-hunt-for-the-kill-switch.html" target="_blank">kill switch</a>. </p>
<p>Enjoy the music!</p>
<p>(Arik, What&#8217;s going on down there in Australia?, we&#8217;re getting a steady stream of weird reports recently <img src='http://securitypie.com/wp-includes/images/smilies/icon_smile.gif' alt=':-)' class='wp-smiley' />  </p>
<p><object classid="clsid:d27cdb6e-ae6d-11cf-96b8-444553540000" width="425" height="344" codebase="http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab#version=6,0,40,0"><param name="allowFullScreen" value="true" /><param name="src" value="http://www.youtube.com/v/JTXBCvAzM5o&amp;hl=en&amp;fs=1" /><embed type="application/x-shockwave-flash" width="425" height="344" src="http://www.youtube.com/v/JTXBCvAzM5o&amp;hl=en&amp;fs=1" allowfullscreen="true"></embed></object></p>
]]></content:encoded>
			<wfw:commentRss>http://securitypie.com/ciscos-greatest-hit/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>The unprecedented use of the term unprecedented in the current crisis is terrifying</title>
		<link>http://securitypie.com/the-unprecedented-use-of-the-term-unprecedented-in-the-current-crisis-is-terrifying/</link>
		<comments>http://securitypie.com/the-unprecedented-use-of-the-term-unprecedented-in-the-current-crisis-is-terrifying/#comments</comments>
		<pubDate>Wed, 01 Oct 2008 00:58:56 +0000</pubDate>
		<dc:creator>assafl</dc:creator>
				<category><![CDATA[Politics]]></category>
		<category><![CDATA[Risk Management]]></category>
		<category><![CDATA[Snafu]]></category>
		<category><![CDATA[Business value]]></category>
		<category><![CDATA[risk]]></category>
		<category><![CDATA[thoughts]]></category>

		<guid isPermaLink="false">http://securitypie.com/?p=144</guid>
		<description><![CDATA[&#8216;An unprecedented crisis&#8216; said Hank Paulson. http://www.politico.com/news/stories/0908/13590.html &#8216;American economy is facing unprecedented challenges&#8216; added a concerned George W. Bush http://www.foxnews.com/story/0,2933,425261,00.html &#8220;The Secretary of the Treasury, Henry Paulson, will be granted unprecedented authority in the financial bailout plan&#8221; http://www.lockergnome.com/forsythe/2008/09/29/unprecedented-authority-granted-to-henry-paulson/ In a series of moves culminating overnight, Washington took an unprecedented step into the financial sector in a [...]]]></description>
			<content:encoded><![CDATA[<p>&#8216;An <strong>unprecedented crisis</strong>&#8216; said Hank Paulson. <a href="http://www.politico.com/news/stories/0908/13590.html">http://www.politico.com/news/stories/0908/13590.html</a></p>
<p>&#8216;American economy is facing <strong>unprecedented challenges</strong>&#8216; added a concerned George W. Bush <a href="http://www.foxnews.com/story/0,2933,425261,00.html">http://www.foxnews.com/story/0,2933,425261,00.html</a></p>
<p>&#8220;The Secretary of the Treasury, Henry Paulson, will be granted <strong>unprecedented authority</strong> in the financial bailout plan&#8221; <a href="http://www.lockergnome.com/forsythe/2008/09/29/unprecedented-authority-granted-to-henry-paulson/">http://www.lockergnome.com/forsythe/2008/09/29/unprecedented-authority-granted-to-henry-paulson/</a></p>
<p>In a series of moves culminating overnight, Washington took an <strong>unprecedented step</strong> into the financial sector in a bid to steady an ailing housing market and ease a global credit crunch, analysts said. <a href="http://www.theaustralian.news.com.au/story/0,25197,24310593-20142,00.html">http://www.theaustralian.news.com.au/story/0,25197,24310593-20142,00.html</a></p>
<p>Tuesday, Paulson is spearheading an <strong>unprecedented global change</strong> as the Bush administration point man for the proposed $700 billion bailout of the U.S. financial industry as the economy reels from the credit crisis sparked by the national real estate slump and spiraling mortgage failure rates. <a href="http://www.usatoday.com/money/economy/2008-09-22-paulson-treasury_N.htm">http://www.usatoday.com/money/economy/2008-09-22-paulson-treasury_N.htm</a></p>
<p>But the $700bn (€480bn, £380bn) bail-out marks an <strong>unprecedented test</strong> of both the Democratic and Republican leadership in Congress, who are seeking to pass a proposal that they know will be unpopular among voters in an important election year and is opposed for ideological reasons by factions within both political parties. <a href="http://www.ft.com/cms/s/0/2c86b58a-89a4-11dd-8371-0000779fd18c.html">http://www.ft.com/cms/s/0/2c86b58a-89a4-11dd-8371-0000779fd18c.html</a></p>
<p>Bush: &#8216;<strong>unprecedented</strong> <strong>challenges</strong>&#8216; call for <strong>&#8216;unprecedented</strong> <strong>action</strong>&#8216; <a href="http://network.nationalpost.com/np/blogs/fpposted/archive/2008/09/19/bush-unprecedented-challenges-call-for-unprecedented-action.aspx">http://network.nationalpost.com/np/blogs/fpposted/archive/2008/09/19/bush-unprecedented-challenges-call-for-unprecedented-action.aspx</a></p>
<p><span style="text-decoration: underline;">Why terrifying?</span><br />
Because after all these exciting &#8216;<strong>unprecedented firsts</strong>&#8216; everything will be <strong>&#8216;precedented seconds&#8217; </strong>or, in other words, bland.</p>
<p>Meanwhile, while things are still interesting, have you placed your bets on September Madness?<br />
<a href="http://securitypie.com/wp-content/uploads/2008/09/att001081.jpg"><img class="alignnone size-medium wp-image-147" title="att001081" src="http://securitypie.com/wp-content/uploads/2008/09/att001081-300x157.jpg" alt="" width="670" height="370" /></a></p>
]]></content:encoded>
			<wfw:commentRss>http://securitypie.com/the-unprecedented-use-of-the-term-unprecedented-in-the-current-crisis-is-terrifying/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>You Don&#8217;t Build A Fence This Way</title>
		<link>http://securitypie.com/you-dont-build-a-fence-this-way/</link>
		<comments>http://securitypie.com/you-dont-build-a-fence-this-way/#comments</comments>
		<pubDate>Thu, 25 Sep 2008 01:37:59 +0000</pubDate>
		<dc:creator>sharon</dc:creator>
				<category><![CDATA[Security Business]]></category>
		<category><![CDATA[Snafu]]></category>
		<category><![CDATA[Federal]]></category>
		<category><![CDATA[risk]]></category>
		<category><![CDATA[technology]]></category>

		<guid isPermaLink="false">http://securitypie.com/?p=107</guid>
		<description><![CDATA[The Following text is taken from a GAO report on the SBInet (DHS Needs to Address Significant Risks in Delivering Key Technology Investment) that was published yesterday and caught my attention. The title says it all: risk, technology and investment &#8211; everything one needs in order to have a good reading). But then, as I [...]]]></description>
			<content:encoded><![CDATA[<p>The Following text is taken from a <a href="http://www.gao.gov/new.items/d081086.pdf?source=ra" target="_blank">GAO report on the SBInet</a> (DHS Needs to Address Significant Risks in Delivering Key Technology Investment) that was published yesterday and caught my attention. The title says it all: risk, technology and investment &#8211; everything one needs in order to have a good reading). But then, as I go over the text I was very disappointed to learn that the DHS was not learning from the Israeli mistakes when the security fence was built. Judge for yourself. Read the executive summary below:</p>
<div id="attachment_109" class="wp-caption aligncenter" style="width: 310px"><a href="http://securitypie.com/wp-content/uploads/2008/09/sbinet.png"><img class="size-medium wp-image-109" title="sbinet" src="http://securitypie.com/wp-content/uploads/2008/09/sbinet-300x208.png" alt="SBInet, DHS Secure Border system" width="300" height="208" /></a><p class="wp-caption-text">SBInet, DHS Secure Border system</p></div>
<p><!--  /* Font Definitions */  @font-face 	{font-family:Batang; 	panose-1:2 3 6 0 0 1 1 1 1 1; 	mso-font-alt:바탕; 	mso-font-charset:129; 	mso-generic-font-family:auto; 	mso-font-format:other; 	mso-font-pitch:fixed; 	mso-font-signature:1 151388160 16 0 524288 0;} @font-face 	{font-family:"BNACN D+ Century"; 	panose-1:0 0 0 0 0 0 0 0 0 0; 	mso-font-alt:Century; 	mso-font-charset:0; 	mso-generic-font-family:roman; 	mso-font-format:other; 	mso-font-pitch:auto; 	mso-font-signature:3 0 0 0 1 0;} @font-face 	{font-family:"BNADM C+ Century"; 	panose-1:0 0 0 0 0 0 0 0 0 0; 	mso-font-alt:Century; 	mso-font-charset:0; 	mso-generic-font-family:roman; 	mso-font-format:other; 	mso-font-pitch:auto; 	mso-font-signature:3 0 0 0 1 0;} @font-face 	{font-family:"\@Batang"; 	panose-1:0 0 0 0 0 0 0 0 0 0; 	mso-font-charset:129; 	mso-generic-font-family:auto; 	mso-font-format:other; 	mso-font-pitch:fixed; 	mso-font-signature:1 151388160 16 0 524288 0;}  /* Style Definitions */  p.MsoNormal, li.MsoNormal, div.MsoNormal 	{mso-style-parent:""; 	margin:0in; 	margin-bottom:.0001pt; 	mso-pagination:widow-orphan; 	font-size:12.0pt; 	font-family:"Times New Roman"; 	mso-fareast-font-family:Batang; 	mso-fareast-language:KO;} p.Default, li.Default, div.Default 	{mso-style-name:Default; 	mso-style-parent:""; 	margin:0in; 	margin-bottom:.0001pt; 	mso-pagination:widow-orphan; 	mso-layout-grid-align:none; 	text-autospace:none; 	font-size:12.0pt; 	font-family:"BNACN D+ Century"; 	mso-fareast-font-family:Batang; 	mso-bidi-font-family:"BNACN D+ Century"; 	color:black;} p.BodyText1, li.BodyText1, div.BodyText1 	{mso-style-name:"Body Text+1"; 	mso-style-parent:Default; 	mso-style-next:Default; 	margin:0in; 	margin-bottom:.0001pt; 	mso-pagination:widow-orphan; 	mso-layout-grid-align:none; 	text-autospace:none; 	font-size:12.0pt; 	font-family:"BNACN D+ Century"; 	mso-fareast-font-family:Batang; 	mso-bidi-font-family:"Times New Roman";} @page Section1 	{size:8.5in 11.0in; 	margin:1.0in 1.25in 1.0in 1.25in; 	mso-header-margin:.5in; 	mso-footer-margin:.5in; 	mso-paper-source:0;} div.Section1 	{page:Section1;} --></p>
<p><!--[if gte mso 10]></p>
<p><mce:style><!   /* Style Definitions */  table.MsoNormalTable 	{mso-style-name:"Table Normal"; 	mso-tstyle-rowband-size:0; 	mso-tstyle-colband-size:0; 	mso-style-noshow:yes; 	mso-style-parent:""; 	mso-padding-alt:0in 5.4pt 0in 5.4pt; 	mso-para-margin:0in; 	mso-para-margin-bottom:.0001pt; 	mso-pagination:widow-orphan; 	font-size:10.0pt; 	font-family:"Times New Roman"; 	mso-ansi-language:#0400; 	mso-fareast-language:#0400; 	mso-bidi-language:#0400;} --></p>
<p>Just replace some of the names and you feel like your in the Middle East, where projects are known to be delayed, technology is always ahead of what was originally planned and the overall cost is several times higher then originally planned&#8230;.</p>
<p class="Default"><span id="more-107"></span></p>
<p class="BodyText1" style="padding-left: 30px;"><span style="font-size: 10.5pt; color: black;">Important aspects of SBI</span><em><span style="font-size: 10.5pt; font-family: &quot;BNADM C+ Century&quot;; color: black;">net </span></em><span style="font-size: 10.5pt; color: black;">remain ambiguous and in a continued state of<br />
flux, making it <span style="color: #ff0000;">unclear and uncertain what technology capabilities will be<br />
delivered, when and where they will be delivered, and how they will be<br />
delivered</span>. For example, the scope and timing of planned SBI</span><em><span style="font-size: 10.5pt; font-family: &quot;BNADM C+ Century&quot;; color: black;">net </span></em><span style="font-size: 10.5pt; color: black;">deployments and<br />
capabilities have continued to change since the program began<span style="color: #ff0000;"> and, even now,<br />
are unclear.</span> Further, the program office does not have an approved integrated<br />
master schedule to guide the execution of the program, and GAO’s assimilation<br />
of available information indicates that the schedule has continued to change.<br />
This schedule-related risk is exacerbated by the continuous change in and the<br />
absence of a clear definition of the approach that is being used to define,<br />
develop, acquire, test, and deploy SBI</span><em><span style="font-size: 10.5pt; font-family: &quot;BNADM C+ Century&quot;; color: black;">net.<span style="color: #ff0000;"> </span></span></em><span style="color: #ff0000;"><span style="font-size: 10.5pt; color: black;">The absence of clarity and stability in these<br />
key aspects of SBI</span><em><span style="font-size: 10.5pt; font-family: &quot;BNADM C+ Century&quot;; color: black;">net </span></em></span><span style="font-size: 10.5pt; color: black;"><span style="color: #ff0000;">impairs<br />
the ability of the Congress to oversee the program and hold DHS accountable for<br />
program results, and it hampers DHS’s ability to measure program progress. </span></span></p>
<p class="BodyText1" style="padding-left: 30px;"><span style="font-size: 10.5pt; color: black;">SBI</span><em><span style="font-size: 10.5pt; font-family: &quot;BNADM C+ Century&quot;; color: black;">net </span></em><span style="font-size: 10.5pt; color: black;"><span style="color: #ff0000;">requirements<br />
have not been effectively defined and managed</span>. While the program office<br />
recently issued guidance that defines key practices associated with effectively<br />
developing and managing requirements, such as eliciting user needs and ensuring<br />
that different levels of requirements and associated verification methods are<br />
properly aligned with one another, the guidance was developed after several key<br />
activities had been completed. In the absence of this guidance, t<span style="color: #ff0000;">he program has<br />
not effectively performed key requirements definition and management practices.</span><br />
For example, it has not ensured that different levels of requirements are<br />
properly aligned, as evidenced by GAO’s analysis of a random probability sample<br />
of component requirements showing that a large percentage of them could not be<br />
traced to higher-level system and operational requirements. Also, some of SBI</span><em><span style="font-size: 10.5pt; font-family: &quot;BNADM C+ Century&quot;; color: black;">net’</span></em><span style="font-size: 10.5pt; color: black;">s operational<br />
requirements, which are the basis for all lower-level requirements, were found<br />
by an independent DHS review to be unaffordable and unverifiable, thus casting<br />
doubt on the quality of lower-level requirements that are derived from them. As<br />
a result, the risk of SBI</span><em><span style="font-size: 10.5pt; font-family: &quot;BNADM C+ Century&quot;; color: black;">net </span></em><span style="font-size: 10.5pt; color: black;">not<br />
meeting mission needs and performing as intended is increased, as are the<br />
chances of expensive and time-consuming system rework. </span></p>
<p class="MsoNormal" style="padding-left: 30px;"><span style="font-size: 10.5pt; color: black;">SBI</span><em><span style="font-size: 10.5pt; font-family: &quot;BNADM C+ Century&quot;; color: black;">net </span></em><span style="font-size: 10.5pt; color: black;"><span style="color: #ff0000;">testing<br />
has not been effectively managed</span>. For example, the program office has not<br />
tested the individual system components to be deployed to the initial<br />
deployment locations, even though the contractor initiated integration testing<br />
of these components with other system components and subsystems in June 2008.<br />
Further, while a test management strategy was drafted in May 2008, it has not<br />
been finalized and approved, and it does not contain, among other things, a<br />
clear definition of testing roles and responsibilities; a high-level master<br />
schedule of SBI</span><em><span style="font-size: 10.5pt; font-family: &quot;BNADM C+ Century&quot;; color: black;">net </span></em><span style="font-size: 10.5pt; color: black;">test<br />
activities; or sufficient detail to effectively guide project-specific test<br />
planning, such as milestones and metrics for specific project testing. <span style="color: #ff0000;">Without<br />
a structured and disciplined approach to testing, the risk that SBI</span></span><span style="color: #ff0000;"><em><span style="font-size: 10.5pt; font-family: &quot;BNADM C+ Century&quot;; color: black;">net </span></em><span style="font-size: 10.5pt; color: black;">will not satisfy user<br />
needs and operational requirements, thus requiring system rework, is increased.</span></span></p>
<p class="MsoNormal" style="padding-left: 30px;">
<p class="MsoNormal" style="padding-left: 30px;">
<p>Seriously, long term, highly technological projects always risky to manage. In a way, I admire those that can manage a project with hundreds and thousands of dependencies, external controls, budget constrains and eventually deliver a solution. I am sure that under the proper guidance, this said system will become the cornerstone of the border control system.</p>
<p style="padding-left: 30px;">
]]></content:encoded>
			<wfw:commentRss>http://securitypie.com/you-dont-build-a-fence-this-way/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Powerpoint Snafu</title>
		<link>http://securitypie.com/powerpoint-snafu/</link>
		<comments>http://securitypie.com/powerpoint-snafu/#comments</comments>
		<pubDate>Sun, 14 Sep 2008 06:42:21 +0000</pubDate>
		<dc:creator>sharon</dc:creator>
				<category><![CDATA[Snafu]]></category>
		<category><![CDATA[powerpoint]]></category>
		<category><![CDATA[presentation]]></category>
		<category><![CDATA[typo]]></category>

		<guid isPermaLink="false">http://securitypie.com/?p=77</guid>
		<description><![CDATA[The life of the technology road warrior are filled with airports, Starbucks, very longs days, short nights and lots of PowerPoint slides &#8230; During my travel last week, I was presenting to a large forum. Typically, I was refreshing the slides at night,  several hours before the presentation.  When I presenting I noticed two errors [...]]]></description>
			<content:encoded><![CDATA[<p>The life of the technology road warrior are filled with airports, Starbucks, very longs days, short nights and lots of PowerPoint slides &#8230; During my <a href="http://blog.imperva.com/2008/09/zero-zero-false-positive.html" target="_blank">travel </a>last week, I was presenting to a large forum. Typically, I was refreshing the slides at night,  several hours before the presentation.  When I presenting I noticed two errors that I have made. One was just a typo. I really don&#8217;t like typos (unfortunately, I have more than a few). The other was an error made while copying and pasting a sentence from another presentation.  To make me feel better, here are two pictures shot in Israel during the past months.  Feel free to choose the caption</p>
<div id="attachment_79" class="wp-caption aligncenter" style="width: 310px"><a href="http://securitypie.com/wp-content/uploads/2008/09/cut-and-paste-issues-1.png"><img class="size-medium wp-image-79" title="cut-and-paste-issues-1" src="http://securitypie.com/wp-content/uploads/2008/09/cut-and-paste-issues-1-300x239.png" alt="Copy&amp;Paste" width="300" height="239" /></a><p class="wp-caption-text">Copy&amp;Paste</p></div>
<div id="attachment_80" class="wp-caption aligncenter" style="width: 310px"><a href="http://securitypie.com/wp-content/uploads/2008/09/pnp_1_wh.jpg"><img class="size-medium wp-image-80" title="pnp_1_wh" src="http://securitypie.com/wp-content/uploads/2008/09/pnp_1_wh-300x233.jpg" alt="Typo" width="300" height="233" /></a><p class="wp-caption-text">Typo</p></div>
]]></content:encoded>
			<wfw:commentRss>http://securitypie.com/powerpoint-snafu/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

