Wednesday, December 13, 2017
Listening In - A MUST Read Cybersecurity Book by Susan Landau
If I had to summarize why I loved working at Sun Microsystems so much, it would be the brilliant people I was able to meet, work with and we became friends.
Susan Landau was a Distinguished Engineer at Sun. She is an Association for Computing Machinery Fellow, a Cybersecurity Hall of Fame inductee and an American Association for the Advancement of Science Fellow. Susan is a globally recognized expert in security.
I had the pleasure of meeting Susan while we were both at Sun. We had a number of very interesting conversations while we were at Sun, as well a number of conversations since Sun was purchased. The conversations we had and have were always enlightening, interesting and very educational for me.
Susan wrote a book titled Listening In - Cybersecurity in an Insecure Age and sent me a signed copy. This is an excellent book and a must read whether or not you are a geek like me, a policy maker, someone who has an interest in security or just your average citizen. Susan's book is extremely well written and well researched. She is able to educate the reader on Cybersecurity in a clear and compelling fashion. You do not need a mathematical, computer science or technical background to learn a ton from this book. My hope would be Susan's book would be embraced by policy makers and citizens around the globe as she does an excellent job explaining the proper role and balance of government in providing national security and law enforcement through numerous real life examples.
When I first got the book and looked at the back cover and saw recommendations from Vint Cert, Jonathan Ziltrain, Matt Olsen (former Director NCTC) and Juliette Kayyem (former Assistant Secretary for Homeland Security), I knew this just moved to the top of my reading queue!
Susan did reach out to me to discuss security in the area of manufacturing. We had a few phone conversations and email discussions. I was thrilled to see that Susan referenced an article I wrote for Advanced Manufacturing titled, With Machine Monitoring, Instant ROI is Possible and my book, MTConnect: To Measure Is To Know. Thanks Susan!
Bottom line is that this a GREAT book and a MUST read for everyone.
Monday, May 11, 2009
Tax Day and Security
April 15th is tax day for Americans. A day everyone just loves :-) When I think of April 15th, I think of security and how it is more important than ever. There is an article today that I just saw on Yahoo!
Hackers grabbed more than 285M records in 2008
- By JORDAN ROBERTSON, AP Technology Writer - Wed Apr 15, 2009 12:05AM EDT
Jordan Robertson states: "Hackers made off with at least 285 million electronic records in 2008, more than in the four previous years combined, according to a new study that shows identity thieves are getting better at exploiting careless mistakes that leave companies vulnerable to attack."
The rest of the arrticle can be read here.
I believe the days of single factor authentication are over and the days of securing at the pipe level alone are over as well. As much as I am not a proponent of big government, I do think there are many valuable services that government has and will do for society. Does the Internet happen if not for DARPA funding? I don't think so. When I think of the right way to do identity management, I think of the DoD's Common Access Card (CAC) program.
Sun Microsystems was a big part of the CAC program and, we at Sun have taken a similar approach with our Java Card.
Now for a controversial suggestion :-) Have the US government follow DoD's lead and issue CAC to every single US citizen above the age of 6. I have kevlar underwear on for this one :-)
Solaris TX Could Have Saved San Francisco
The story that came out of San Francisco on August 12th, 2008 should be extremely frightening for all IT Managers. The Washington Post, has a great article on this written by Ashley Surdin.
Ashley brings out, "San Francisco is being forced to overhaul security measures on the computer network that controls data for its police, courts, jails, payroll and health services, as well as other crucial information, after the technology administrator entrusted with the system blocked access for everyone but himself last month and for days refused to reveal the password, even from jail. "
There is a misconception that Solaris with Trusted Extensions is only for the three letter government agencies and it is simply not true. A very important aspect is how Solaris Trusted Extensions - Labeled Security for Absolute Protection - simply extends Solaris security. The paragraph below is brought out on the Solaris TX page and is key for everyone to understand:
"It utilizes User and Process Rights Management, Solaris Containers, file systems, and networking and doesn't require a new or separate kernel. Best of all, it doesn't require ISVs to requalify their applications to run them with sensitivity labels. And because it's an extension to the Solaris 10 OS's security policy, Solaris Trusted Extensions technology is flexible and quick to deploy: You can add new applications, new users, and more, very quickly, without extensive analysis of each application — and without the need to write complex, error-prone security policies that require a system reboot."
Solaris has been and will continue to be a leader in being the most open and secure operating system on planet earth.