<?xml version="1.0" encoding="utf-8"?>
<feed xmlns="http://www.w3.org/2005/Atom">
 
  <title>Cloud Security</title>
  <subtitle>Where Is Your Computer Today?</subtitle>
  <link href="http://cloudsecurity.org//" rel="self" />
  <link href="http://cloudsecurity.org/" />
  <updated>2013-01-24T12:08:47+01:00</updated>
  <author>
    <name>Craig Balding</name>
    <email>craig.balding@gmail.com</email>
  </author>
  <id>http://cloudsecurity.org/</id>
  
  <entry>
    <title>Happy New Year from the Cloud Security blog</title>
    <link href="/blog/2012/12/31/happy-new-year-from-cloud-security.html" />
    <id>tag:cloudsecurity.org,2012-12-31:1356974006</id>
    <updated>2012-12-31T18:13:26+01:00</updated>
    <content type="html">&lt;p style=&quot;text-align:center;&quot;&gt;&lt;img src=&quot;/files/happynewyear.png&quot; title=&quot;Wishing you Happy Cloud Fiddling in 2013&quot; alt=&quot;Wishing you Happy Cloud Fiddling in 2013&quot; /&gt;&lt;/p&gt;
&lt;p&gt;Hello again and Happy New Year!&lt;/p&gt;
&lt;p&gt;I&amp;#8217;ve just updated my &lt;a href=&quot;/about.html&quot;&gt;About&lt;/a&gt; page ready for 2013.&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;After a break from blogging and with mainstream cloud and “cloud-marketed” services gaining real traction, my goals for this site have changed. Friends and family frequently ask which cloud services, apps and cloud providers I recommend along with how to use them “safely”. Again, I’m not aware of any sites that cover this from a security perspective. Consequently, I decided to broaden the site to address the concerns and practicalities for cloud “users” and developers in addition to security professionals and curious geeks. This means more practical hands-on reviews, HOWTOs and walkthroughts via screencasts. In short: I show you how to select and use cloud apps, APIs and services with security in mind.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;I look forward to sharing my cloud fiddling with you in 2013!&lt;/p&gt;
&lt;p&gt;Let me know in the comments if there&amp;#8217;s something specific you&amp;#8217;d like to see.&lt;/p&gt;
&lt;p&gt;Cheers&lt;br /&gt;
Craig&lt;/p&gt;</content>
  </entry>
  
  <entry>
    <title>GoGrid Security Breach</title>
    <link href="/blog/2011/03/30/gogrid-security-breach.html" />
    <id>tag:cloudsecurity.org,2011-03-30:1301520808</id>
    <updated>2011-03-30T23:33:28+02:00</updated>
    <content type="html">&lt;p&gt;Bad news for GoGrid customers as today we received the following breach notification by email…&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;Dear Valued Customer:&lt;/p&gt;
&lt;/blockquote&gt;
&lt;blockquote&gt;
&lt;p&gt;In the normal process of reviewing our system activity, our Security Team discovered that an unauthorized third party may have viewed your account information, including payment card data. We immediately took action to protect our customers, including notifying federal law enforcement authorities, who have since seized the computing equipment and records of the single individual suspected of this misconduct. The criminal investigation is ongoing, and we will continue to assist the authorities in working toward a successful prosecution.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;blockquote&gt;
&lt;p&gt;The security and reliability of our platform is fundamental to our business, as is the trust and faith that our customers place in us. We have completed a rigorous audit conducted by a leading security firm. There were three important findings that lead us to believe the situation has been contained:&lt;/p&gt;
&lt;/blockquote&gt;
&lt;blockquote&gt;
&lt;p&gt;1. The method utilized by the suspect to gain access has been identified and remediated.&lt;br /&gt;
2. It appears that the suspect’s sole motive was to acquire free services from us. We have no evidence suggesting that the suspect was targeting customer infrastructure or payment cards.&lt;br /&gt;
3. We have no indication that any customer information was shared with any other unauthorized parties or that there has been unauthorized use of any cardholder’s data.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;blockquote&gt;
&lt;p&gt;In addition, we are instituting a series of new measures designed to further enhance security. Any information that you may need in order to comply with these measures will be communicated through the user portal and the support ticketing system. As an added precaution, affected cardholders will receive a letter in the mail offering credit monitoring services at our expense.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;blockquote&gt;
&lt;p&gt;Client privacy, confidentiality and security are central to us. We greatly value your business and apologize for any inconvenience this causes. If you have any questions related to any of the above, please contact our Customer Service Team at 1-866-310-8477 or 1-415-963-9955 or via email at gogridteam@gogrid.com.&lt;br /&gt;
Sincerely,&lt;br /&gt;
John Keagy, Chief Executive Officer, and the GoGrid Team&lt;/p&gt;
&lt;/blockquote&gt;
&lt;blockquote&gt;
&lt;p&gt;This email was sent by:GoGrid&lt;/p&gt;
&lt;/blockquote&gt;
&lt;blockquote&gt;
&lt;p&gt;360 Spear Street, Suite 200 San Francisco, CA, 94105, USA&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;Anyone know any details of the case?&lt;/p&gt;</content>
  </entry>
  
  <entry>
    <title>Brucon 2010 - More on Project Skylab</title>
    <link href="/blog/2010/12/17/brucon-2010-more-on-project-skylab.html" />
    <id>tag:cloudsecurity.org,2010-12-17:1292624565</id>
    <updated>2010-12-17T23:22:45+01:00</updated>
    <content type="html">&lt;p&gt;The &lt;a href=&quot;http://brucon.org&quot;&gt;Brucon&lt;/a&gt; multimedia people recently posted the video of all the &lt;a href=&quot;http://2010.brucon.org/index.php/Presentations&quot;&gt;Brucon 2010 talks&lt;/a&gt;.&lt;/p&gt;
                &lt;p&gt;Here&amp;#8217;s a video of my &lt;a href=&quot;http://corelan.pwnsauces.eu/brucon/2010/Craig%20Balding%20-%20Project%20Skylab.avi&quot;&gt;Project Skylab talk&lt;/a&gt; [1 hour / 120MB AVI] hosted by the &lt;a href=&quot;http://www.corelan.be:8800/&quot;&gt;Corelan team&lt;/a&gt; (thanks guys!).  The first half is mostly a &amp;#8220;call to action&amp;#8221; for security practitioners, the second half covers Skylab components, architecture and plans.&lt;/p&gt;
                &lt;p&gt;I plan to post a demo video of Skylab in late January/early Febuary, so if you&amp;#8217;re looking for that, hold tight.&lt;/p&gt;
                &lt;p&gt;For those that want to peruse the slidedeck and speaker notes, here&amp;#8217;s the Slideshare powered preso:&lt;/p&gt;
                &lt;div style=&quot;width:477px&quot; id=&quot;__ss_5288587&quot;&gt;&lt;strong style=&quot;display:block;margin:12px 0 4px&quot;&gt;&lt;a href=&quot;http://www.slideshare.net/craigbalding/project-skylab-helping-you-get-your-cloud-on&quot; title=&quot;Project Skylab: Helping You Get Your Cloud On&quot;&gt;Project Skylab: Helping You Get Your Cloud On&lt;/a&gt;&lt;/strong&gt;&lt;object id=&quot;__sse5288587&quot; width=&quot;477&quot; height=&quot;510&quot;&gt;&lt;param name=&quot;movie&quot; value=&quot;http://static.slidesharecdn.com/swf/doc_player.swf?doc=skylabv2-100926031114-phpapp01&amp;stripped_title=project-skylab-helping-you-get-your-cloud-on&amp;userName=craigbalding&quot; /&gt;&lt;param name=&quot;allowFullScreen&quot; value=&quot;true&quot;/&gt;&lt;param name=&quot;allowScriptAccess&quot; value=&quot;always&quot;/&gt;&lt;embed name=&quot;__sse5288587&quot; src=&quot;http://static.slidesharecdn.com/swf/doc_player.swf?doc=skylabv2-100926031114-phpapp01&amp;stripped_title=project-skylab-helping-you-get-your-cloud-on&amp;userName=craigbalding&quot; type=&quot;application/x-shockwave-flash&quot; allowscriptaccess=&quot;always&quot; allowfullscreen=&quot;true&quot; width=&quot;477&quot; height=&quot;510&quot;&gt;&lt;/embed&gt;&lt;/object&gt;&lt;div style=&quot;padding:5px 0 12px&quot;&gt;View more &lt;a href=&quot;http://www.slideshare.net/&quot;&gt;documents&lt;/a&gt; from &lt;a href=&quot;http://www.slideshare.net/craigbalding&quot;&gt;craigbalding&lt;/a&gt;.&lt;/div&gt;&lt;/div&gt;
                &lt;p&gt;&lt;a href=&quot;http://brucon.org&quot;&gt;Brucon&lt;/a&gt; remains one of my favourite infosec conferences &amp;#8211; its relaxed, friendly and has consistently good talks.  As with many non-profit conferences, it relies very much on the goodwill and sweat of a volunteer crew and I&amp;#8217;d like to say a special thankyou to all those that lent a helping hand.&lt;/p&gt;</content>
  </entry>
  
  <entry>
    <title>How to Kick Ass in Cloud Computing Marketing</title>
    <link href="/blog/2010/05/18/how-to-kick-ass-in-cloud-computing-marketing.html" />
    <id>tag:cloudsecurity.org,2010-05-18:1274213881</id>
    <updated>2010-05-18T22:18:01+02:00</updated>
    <content type="html">&lt;p&gt;Few things inspire a blogger to write blog posts than appealing to their ego and sense of humour.  Despite concerted appearances to the contrary, it appears I too am susceptible.&lt;/p&gt;
&lt;p&gt;Here we take a lesson in marketing brilliance from Novell&amp;#8230;as they &amp;#8220;take the drama out of Cloud Computing&amp;#8221;&amp;#8230;by bringing a &lt;a href=&quot;http://cloudsecurity.org/blog/2010/01/25/are-you-trying-to-pin-the-tail-on-the-cloud-donkey.html&quot;&gt;slightly surreal blog post&lt;/a&gt; I wrote to the small stage/screen:&lt;/p&gt;
&lt;p style=&quot;text-align:center;&quot;&gt;&lt;object width=&quot;400&quot; height=&quot;225&quot;&gt;&lt;param name=&quot;allowfullscreen&quot; value=&quot;true&quot; /&gt;&lt;param name=&quot;allowscriptaccess&quot; value=&quot;always&quot; /&gt;&lt;param name=&quot;movie&quot; value=&quot;http://vimeo.com/moogaloop.swf?clip_id=11686394&amp;amp;server=vimeo.com&amp;amp;show_title=1&amp;amp;show_byline=1&amp;amp;show_portrait=0&amp;amp;color=&amp;amp;fullscreen=1&quot; /&gt;&lt;embed src=&quot;http://vimeo.com/moogaloop.swf?clip_id=11686394&amp;amp;server=vimeo.com&amp;amp;show_title=1&amp;amp;show_byline=1&amp;amp;show_portrait=0&amp;amp;color=&amp;amp;fullscreen=1&quot; type=&quot;application/x-shockwave-flash&quot; allowfullscreen=&quot;true&quot; allowscriptaccess=&quot;always&quot; width=&quot;400&quot; height=&quot;225&quot;&gt;&lt;/embed&gt;&lt;/object&gt;&lt;/p&gt;
&lt;p&gt;If the above doesn&amp;#8217;t display for you, click &lt;a href=&quot;http://vimeo.com/11686394&quot;&gt;An interpretation from the blog post: Are You Trying to Pin the Tail on the Cloud Donkey? by Craig Balding&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;Thanks to the actors for giving me a laugh out loud moment &amp;#8211; commanding performances gents! :)&lt;/p&gt;
&lt;p&gt;Cheers,&lt;br /&gt;
Craig&lt;/p&gt;
&lt;p&gt;P.S For more hilarity, check out their &lt;a href=&quot;http://vimeo.com/novell&quot;&gt;Vimeo channel&lt;/a&gt;&lt;/p&gt;</content>
  </entry>
  
  <entry>
    <title>Introducing the Skylab Community Project</title>
    <link href="/blog/2010/03/24/introducing-the-skylab-community-project.html" />
    <id>tag:cloudsecurity.org,2010-03-24:1269467027</id>
    <updated>2010-03-24T22:43:47+01:00</updated>
    <content type="html">&lt;p&gt;Last week I attended SecureCloud 2010 in Barcelona, a conference dedicated to cloud computing and security, organised by the Cloud Security Alliance, ENISA, ISACA and IEEE.&lt;/p&gt;
&lt;p&gt;This proved to be an excellent opportunity for deep dive conversations with others heavily involved with cloud security, both providers and users.&lt;/p&gt;
&lt;p&gt;The conference was well run &amp;#8211; particularly for a first time out.  The presentations were a mixed bunch, which I felt reflected:&lt;/p&gt;
&lt;ul&gt;
	&lt;li&gt;the on-going open interpretation of the term &amp;#8220;cloud&amp;#8221; (and a few who insisted on muddying the waters by referring to traditional web hosting providers as &amp;#8220;cloud providers&amp;#8221; &amp;#8211; eek!)&lt;/li&gt;
	&lt;li&gt;the different stages that people are at with their understanding of cloud computing and security and&lt;/li&gt;
	&lt;li&gt;the wide diversity of speakers present (a healthy thing in my book)..&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;I&amp;#8217;m very glad I attended and was able to present the kick-off to Project Skylab.&lt;/p&gt;
&lt;p&gt;A number of readers asked if the presentations would be recorded and made available to non-attendees.  Unfortunately, they were not, so I&amp;#8217;ve recorded the &amp;#8220;home edition&amp;#8221; version of my talk and make it available here.&lt;/p&gt;
&lt;p&gt;The Skylab Project is aimed at IT and IT security professionals that are &amp;#8220;cloud curious&amp;#8221; and want to get their hands dirty in a relatively safe way (i.e. no business data involved).  You could say its for the hobbyist security geek.  This talk sets out the concept, design goals and plans for Project Skylab.  Hence, this presentation is &lt;strong&gt;not&lt;/strong&gt; about &amp;#8220;cloud security&amp;#8221; per se or &amp;#8220;securing the cloud&amp;#8221;.  At most its about delivering a security related service (an demand security test lab) from the cloud.  Check out my other &lt;a href=&quot;http://cloudsecurity.org/tag/presentations.html&quot;&gt;cloud computing and security presentations&lt;/a&gt; if you&amp;#8217;re looking for coverage of cloud security challenges.&lt;/p&gt;
&lt;p&gt;Important notes:&lt;/p&gt;
&lt;ul&gt;
	&lt;li&gt;this is the &amp;#8220;kick-off&amp;#8221; of Skylab &amp;#8211; not the &amp;#8220;solution&amp;#8221; stage (!)&lt;/li&gt;
	&lt;li&gt;if you&amp;#8217;re an old hand with IaaS services (including cloud overlay networks), I doubt you&amp;#8217;ll learn anything new about cloud.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;I plan to develop Skylab on an on-going basis.  I&amp;#8217;m also encouraging others to contibute their ideas (with full credit of course).&lt;/p&gt;
&lt;p&gt;Finally, I&amp;#8217;ve applied to speak at Brucon 2010 in September.  If my application is successful I will present the first tried and tested incarnation of Skylab.&lt;/p&gt;
&lt;p&gt;Please let me know if you enjoy this video (or not!) as this is the first time I&amp;#8217;ve tried this.  I welcome your feedback.&lt;/p&gt;
&lt;p&gt;&lt;embed src=&quot;http://blip.tv/play/AYHQqSoA&quot; type=&quot;application/x-shockwave-flash&quot; width=&quot;500&quot; height=&quot;360&quot; allowscriptaccess=&quot;always&quot; allowfullscreen=&quot;true&quot;&gt;&lt;/embed&gt;&lt;/p&gt;
&lt;p&gt;I&amp;#8217;d like to thank Jim Reavis and his team for the excellent logistical support throughout the conference, along with the SecureCloud presentation committee for inviting me to speak.&lt;/p&gt;
&lt;p&gt;Cheers,&lt;br /&gt;
Craig&lt;/p&gt;
&lt;p&gt;P.S cloudsecurity.org now has a forum dedicated to &lt;a href=&quot;http://cloudsecurity.org/forum/index.php&quot;&gt;discussions about cloud computing and security&lt;/a&gt;.  There is also a dedicated board for Project Skylab communication.&lt;/p&gt;</content>
  </entry>
  
  <entry>
    <title>Cloud Computing and Security Conference: SecureCloud 2010</title>
    <link href="/blog/2010/03/14/cloud-computing-and-security-conference-securecloud-2010.html" />
    <id>tag:cloudsecurity.org,2010-03-14:1268575161</id>
    <updated>2010-03-14T14:59:21+01:00</updated>
    <content type="html">&lt;p style=&quot;text-align:center;&quot;&gt;&lt;img src=&quot;/files/securecloud2010.jpg&quot; title=&quot;SecureCloud Cloud Computing and Security Conference&quot; alt=&quot;SecureCloud Cloud Computing and Security Conference&quot; /&gt;&lt;/p&gt;
&lt;p&gt;Next Tueday and Wednesday I&amp;#8217;ll be attending &lt;a href=&quot;http://cloudsecurityalliance.org/sc2010.html&quot;&gt;SecureCloud 2010&lt;/a&gt; in Barcelona, Spain.  This looks to be a very promising conference, totally focused on cloud computing and security.  Admission is &lt;strong&gt;free&lt;/strong&gt;, and the event is organised by the Cloud Security Alliance, ENISA, ISACA and IEEE.&lt;/p&gt;
&lt;p&gt;On Wednesday, I&amp;#8217;ll present &amp;#8220;Skylab: How To Create A Simple Security Test Lab With No Hardware&amp;#8221;.  Here&amp;#8217;s the blurb:&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;This presentation will be technical in nature and focus on how&lt;br /&gt;
security practitioners can leverage public IaaS clouds today, to create&lt;br /&gt;
an ad-hoc security test lab for both offensive and defensive security&lt;br /&gt;
research.  We&amp;#8217;ll explore prior use cases of cloud by security&lt;br /&gt;
researchers, define a simple test lab network architecture and&lt;br /&gt;
associated requirements, get an overview of existing IaaS capabilities&lt;br /&gt;
and the challenges you&amp;#8217;ll face when replicating even relatively simple&lt;br /&gt;
network topologies (along with some workarounds).  At the end of this&lt;br /&gt;
presentation, attendees will know how to build their own virtual skylab.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;When I get back, I&amp;#8217;ll upload my slides and explain more about Skylab.&lt;/p&gt;
&lt;p&gt;If you&amp;#8217;re attending, definitely come up and say hello.&lt;/p&gt;
&lt;p&gt;Cheers,&lt;/p&gt;
&lt;p&gt;Craig&lt;/p&gt;</content>
  </entry>
  
  <entry>
    <title>Cloud Security Threats Survey</title>
    <link href="/blog/2010/02/23/cloud-security-threats-survey.html" />
    <id>tag:cloudsecurity.org,2010-02-23:1266926938</id>
    <updated>2010-02-23T13:08:58+01:00</updated>
    <content type="html">&lt;p&gt;Ask a room full of security professionals what cloud threats they are concerned with and you&amp;#8217;ll get quite a variety of answers.  Partly this stems from the widly varying definitions of &amp;#8220;Cloud&amp;#8221;, but also reflects their respective experience dealing with security threats faced by their organisation.&lt;/p&gt;
&lt;p&gt;Maybe you think &amp;#8220;insider threats&amp;#8221; are the big issue, or perhaps you feel attacks against the shiny new attack surface offered by cloud providers is the big concern.  Or you may look at things the other way round and feel that attacks against cloud &lt;strong&gt;clients&lt;/strong&gt; are the most significant threat &amp;#8211; especially given what we know about client side computing, mobile professionals and insecure WiFi setups.&lt;/p&gt;
&lt;p&gt;Either way, here is a chance to express your view.&lt;/p&gt;
&lt;p&gt;Right now, the Cloud Security Alliance (CSA) is seeking your input.  They are currently finalising a paper for release at RSA 2010 next week, called the &lt;em&gt;Top Threats to Cloud Computing&lt;/em&gt;.  The CSA &amp;#8220;top threats&amp;#8221; working group is seeking wider input on the respective ranking of 7 specific cloud threats.&lt;/p&gt;
&lt;p&gt;If you are a cloud user and/or security professional, I encourage you to &lt;a href=&quot;http://www.surveymonkey.com/s/VRPMBRM&quot;&gt;take the 5 minute survey&lt;/a&gt;.  Results will be collected at the end of this week.&lt;/p&gt;</content>
  </entry>
  
  <entry>
    <title>The Global Security Challenge: Money and Mentorship for Radical Cloud Securty Ideas</title>
    <link href="/blog/2010/02/03/the-cloud-security-challenge-money-and-mentorship-for-radical-ideas.html" />
    <id>tag:cloudsecurity.org,2010-02-03:1265232746</id>
    <updated>2010-02-03T22:32:26+01:00</updated>
    <content type="html">&lt;p&gt;&lt;img src=&quot;/files/globalsecurity.gif&quot; class=&quot;left&quot; title=&quot;Global Security Challenge Logo&quot; alt=&quot;Global Security Challenge Logo&quot; /&gt;&lt;/p&gt;
&lt;p&gt;Cloudsecurity.org is proud to be supporting the Global Security Challenge with their &amp;#8220;Cloud Security Challenge&amp;#8221; competition.&lt;/p&gt;
&lt;p&gt;If you&amp;#8217;ve a bright idea for cloud security or you know someone who has, this is an opportunity to grow it quickly.&lt;/p&gt;
&lt;p&gt;The competition aims &amp;#8220;to empower entrepreneurs in the security technology space.&amp;#8221;&lt;/p&gt;
&lt;p&gt;The Global Security Challenge team do this through running challenges that anyone with a clever idea and a decent business plan can enter.  A panel of experts select the most promising security technology start-ups.&lt;/p&gt;
&lt;p&gt;The winner of this challenge will receive a 10,000USD grant and mentorship from CapGemini.  HP Labs in Bristol UK are sponsoring the event and offering use of their test-bed for up to 3 finalists.&lt;/p&gt;
&lt;p&gt;Ultimately it may provide a path to additional funding &amp;#8212; top contenders from previous challenges raised 57MM USD.&lt;/p&gt;
&lt;p&gt;The competition is free to enter and the deadline is 15th March.&lt;/p&gt;
&lt;p&gt;To learn more and submit your idea, visit the &lt;a href=&quot;http://www.globalsecuritychallenge.com/gsc_competitions.php#cloud&quot;&gt;Global Security Challenge website&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;Let me know if you have any questions and I&amp;#8217;ll do my best to get them answered.&lt;/p&gt;</content>
  </entry>
  
  <entry>
    <title>Are You Trying to Pin the Tail on the Cloud Donkey?</title>
    <link href="/blog/2010/01/25/are-you-trying-to-pin-the-tail-on-the-cloud-donkey.html" />
    <id>tag:cloudsecurity.org,2010-01-25:1264378455</id>
    <updated>2010-01-25T01:14:15+01:00</updated>
    <content type="html">&lt;p style=&quot;text-align:center;&quot;&gt;&lt;img src=&quot;http://farm3.static.flickr.com/2427/3771419019_b8a078f79f_d.jpg&quot; title=&quot;Pin the Tail on the Donkey Game&quot; alt=&quot;Pin the Tail on the Donkey Game&quot; /&gt;&lt;/p&gt;
&lt;p&gt;Today, when it comes to security due diligence and on-going operational security visibility of cloud services, enterprise security pros are acting out the childrens game, Pin the Tail on the Donkey.&lt;/p&gt;
&lt;p&gt;With security policy in hand, we&amp;#8217;re groping around, blindfolded by a lack of security visibility whilst disoriented by the scale and combination of new (and old) technologies and service models.  The Cloud Donkey &amp;#8211; known for a strong sense of preservation &amp;#8211; looks on.&lt;/p&gt;
&lt;p&gt;The problem is that there are many donkeys, and even more tails.  Worse, we&amp;#8217;re all trying to stick different tails on the same donkeys.&lt;/p&gt;
&lt;p&gt;If we don&amp;#8217;t like what we&amp;#8217;re (not) seeing, we can either moan about our predicament or try to change things.  Like collaborating with others that share the same concerns to develop the &amp;#8220;Audit, Assertion, Assessment, and Assurance API (A6)&amp;#8221; for cloud services.&lt;/p&gt;
&lt;p&gt;If you&amp;#8217;re a security pro, don&amp;#8217;t be an ass, &lt;a href=&quot;http://groups.google.com/group/A6WG&quot;&gt;join the A6 security group&lt;/a&gt;.&lt;/p&gt;
&lt;p style=&quot;text-align:right;&quot;&gt;&lt;em&gt;Photo credit: &lt;a href=&quot;http://www.flickr.com/photos/31418704@N02/&quot;&gt;cherrypatter&lt;/a&gt;&lt;/em&gt;&lt;/p&gt;</content>
  </entry>
  
  <entry>
    <title>Can the Cloud Help Haiti?</title>
    <link href="/blog/2010/01/18/can-the-cloud-help-haiti.html" />
    <id>tag:cloudsecurity.org,2010-01-18:1263833646</id>
    <updated>2010-01-18T17:54:06+01:00</updated>
    <content type="html">&lt;p&gt;&lt;img src=&quot;http://www.cloudcamp.org/images/logo_cloudcamp.gif&quot; title=&quot;CloudCamp Haiti&quot; alt=&quot;CloudCamp Haiti&quot; /&gt;&lt;/p&gt;
&lt;p&gt;If you&amp;#8217;ve been looking for a way to extend a hand to the people of Haiti, or you want your cloud venture to spread some goodwill, this post is written for you.&lt;/p&gt;
&lt;p&gt;On Wednesday this week, many of us will be attending CloudCamp Haiti &amp;#8211; and you can join us.&lt;/p&gt;
&lt;h2&gt;Here&amp;#8217;s what you need to know&lt;/h2&gt;
&lt;blockquote&gt;
&lt;p&gt;CloudCamp Haiti is a virtual unconference held as a public webinar. CloudCamp Haiti builds upon the popular CloudCamp format by providing a free and open place for the introduction and advancement of cloud computing. For this event, we are raising funds to donate to the aid effort in Haiti. Funds will be donated directly to the Red Cross efforts in Haiti.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;blockquote&gt;
&lt;p&gt;Using an online meeting format attendees can exchange ideas, knowledge and information in a creative and supporting environment, advancing the current state of cloud computing and related technologies.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;blockquote&gt;
&lt;p&gt;Date/Time:&lt;br /&gt;
- Jan 20th 11:00am &amp;#8211; 2:30pm Eastern Standard Time (EST)&lt;/p&gt;
&lt;/blockquote&gt;
&lt;blockquote&gt;
&lt;p&gt;Location:&lt;br /&gt;
- Online Webinar via GoToMeeting&lt;/p&gt;
&lt;/blockquote&gt;
&lt;blockquote&gt;
&lt;p&gt;Get involved:&lt;br /&gt;
If you are interesting in getting involved as a presenter contact John Willis (john.willis AT zabovo.com) Interested in sponsoring? contact Dave Nielsen (dave AT platformd.com)&lt;/p&gt;
&lt;/blockquote&gt;
&lt;h2&gt;What You Can Do&lt;/h2&gt;
&lt;p&gt;Sponsor this event &amp;#8211; either as a company or privately, or &lt;a href=&quot;http://www.cloudcamp.org/haiti&quot;&gt;register to attend for 25USD.&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;If you&amp;#8217;re still reading, &lt;a href=&quot;http://www.cloudcamp.org/haiti&quot;&gt;what are you waiting for?&lt;/a&gt;&lt;/p&gt;</content>
  </entry>
  
</feed>
