Wednesday, October 18, 2006

distracting the audience

While misdirecting the audience's attention works well in magic shows, I don't think "forget how much we suck, these other people suck worse. really." is a terribly effective PR strategy. But what do I know, I'm not a marketing expert.

"As you might imagine, we are upset at Windows for not being more hardy against such viruses, and even more upset with ourselves for not catching it," Apple said on its site.
The chutzpa does make me laugh though. After all, your immune system really should be stronger to fight the SARS I brought into your home when you invited me to dinner last week. I bet you don't even take vitamin C. You're bringing illness on yourself really. You should seek psychiatric help, you're obviously suffering from Munchausen Syndrome.

I've said it before and I'll say it again, I like Apple, but they are kidding themselves if they really believe that they are superior when it comes to security. Based on what I've seen in the world, I'd say EVERYONE sucks. Hell, if a critical system like electronic voting boxes can't be locked down, what chances does a commercial app have?

~Elphie

Labels: , , ,

Friday, April 07, 2006

I'd like to buy an 0, HOPE6, BSOD, Captain Obvious and media whoring...

Let's start with CanSecWest, and the vulnerability commercialization panel they had on Wednesday. There was much spirited debate but no end agreement between the parties... takes me back to ShmooCon and the BOF panel on training... but I digress.

In the press, Michael Sutton is quoted as saying that vendors need to pay for vulns, and later in the article a customer states he expects vendors to pay for vulns as well.
"The only economic model that does not make sense to me is the vendor's," Sutton said. "They get to know about a vulnerabilities ahead of time, but they are unwilling to pay for them."
Let's blithely assume for a moment that vendors and researchers could agree on the dollar value of a vulnerability (ROTFLMAO). There is still a big problem with the 'buying vulnerabilities protects customers' argument: if Oracle buys a vuln from David Litchfield, Oracle now owns the vuln. That means that they don't EVER have to fix it if they don't want to. I'm not just picking on Oracle - this is true of ANY vendor. They wouldn't be buying vulns, they'd be buying silence. And that would just piss everyone off - hell, that's why full disclosure practices started to begin with - the only way to get a vendor to fix a security bug was to publicly shame them with it. So I wholeheartedly disagree that vendors buying bugs would make me as a computer user any safer.

I have no problem with reputable third parties buying vulnerabilities and working with vendors to protect customers. I'll admit I think Tipping Point's ZDI program does a better job of that than iDefense's VCP program simply because iDefense's customers leak their confidential advisories all the time before patches are available. But these programs do play an important role in the security ecosystem that benefit customers, researchers, and vendors.

Other stuff:

Dates for HOPE number 6 have been announced - July 21-23, just a week or so before Black Hat Vegas. Of course I've added HOPE to the upcoming cons list...

Check this out - I've heard most people aren't having much trouble with Apple's Boot Camp beta, but this guy managed to get the legendary Blue Screen of Death. I haven't seen that on one of my boxes in over five years. Wow. Comments on the blog suggest that this was a known bug in the beta relating to iSight... doh!

Adam Shostack makes some interesting observations on recent media regarding rootkits on the Emergent Chaos blog. Yeah, he is right, this is a Captain Obvious type of situation where everyone in the security space already knew that rootkits were a big dangerous problem. But I think (or at least hope) the point of the Microsoft presentation at InfoSecWorld in FL that spurred the eweek article was to educate less security savvy customers about threats we are facing today and give guidance on how to deal with them. Adam also mentions the extremely cool work being done by John Heasman of NGS on ACPI BIOS rootkits that was presented not only at Black Hat Federal, but Black Hat Amsterdam and will again be presented in May at the Computer and Enterprise Investigations Conference. Right now it is super cutting edge stuff - so maybe if John gives the talk often enough, more people will pay attention (and by someone I don't mean the bad guys). After giving the talk at Black Hat Federal in January, Rob Lemos ran a story which quoted Greg Hoglund as saying:
"It is going to be about one month before malware comes out to take advantage of this," said Greg Hoglund, CEO of reverse engineering firm HBGary and editor of Rootkit.com. "This is so easy to do. You have widely available tools, free compilers for the ACPI language, and high-level languages to write the code in."

It would be a shame if the security industry didn't pay attention in January to John's early warning and is surprised when malicious bios rootkits emerge.

And since I've mentioned CEIC, I may as well throw a shameless plug out for Vinnie Liu's talk on Defeating Forensic Analysis (with his business partner Patrick Stach) on Thursday May 4 at the con. Vinnie is a very smart guy - if you are attending CEIC, I'd definitely attend their session. I'm such a groupie I'd go to NV just to see this talk, but I think that would violate the restraining order...

~Elphie

Labels: , , , , , , , , , ,

Wednesday, April 05, 2006

Mac's officially go both ways now...

This is AWESOME. If you are one of the three people who read my blog regularly, you know I'm a fan of Mac hardware already, I'm just not willing to give up my Windows OS...
Apple's Boot Camp beta installs WinXP
Apple today introduced Boot Camp, new public beta software that enables Intel-based Macs to run Windows XP. Available as a download beginning today, Boot Camp allows users with a Microsoft Windows XP installation disc to install Windows XP on an Intel-based Mac, and once installation is complete, users can restart their computer to run either Mac OS X or Windows XP.

I think it is brilliant that Mac is taking steps to enable the Windows platform to run on their hardware. My next box is sooooo going to be a Mac...

~Elphie

Labels: , ,

Thursday, March 16, 2006

Innovations that have made my week...

First, I am stoked that someone has gotten WinXP to run on the new Intel Macs. Lets face it: Mac hardware is sexy. I'll be getting a new box when Windows Vista comes out, and this is the first step towards the possibility of that box being a Mac instead of a PC. (I know, I could get a Mac now and run OSX or Virtual PC, but I'm addicted to a number of Windows based applications and the idea of Windows running natively on a Mac is just too cool).

Forgetting for a moment my own future hardware purchases, I'm even more excited by what this means for the computer hardware industry as a whole. PC manufacturers are going to be forced to innovate and come up with better design to compete with Apple. And that is a good thing for everyone if you ask me. (for a chuckle, here is an example of Apple's m4d d3sign 5killz. You'll have to install Google Video Player - if someone has a link to this in Windows Media Player or any other media players, please send it to me and I'll add the links)

Second bit of news I feel the need to rave about is a significant advance in cancer prevention, reproductive health, and public health in general. In 2005 a vaccine for Human Papilloma Virus (HPV) was developed which should be available in the US in the second half of 2006.

HPV is extremely common. Half of all sexually active women between 18 and 22 in the US are infected (another way to think about this: more women have HPV than graduate college). HPV is harmless in 90% of cases. Unfortunately, some strains of HPV significantly increase a woman's risk for cervical cancer - HPV-16 for example is found in 50% of cervical cancers, and about a dozen other HPV types are involved in most other cases of the disease. An estimated 250,000 women die worldwide from cervical cancer each year.

It is in the news again because human trials of the vaccine have started in Australia and drug companies are starting to submit vaccines for US FDA approval - the first drug is expected to be approved in June 2006. Unfortunately there is resistance to a widespread vaccination program when the vaccines become available. This vaccine, if given to boys and girls (boys may not get cervical cancer, but they are rather instrumental in spreading HPV so it makes sense to me that they should also get the vaccine) could eradicate HPV from the planet as we have done with other infectious diseases in the past. The controversy is that the vaccine needs to be given before an individual becomes sexually active - and very few parents are comfortable acknowledging that their little angels are fooling around at age 13. But IMHO the bigger barrier to widespread vaccination is the fact that this isn't being viewed as a cancer vaccine but an STD vaccine - and we all know that there are cultural, religious, and political groups the world over which feel that "abstinence only" is the only approach to take when it comes to STDs.

The technology used to create the HPV vaccine is pretty neat - and this is one of the first medical advances to PREVENT cancer that I recall seeing. Sure, chemo and radiation might help once you've got it, and we all know that behavioral changes will prevent skin or lung cancer, but this is the first 'magic shot' for cancer prevention. Hooray for science.

~Elphie

Labels: , , , , , , ,