<?xml version="1.0" encoding="UTF-8"?>
<?xml-stylesheet type="text/xsl" media="screen" href="/~d/styles/atom10full.xsl"?><?xml-stylesheet type="text/css" media="screen" href="http://feeds.feedburner.com/~d/styles/itemcontent.css"?><feed xmlns="http://www.w3.org/2005/Atom" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:thr="http://purl.org/syndication/thread/1.0" xmlns:feedburner="http://rssnamespace.org/feedburner/ext/1.0">
    <title>Rational Survivability</title>
    
    <link rel="hub" href="http://hubbub.api.typepad.com/" />
    <link rel="alternate" type="text/html" href="http://rationalsecurity.typepad.com/blog/" />
    <id>tag:typepad.com,2003:weblog-363988</id>
    <updated>2009-05-21T15:38:11-04:00</updated>
    <subtitle>PLEASE NOTE: I HAVE PERMANENTLY MOVED MY BLOG TO http://www.rationalsurvivability.com/blog &lt;-- All these posts/comments have been moved there and all new posts since May 2009 appear there.</subtitle>
    <generator uri="http://www.typepad.com/">TypePad</generator>
    <atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="hub" href="http://pubsubhubbub.appspot.com" /><link rel="self" href="http://feeds.feedburner.com/feedburner/rarz" type="application/atom+xml" /><entry>
        <title>IMPORTANT REMINDER: My Blog and RSS Feed Have Moved To http://www.rationalsurvivability.com/blog</title>
        <link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/feedburner/rarz/~3/OOCpM3SqXXU/important-reminder-my-blog-and-rss-feed-have-moved-to-httpwwwrationalsurvivabilitycomblog.html" />
        <link rel="replies" type="text/html" href="http://rationalsecurity.typepad.com/blog/2009/05/important-reminder-my-blog-and-rss-feed-have-moved-to-httpwwwrationalsurvivabilitycomblog.html" />
        <id>tag:typepad.com,2003:post-67119407</id>
        <published>2009-05-21T15:38:11-04:00</published>
        <updated>2009-05-21T15:38:11-04:00</updated>
        <summary>This will be my last post here, so please adjust your landing accordingly to now point to: www.rationalsurvivability.com/blog If you're using an RSS reader for raw RSS feeds, please adjust your feed to: feed://www.rationalsurvivability.com/blog/?feed=rss2 If you're using Feedburner, I'm going...</summary>
        <author>
            <name>beaker</name>
        </author>
        
        
<content type="xhtml" xml:lang="en-US" xml:base="http://rationalsecurity.typepad.com/blog/">
<div xmlns="http://www.w3.org/1999/xhtml"><div>This will be my last post here, so please adjust your landing accordingly to now point to:</div><blockquote class="webkit-indent-blockquote"><p><a href="http://www.rationalsurvivability.com/blog">www.rationalsurvivability.com/blog</a></p></blockquote><div>If you're using an RSS reader for raw RSS feeds, please adjust your feed to:</div><blockquote class="webkit-indent-blockquote"><p><a href="feed://www.rationalsurvivability.com/blog/?feed=rss2">feed://www.rationalsurvivability.com/blog/?feed=rss2</a></p></blockquote><div>If you're using Feedburner, I'm going to adjust the feeds tonight. Hopefully it will work:</div><br /><blockquote class="webkit-indent-blockquote"><p>Feed Title: Rational Survivability<br />Feed Address: <a href="http://feeds2.feedburner.com/rationalsurvivability/blog">http://feeds2.feedburner.com/rationalsurvivability/blog</a></p></blockquote><div><span style="line-height: 20px;">Thanks for your patience.</span><br /></div><div><span style="line-height: 20px;"><br /></span></div><div><span style="line-height: 20px;">/Hoff</span></div></div>
</content>


    <feedburner:origLink>http://rationalsecurity.typepad.com/blog/2009/05/important-reminder-my-blog-and-rss-feed-have-moved-to-httpwwwrationalsurvivabilitycomblog.html</feedburner:origLink><feedburner:origLink>http://feedproxy.google.com/~r/typepad/nOnJ/~3/U6QlUR6bYXg/important-reminder-my-blog-and-rss-feed-have-moved-to-httpwwwrationalsurvivabilitycomblog.html</feedburner:origLink></entry>
    <entry>
        <title>IMPORTANT REMINDER: My Blog and RSS Feed Have Moved</title>
        <link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/feedburner/rarz/~3/hq7B3ef3pF0/important-reminder-my-blog-and-rss-feed-have-moved.html" />
        <link rel="replies" type="text/html" href="http://rationalsecurity.typepad.com/blog/2009/04/important-reminder-my-blog-and-rss-feed-have-moved.html" />
        <id>tag:typepad.com,2003:post-66103753</id>
        <published>2009-04-28T07:22:10-04:00</published>
        <updated>2009-04-28T07:22:10-04:00</updated>
        <summary>This is generally a messy thing to do and I'm sure it's going to screw some things up for folks, but I'm moving my blog. I've decided that after 3 years at TypePad, I need some flexibility to control my...</summary>
        <author>
            <name>beaker</name>
        </author>
        
        
<content type="xhtml" xml:lang="en-US" xml:base="http://rationalsecurity.typepad.com/blog/">
<div xmlns="http://www.w3.org/1999/xhtml"><p>This is generally a messy thing to do and I'm sure it's going to
screw some things up for folks, but I'm moving my blog.  I've decided
that after 3 years at TypePad, I need some flexibility to control my
own destiny and manage my brand a little better.</p><div>This will be my last post here, so please adjust your landing accordingly to now point to:</div><blockquote class="webkit-indent-blockquote"><p><a href="http://www.rationalsurvivability.com/blog">www.rationalsurvivability.com/blog</a></p></blockquote><div>If you're using an RSS reader for raw RSS feeds, please adjust your feed to:</div><blockquote class="webkit-indent-blockquote"><p><a href="feed://www.rationalsurvivability.com/blog/?feed=rss2">feed://www.rationalsurvivability.com/blog/?feed=rss2</a></p></blockquote><div>If you're using Feedburner, I'm going to adjust the feeds tonight. Hopefully it will work:</div><br /><blockquote class="webkit-indent-blockquote"><p>Feed Title: Rational Survivability<br />Feed Address: <a href="http://feeds2.feedburner.com/rationalsurvivability/blog">http://feeds2.feedburner.com/rationalsurvivability/blog</a></p></blockquote><div><span style="line-height: 20px;">Thanks for your patience.</span><br /></div><div><span style="line-height: 20px;"><br /></span></div><div><span style="line-height: 20px;">/Hoff</span></div><div><span style="line-height: 20px;"><br /></span></div><br /></div>
</content>


    <feedburner:origLink>http://rationalsecurity.typepad.com/blog/2009/04/important-reminder-my-blog-and-rss-feed-have-moved.html</feedburner:origLink><feedburner:origLink>http://feedproxy.google.com/~r/typepad/nOnJ/~3/uZJAPOScgW0/important-reminder-my-blog-and-rss-feed-have-moved.html</feedburner:origLink></entry>
    <entry>
        <title>IMPORTANT: Moving My Blog &amp; RSS Feed</title>
        <link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/feedburner/rarz/~3/-VoSNeUCDJU/moving-my-blog.html" />
        <link rel="replies" type="text/html" href="http://rationalsecurity.typepad.com/blog/2009/03/moving-my-blog.html" thr:count="0" />
        <id>tag:typepad.com,2003:post-64236503</id>
        <published>2009-03-16T20:47:27-04:00</published>
        <updated>2009-03-16T20:47:27-04:00</updated>
        <summary>This is generally a messy thing to do and I'm sure it's going to screw some things up for folks, but I'm moving my blog. I've decided that after 3 years at TypePad, I need some flexibility to control my...</summary>
        <author>
            <name>beaker</name>
        </author>
        
        
<content type="xhtml" xml:lang="en-US" xml:base="http://rationalsecurity.typepad.com/blog/">
<div xmlns="http://www.w3.org/1999/xhtml"><p>This is generally a messy thing to do and I'm sure it's going to screw some things up for folks, but I'm moving my blog.  I've decided that after 3 years at TypePad, I need some flexibility to control my own destiny and manage my brand a little better.</p><div>This will be my last post here, so please adjust your landing accordingly to now point to:</div><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><p><a href="http://www.rationalsurvivability.com/blog">www.rationalsurvivability.com/blog</a></p></blockquote><div>If you're using an RSS reader for raw RSS feeds, please adjust your feed to:</div><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><p><a href="feed://www.rationalsurvivability.com/blog/?feed=rss2">feed://www.rationalsurvivability.com/blog/?feed=rss2</a></p></blockquote><div>If you're using Feedburner, I'm going to adjust the feeds tonight. Hopefully it will work:</div><br /><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><p>Feed Title: Rational Survivability<br />Feed Address: <a href="http://feeds2.feedburner.com/rationalsurvivability/blog">http://feeds2.feedburner.com/rationalsurvivability/blog</a></p></blockquote><div><span style="font-family: Arial; font-size: 14px; line-height: 20px; -webkit-border-horizontal-spacing: 2px; -webkit-border-vertical-spacing: 2px; " /></div><br /><div><span style="line-height: 20px; -webkit-border-horizontal-spacing: 2px; -webkit-border-vertical-spacing: 2px; font-size: 13px; font-family: 'Trebuchet MS'; ">I'm sure this is going to cause pandaemonium, but c'est la vie.</span></div><div><span style="line-height: 20px; -webkit-border-horizontal-spacing: 2px; -webkit-border-vertical-spacing: 2px;"><br /></span></div><div><span style="line-height: 20px; -webkit-border-horizontal-spacing: 2px; -webkit-border-vertical-spacing: 2px; ">Thanks for your patience.</span><br /></div><div><span style="line-height: 20px; -webkit-border-horizontal-spacing: 2px; -webkit-border-vertical-spacing: 2px;"><br /></span></div><div><span style="line-height: 20px; -webkit-border-horizontal-spacing: 2px; -webkit-border-vertical-spacing: 2px;">/Hoff</span></div><div><span style="line-height: 20px; -webkit-border-horizontal-spacing: 2px; -webkit-border-vertical-spacing: 2px;"><br /></span></div><br /><br /></div>
</content>


    <feedburner:origLink>http://rationalsecurity.typepad.com/blog/2009/03/moving-my-blog.html</feedburner:origLink><feedburner:origLink>http://feedproxy.google.com/~r/typepad/nOnJ/~3/gzfXnli7xvU/moving-my-blog.html</feedburner:origLink></entry>
    <entry>
        <title>BeanSec! Wednesday, March 18, 2009 - 6PM to ?</title>
        <link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/feedburner/rarz/~3/xbTwpqpIsfA/beansec-wednesday-march-18-2009-6pm-to-.html" />
        <link rel="replies" type="text/html" href="http://rationalsecurity.typepad.com/blog/2009/03/beansec-wednesday-march-18-2009-6pm-to-.html" thr:count="0" />
        <id>tag:typepad.com,2003:post-64192653</id>
        <published>2009-03-15T20:51:35-04:00</published>
        <updated>2009-03-15T20:51:35-04:00</updated>
        <summary>Yo! BeanSec! is once again upon us. Wednesday, March 18, 2009. Middlesex Lounge: 315 Massachusetts Ave, Cambridge 02139. BeanSec! is an informal meetup of information security professionals, researchers and academics in the Greater Boston area that meets the third Wednesday...</summary>
        <author>
            <name>beaker</name>
        </author>
        <category scheme="http://www.sixapart.com/ns/types#category" term="BeanSec!" />
        
        <category scheme="http://sixapart.com/ns/types#tag" term="BeanSec" />
        <category scheme="http://sixapart.com/ns/types#tag" term="BeanSec!" />
        <category scheme="http://sixapart.com/ns/types#tag" term="Chris Hoff" />
        <category scheme="http://sixapart.com/ns/types#tag" term="Christofer Hoff" />
        <category scheme="http://sixapart.com/ns/types#tag" term="CitySec" />
        <category scheme="http://sixapart.com/ns/types#tag" term="Rational Security" />
        <category scheme="http://sixapart.com/ns/types#tag" term="Rational Survivability" />
        
<content type="xhtml" xml:lang="en-US" xml:base="http://rationalsecurity.typepad.com/blog/">
<div xmlns="http://www.w3.org/1999/xhtml"><br /><div><span style="color: #333333; font-family: 'trebuchet ms'; line-height: normal; "><p style="margin-top: 10px; margin-bottom: 10px; "><a href="http://rationalsecurity.typepad.com/.shared/image.html?/photos/uncategorized/2007/11/16/beansec3_2.jpg" onclick="window.open(this.href, '_blank', 'width=200,height=200,scrollbars=no,resizable=no,toolbar=no,directories=no,location=no,menubar=no,status=no,left=0,top=0'); return false" style="color: #406fc1; text-decoration: none; "><img alt="Beansec3_2" border="0" height="200" src="http://rationalsecurity.typepad.com/blog/images/2007/11/16/beansec3_2.jpg" style="margin-top: 0px; margin-right: 5px; margin-bottom: 5px; margin-left: 0px; float: left; border-top-width: 0px; border-right-width: 0px; border-bottom-width: 0px; border-left-width: 0px; border-style: initial; border-color: initial; " title="Beansec3_2" width="200" /></a>Yo!  BeanSec! is once again upon us.  Wednesday, March 18, 2009.</p><p style="margin-top: 10px; margin-bottom: 10px; "><strong>Middlesex Lounge: 315 Massachusetts Ave, Cambridge 02139. </strong></p><p style="margin-top: 10px; margin-bottom: 10px; ">BeanSec! is an informal meetup of information security professionals, researchers and academics in the Greater Boston area that meets the third Wednesday of each month.</p><p style="margin-top: 10px; margin-bottom: 10px; ">I say again, BeanSec! is hosted the third Wednesday of every month.  Add it to your calendar.</p><p style="margin-top: 10px; margin-bottom: 10px; ">Come get your grub on and have a drink.  Lots of good people show up.  Really.</p><p style="margin-top: 10px; margin-bottom: 10px; ">Unlike other meetings, you will not be expected to pay dues, “join up”, present a zero-day exploit, or defend your dissertation to attend.</p><p style="margin-top: 10px; margin-bottom: 10px; ">Don't worry about being "late" because most people just show up when they can. 6:30 is a good time to aim for. We'll try and save you a seat. There is a plenty of parking around or take the T.</p><p style="margin-top: 10px; margin-bottom: 10px; ">The food selection is basically high-end finger-food appetizers and the drinks are really good; an attentive staff and eclectic clientèle make the joint fun for people watching. Zach and I will generally annoy you into participating somehow, even if it's just fetching napkins. ;)</p><p style="margin-top: 10px; margin-bottom: 10px; "><span style="font-weight: bold; color: #ff0000; font-family: 'Trebuchet MS'; ">This week's BeanSec refreshments sponsored by: </span><a href="http://www.ioactive.com">IOActive</a></p><p style="margin-top: 10px; margin-bottom: 10px; ">We often retire across the street to Asgard for more substantive fare after the event and then to Tosci's for coffee...</p><p style="margin-top: 10px; margin-bottom: 10px; ">A little administrivia note: After 2 years, we're finally getting the beansec.org domain, blog, email, etc. setup...expect completion in about a week.</p><p style="margin-top: 10px; margin-bottom: 10px; ">See you there!</p><p style="margin-top: 10px; margin-bottom: 10px; ">/Hoff</p></span></div></div>
</content>


    <feedburner:origLink>http://rationalsecurity.typepad.com/blog/2009/03/beansec-wednesday-march-18-2009-6pm-to-.html</feedburner:origLink><feedburner:origLink>http://feedproxy.google.com/~r/typepad/nOnJ/~3/-HPAYXBKCzU/beansec-wednesday-march-18-2009-6pm-to-.html</feedburner:origLink></entry>
    <entry>
        <title>How To Be PCI Compliant in the Cloud...</title>
        <link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/feedburner/rarz/~3/hGoxwvu8_UU/how-to-be-pci-compliant-in-the-cloud.html" />
        <link rel="replies" type="text/html" href="http://rationalsecurity.typepad.com/blog/2009/03/how-to-be-pci-compliant-in-the-cloud.html" thr:count="9" thr:updated="2009-03-20T00:29:07-04:00" />
        <id>tag:typepad.com,2003:post-64173611</id>
        <published>2009-03-15T09:35:37-04:00</published>
        <updated>2009-03-15T09:40:48-04:00</updated>
        <summary>I kicked off a bit of a dust storm some months ago when I wrote a tongue-in-cheek post titled "Please Help Me: I Need a QSA to Assess PCI/DSS Compliance In the Cloud." It may have been a little contrived,...</summary>
        <author>
            <name>beaker</name>
        </author>
        <category scheme="http://www.sixapart.com/ns/types#category" term="Cloud Computing" />
        <category scheme="http://www.sixapart.com/ns/types#category" term="Cloud Security" />
        <category scheme="http://www.sixapart.com/ns/types#category" term="Compliance" />
        <category scheme="http://www.sixapart.com/ns/types#category" term="PCI" />
        
        <category scheme="http://sixapart.com/ns/types#tag" term="Chris Hoff" />
        <category scheme="http://sixapart.com/ns/types#tag" term="Christofer Hoff" />
        <category scheme="http://sixapart.com/ns/types#tag" term="Cloud" />
        <category scheme="http://sixapart.com/ns/types#tag" term="Cloud Compliance" />
        <category scheme="http://sixapart.com/ns/types#tag" term="Cloud Computing" />
        <category scheme="http://sixapart.com/ns/types#tag" term="Cloud Security" />
        <category scheme="http://sixapart.com/ns/types#tag" term="Craig Balding" />
        <category scheme="http://sixapart.com/ns/types#tag" term="Mike Dahn" />
        <category scheme="http://sixapart.com/ns/types#tag" term="Mosso" />
        <category scheme="http://sixapart.com/ns/types#tag" term="PCI" />
        <category scheme="http://sixapart.com/ns/types#tag" term="PCI" />
        <category scheme="http://sixapart.com/ns/types#tag" term="PCI Compliance" />
        <category scheme="http://sixapart.com/ns/types#tag" term="PCI DSS" />
        <category scheme="http://sixapart.com/ns/types#tag" term="Rackspace" />
        <category scheme="http://sixapart.com/ns/types#tag" term="Rational Security" />
        <category scheme="http://sixapart.com/ns/types#tag" term="Rational Survivability" />
        
<content type="xhtml" xml:lang="en-US" xml:base="http://rationalsecurity.typepad.com/blog/">
<div xmlns="http://www.w3.org/1999/xhtml"><p><a href="http://rationalsecurity.typepad.com/.a/6a00d83451be3669e20112796b946628a4-pi" style="float: right;"><img alt="Monkeys" class="at-xid-6a00d83451be3669e20112796b946628a4 " src="http://rationalsecurity.typepad.com/.a/6a00d83451be3669e20112796b946628a4-200wi" style="width: 200px; margin: 0px 0px 5px 5px;" /></a>
 I kicked off a bit of a dust storm some months ago when I wrote a tongue-in-cheek post titled "<a href="http://rationalsecurity.typepad.com/blog/2008/10/please-help-me-i-need-a-qsa-to-assess-pcidss-compliance-in-the-cloud.html">Please Help Me: I Need a QSA to Assess PCI/DSS Compliance In the Cloud.</a>"  It may have been a little contrived, but it asked some really important questions and started some really good conversations on my blog and elsewhere.</p><br /><div>At <a href="http://www.sourceconference.com">SourceBoston</a> I sat in on Mike Dahn's presentation titled "<a href="http://www.sourceconference.com/index.php/source-boston-2009/boston-2009-sessions">Cloud Compliance and Privacy"</a> in which he did an excellent job outlining the many issues surrounding PCI and Compliance and it's relevance to Cloud Computing.  </div><br /><div>Shortly thereafter, I was speaking to Geva Perry and James Urquhart on their "<a href="http://rationalsecurity.typepad.com/blog/2009/03/on-the-overcast-podcast-with-geva-perry-and-james-urquhart.html">Overcast</a>" podcast and the topic of PCI and Cloud came up. </div><br /><div>Geva asked me if after my rant on PCI and Cloud if what I was saying was that one could never be PCI compliant in the Cloud.  I basically answered that one <span style="font-weight: bold;"><span style="font-style: italic;">could</span></span> be PCI compliant in the Cloud depending upon the services used/offered by the provider and what sort of data you trafficked in.</div><br /><div>Specifically, Geva made reference to the latest announcement by Rackspace regarding their <a href="http://blog.mosso.com/2009/03/cloud-hosting-is-secure-for-take-off-mosso-enables-the-spreadsheet-store-an-online-merchant-to-become-pci-compliant/">Mosso Cloud offering and PCI compliance</a> in which they tout that by using Mosso, a customer can be "PCI Compliant"  Since I hadn't seen the specifics of the offering, I deferred my commentary but here's what I found:</div><br /><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><p><span style="color: #333333; font-family: 'Lucida Grande'; font-size: 12px; font-style: italic; line-height: 16px; ">Cloud Sites, Mosso|The Rackspace Cloud’s Flagship offering, is <span style="font-weight: bold;">officially the very first cloud hosting solution to enable an Internet merchant to pass PCI Compliance scans for both McAfee’s PCI scans and McAfee Secure Site scans. </span></span></p></blockquote><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><p><span style="color: #333333; font-family: 'Lucida Grande'; font-size: 12px; line-height: 16px; "><span style="font-style: italic;">This achievement occurred just after </span><a href="http://www.computerworld.com/action/article.do?command=viewArticleBasic&amp;articleId=9128840&amp;intsrc=news_ts_head" style="color: #0066cc; text-decoration: none; " target="_blank"><span style="font-style: italic;">Computer World</span></a><span style="font-style: italic;"> published an article where some CIO’s shared their concern that Cloud Computing is still limited to “things that don’t require full levels of security.” <span style="font-weight: bold;"> This landmark breakthrough may be the beginning of an answer to those fears, as Mosso leads Cloud Hosting towards a solid future of trust and reliability.</span></span></span></p></blockquote><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><p><span style="font-style: italic;" /></p></blockquote><p>Mosso's blog featured an example of a customer -- The Spreadsheet Store -- who allegedly attained PCI compliance by using Mosso's offering. Pay very close attention to the bits below:</p><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><p><span style="color: #333333; font-family: 'Lucida Grande'; font-size: 12px; line-height: 16px; "><span style="font-style: italic;">“We are making the Cloud business-ready.  Online merchants, like </span><a href="http://www.spreadsheetstore.com/" style="color: #0066cc; text-decoration: none; " target="_blank"><span style="font-style: italic;">The Spreadsheet Store</span></a><span style="font-style: italic;"> can now benefit from the scalability of the Cloud without compromising the security of online transactions,” says Emil Sayegh, General Manager of Mosso|The Rackspace Cloud.  “<span style="font-weight: bold;">We are thrilled to have worked with The Spreadsheet Store to prepare the Cloud for their online transactions.”</span></span></span></p></blockquote><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><p><span style="color: #333333; font-family: 'Lucida Grande'; font-size: 12px; line-height: 16px; ">...</span></p></blockquote><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><p><span style="color: #333333; font-family: 'Lucida Grande'; font-size: 12px; line-height: 16px; "><span style="font-style: italic; ">The Spreadsheet Store set up their site using </span><a href="http://www.aspdotnetstorefront.com/" style="color: #0066cc; text-decoration: none; " target="_blank"><span style="font-style: italic; ">aspdotnetstorefron</span></a><span style="font-style: italic; ">t, “Which is, in our opinion, the best shopping cart solution on the market today,” says Murphy.  “It also happens to be fully compatible with Mosso.”  </span><span style="font-weight: bold; "><span style="font-style: italic; ">Using </span></span><a href="http://authorize.net/" style="color: #0066cc; text-decoration: none; " target="_blank"><span style="font-weight: bold; "><span style="font-style: italic; ">Authorize.Net</span></span></a><span style="font-weight: bold; "><span style="font-style: italic; ">, a secure payment gateway, to handle credit card transaction, The Spreadsheet Store does not store any credit card information on the servers. </span></span><span style="font-style: italic; "> Murphy and team use MaxMind for fraud prevention, Cardinal Commerce for MasterCard Secure Code and Verified by Visa, McAfee for PCI and daily vulnerability scans, and Thawte for SSL certification.</span></span></p></blockquote><div><span style="font-weight: bold;">So after all of those lofty words relating to "...preparing the Cloud for...online transactions," what you can decipher is that Mosso doesn't seem to provide services to The Spreadsheet Store which are actually in scope for PCI in the first place!*</span></div><br /><div>The Spreadsheet store redirects that functionality to a third party card processor!  </div><br /><div><span style="font-weight: bold;">So what this really means is if you utilize a Cloud based offering and don't traffic in data that is within PCI scope and instead re-direct/use someone else's service to process and store credit card data, then it's much easier to become PCI compliant.  Um, duh.</span> <br /></div><br /><div>The goofiest bit here is that in Mosso's own "<a href="http://www.mosso.com/docs/PCI_HowTo.pdf">PCI How-To</a>" (warning: PDF) primer, they basically establish that you cannot be PCI compliant by using them if you traffic in credit card information:</div><br /><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><p><span style="line-height: 19px; "><span style="font-weight: bold;">Cloud Sites is not currently designed for the storage or archival of credit card information.  In order to build a PCI compliant e-commerce solution, Cloud Sites needs to be paired up with a payment gateway partner</span>.</span></p></blockquote><div>Doh!</div><br /><div>I actually wrote quite a detailed breakdown of this announcement for this post yesterday, but I awoke to find my buddy Craig Balding <a href="http://cloudsecurity.org/2009/03/14/what-does-pci-compliance-in-the-cloud-really-mean/">had already done a stellar job of that </a>(curses, timezones!)  I'll refer you to his post on the matter, but here's the gem in all of this.  Craig summed it up perfectly:<br /></div><br /><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><p><span style="font-family: Arial; line-height: 19px; "><span style="font-style: italic;">The fact that Mosso is seeking ways to help their customers off-load as much PCI compliance requirements to other 3rd parties is fine - it makes business sense for them and their merchant customers.  It’s their positioning of the effort as a </span><a href="http://blog.mosso.com/2009/03/cloud-hosting-is-secure-for-take-off-mosso-enables-the-spreadsheet-store-an-online-merchant-to-become-pci-compliant/" onclick="javascript:urchinTracker('/outbound/blog.mosso.com/2009/03/cloud-hosting-is-secure-for-take-off-mosso-enables-the-spreadsheet-store-an-online-merchant-to-become-pci-compliant/');" style="font-weight: bold; color: #1359ae; text-decoration: none; "><span style="font-style: italic;">“landmark breakthrough”</span></a><span style="font-style: italic;"> and that they are somehow pioneers which leads to generalisations rooted in misunderstandings that is the problem.</span></span><span style="font-style: italic;"><br /></span><span style="font-family: Arial; font-weight: bold; line-height: 19px; "><span style="font-style: italic;">Next time you hear someone say ‘Cloud Provider X is PCI compliant’, ask the golden PCI question: is their Cloud receiving, processing, storing or transmitting Credit Card data (as defined by the PCI DSS)?  If they say ‘No’, you’ll know what that really means…</span><a href="http://en.wikipedia.org/wiki/Marchitecture" onclick="javascript:urchinTracker('/outbound/en.wikipedia.org/wiki/Marchitecture');" style="font-weight: bold; color: #1359ae; text-decoration: none; "><span style="font-style: italic;">marketecture</span></a><span style="font-style: italic;">.</span></span></p></blockquote><div>There's some nifty marketing for you, eh?<br /></div><br /><div>--</div><div>* Except for the fact that the web servers housed at Mosso must undergo regularly-scheduled vulnerability scans -- which Mosso doesn't do, either.</div></div>
</content>


    <feedburner:origLink>http://rationalsecurity.typepad.com/blog/2009/03/how-to-be-pci-compliant-in-the-cloud.html</feedburner:origLink><feedburner:origLink>http://feedproxy.google.com/~r/typepad/nOnJ/~3/TYXyLfAOlRI/how-to-be-pci-compliant-in-the-cloud.html</feedburner:origLink></entry>
    <entry>
        <title>On the Overcast Podcast with Geva Perry and James Urquhart</title>
        <link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/feedburner/rarz/~3/HGcBPnCZaIo/on-the-overcast-podcast-with-geva-perry-and-james-urquhart.html" />
        <link rel="replies" type="text/html" href="http://rationalsecurity.typepad.com/blog/2009/03/on-the-overcast-podcast-with-geva-perry-and-james-urquhart.html" thr:count="0" />
        <id>tag:typepad.com,2003:post-64066711</id>
        <published>2009-03-13T19:27:06-04:00</published>
        <updated>2009-03-13T19:33:31-04:00</updated>
        <summary>Geva and James were kind (foolish?) enough to invite me onto their Overcast podcast today: In this podcast we talk to Christopher Hoff, renowned information security expert, and especially security in the context of virtualization and cloud computing. Chris is...</summary>
        <author>
            <name>beaker</name>
        </author>
        <category scheme="http://www.sixapart.com/ns/types#category" term="Cloud Computing" />
        <category scheme="http://www.sixapart.com/ns/types#category" term="Cloud Security" />
        <category scheme="http://www.sixapart.com/ns/types#category" term="Press" />
        <category scheme="http://www.sixapart.com/ns/types#category" term="Virtualization" />
        
        <category scheme="http://sixapart.com/ns/types#tag" term="Chris Hoff" />
        <category scheme="http://sixapart.com/ns/types#tag" term="Christofer Hoff" />
        <category scheme="http://sixapart.com/ns/types#tag" term="Cloud" />
        <category scheme="http://sixapart.com/ns/types#tag" term="Cloud Computing" />
        <category scheme="http://sixapart.com/ns/types#tag" term="Cloud Security" />
        <category scheme="http://sixapart.com/ns/types#tag" term="CloudSec" />
        <category scheme="http://sixapart.com/ns/types#tag" term="Geva Perry" />
        <category scheme="http://sixapart.com/ns/types#tag" term="James Urquhart" />
        <category scheme="http://sixapart.com/ns/types#tag" term="Overcast" />
        <category scheme="http://sixapart.com/ns/types#tag" term="Rational Security" />
        <category scheme="http://sixapart.com/ns/types#tag" term="Rational Survivability" />
        
<content type="xhtml" xml:lang="en-US" xml:base="http://rationalsecurity.typepad.com/blog/">
<div xmlns="http://www.w3.org/1999/xhtml"><p><a href="http://rationalsecurity.typepad.com/.a/6a00d83451be3669e2011279672be228a4-popup" onclick="window.open( this.href, '_blank', 'width=640,height=480,scrollbars=no,resizable=no,toolbar=no,directories=no,location=no,menubar=no,status=no,left=0,top=0' ); return false" style="float: right;"><img alt="Overcastlogo" class="at-xid-6a00d83451be3669e2011279672be228a4 " src="http://rationalsecurity.typepad.com/.a/6a00d83451be3669e2011279672be228a4-150wi" style="width: 150px; margin: 0px 0px 5px 5px;" /></a>
 Geva and James were kind (foolish?) enough to invite me onto their Overcast podcast today:</p><div><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><p><span style="color: #42545d; font-size: 12px; line-height: 18px; ">In this podcast we talk to Christopher Hoff, renowned information security expert, and especially security in the context of virtualization and cloud computing. Chris is the author of the <a href="http://rationalsecurity.typepad.com/" style="color: #7aa3bf; text-decoration: none; ">Rational Survivability</a> blog, and can be followed as <a href="http://twitter.com/beaker" style="color: #7aa3bf; text-decoration: none; ">@Beaker</a> on Twitter.</span><br /><span style="color: #42545d; font-size: 12px; font-weight: bold; line-height: 18px; ">Show Notes:</span></p></blockquote><div><span style="color: #42545d; font-size: 12px; line-height: 18px; "><ul style="margin-top: 10px; margin-bottom: 10px; "><ul style="margin-top: 10px; margin-bottom: 10px; "><li>Chris talks about some of the myths and misconceptions about security in the cloud. He addresses the claim that <a href="http://rationalsecurity.typepad.com/blog/2008/11/cloud-providers-are-better-at-securing-your-data-than-you-are.html" style="color: #7aa3bf; text-decoration: none; ">Cloud Providers Are Better At Securing Your Data Than You Are</a> and the benefits and shortcomings of security in the cloud.</li>
<li>We talk about Chris's <a href="http://rationalsecurity.typepad.com/blog/2009/02/what-people-really-mean-when-they-say-the-cloud-is-more-secure.html" style="color: #7aa3bf; text-decoration: none; ">Taxonomy of Cloud Computing</a> (excuse me, model of cloud computing)</li>
<li>Chris goes through some specific challenges and solutions for PCI-compliance in the cloud</li>
<li>Chris examines some of the security issues associated with multi-tenant architecture and virtualization</li>
</ul>
</ul>
<div><span style="color: #000000; font-size: 13px; line-height: 15px; ">Check it out <a href="http://overcast.typepad.com/overcast/2009/03/overcast-show-8-mar-13-2009-with-chris-hoff-cloud-security-expert.html">here</a>.</span><br /></div></span></div><br /><div><span style="color: #42545d; font-size: 12px; line-height: 18px; "><span style="color: #000000; font-size: 13px; line-height: 15px; ">/Hoff<span style="color: #42545d; font-size: 12px; line-height: 18px; "> </span></span></span></div></div></div>
</content>


    <feedburner:origLink>http://rationalsecurity.typepad.com/blog/2009/03/on-the-overcast-podcast-with-geva-perry-and-james-urquhart.html</feedburner:origLink><feedburner:origLink>http://feedproxy.google.com/~r/typepad/nOnJ/~3/qEd0tBxr1HA/on-the-overcast-podcast-with-geva-perry-and-james-urquhart.html</feedburner:origLink></entry>
    <entry>
        <title>More On Clouds &amp; Botnets: MeatClouds, CloudFlux, LeapFrog, EDoS and More!</title>
        <link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/feedburner/rarz/~3/av6x7CYnzz8/more-on-clouds-botnets-meatclouds-cloudflux-leapfrog-edos-and-more.html" />
        <link rel="replies" type="text/html" href="http://rationalsecurity.typepad.com/blog/2009/03/more-on-clouds-botnets-meatclouds-cloudflux-leapfrog-edos-and-more.html" thr:count="3" thr:updated="2009-03-14T23:17:40-04:00" />
        <id>tag:typepad.com,2003:post-64066479</id>
        <published>2009-03-13T19:18:10-04:00</published>
        <updated>2009-03-13T19:51:44-04:00</updated>
        <summary>After my "Frogs" talk at Source Boston yesterday, Adam O'Donnell and I chatted about one of my chuckle slides I threw up in the presentation in which I give some new names to some (perhaps not new) attack/threat scenarios which...</summary>
        <author>
            <name>beaker</name>
        </author>
        <category scheme="http://www.sixapart.com/ns/types#category" term="Cloud Computing" />
        <category scheme="http://www.sixapart.com/ns/types#category" term="Cloud Security" />
        
        <category scheme="http://sixapart.com/ns/types#tag" term="Adam O'Donnell" />
        <category scheme="http://sixapart.com/ns/types#tag" term="Chris Hoff" />
        <category scheme="http://sixapart.com/ns/types#tag" term="Christofer Hoff" />
        <category scheme="http://sixapart.com/ns/types#tag" term="Cloud" />
        <category scheme="http://sixapart.com/ns/types#tag" term="Cloud Computing" />
        <category scheme="http://sixapart.com/ns/types#tag" term="Cloud Security" />
        <category scheme="http://sixapart.com/ns/types#tag" term="CloudSec" />
        <category scheme="http://sixapart.com/ns/types#tag" term="Rational Security" />
        <category scheme="http://sixapart.com/ns/types#tag" term="Rational Survivability" />
        <category scheme="http://sixapart.com/ns/types#tag" term="Source Boston" />
        <category scheme="http://sixapart.com/ns/types#tag" term="Source Conference" />
        <category scheme="http://sixapart.com/ns/types#tag" term="ZDNet" />
        <category scheme="http://sixapart.com/ns/types#tag" term="Zero Day" />
        
<content type="xhtml" xml:lang="en-US" xml:base="http://rationalsecurity.typepad.com/blog/">
<div xmlns="http://www.w3.org/1999/xhtml"><p>After my "Frogs" talk at Source Boston yesterday, Adam O'Donnell and I chatted about one of my chuckle slides I threw up in the presentation in which I give some new names to some (perhaps not new) attack/threat scenarios which involve Cloud Computing:</p><div><br /><center><div><a href="http://rationalsecurity.typepad.com/.a/6a00d83451be3669e2011279671d9528a4-pi" style="display: inline;"><img alt="CloudSecBingo.058" class="at-xid-6a00d83451be3669e2011279671d9528a4 " src="http://rationalsecurity.typepad.com/.a/6a00d83451be3669e2011279671d9528a4-500wi" /></a>
 <br /></div></center><div><ul>
<li><span style="font-weight: bold; ">MeatCloud</span> - Essentially abusing Amazon's Mechanical Turk and using it to produce the Cloud version of a sweat shop; exploiting the ignorant for fun and profit to perform menial illegal muling tasks on your behalf...think SETI meets underage garment workers...</li>
<p>
</p><li><span style="font-weight: bold;">CloudFlux</span> - Take a mess of stolen credit cards, open up  a slew of Amazon AWS accounts using them, build/scale to thousands of instances overnight, launch carpet bomb attack (you choose,) tear it down/have it torn down, and move your botnet elsewhere...rinse, lather, repeat...</li>
<p>
</p><li><span style="font-weight: bold;">LeapFrog</span> - As we move to hybrid private/public clouds and load balancing/cloudbursting across multiple cloud providers, we'll interconnect Clouds via VPNs to the "trusted internals" of your Cloudbase... Attackers will thank us by abusing these tunnels to penetrate your assets through the, uh, back door.</li>
<p>
</p><li><span><span style="font-weight: bold;">vMotion Poison Potion </span>- When VMware's vCloud makes its appearance and we start to allow vMotion across datacenters and across Clouds (in the clear?,) imagine the fun we'll have as we see attacks against vMotion protocols and VM state... </span> </li>
<p>
</p><li><span style="font-weight: bold;">EDoS</span> - Economic Denial of Sustainability - Covered previously <a href="http://rationalsecurity.typepad.com/blog/2009/01/a-couple-of-followups-on-my-edos-economic-denial-of-sustainability-concept.html">here</a>. </li>
<p>
</p></ul>
Adam mentioned that I might have considered that Botnets were a great example of a Cloud-based service and wrote a very cool piece about it on <a href="http://blogs.zdnet.com/security/?p=2883">ZDNet here</a>.</div><br /><div>I remembered after the fact that I wrote a related blog on the topic several months ago titled "<a href="http://rationalsecurity.typepad.com/blog/2008/11/cloud-computing-invented-by-criminals-secured-by.html">Cloud Computing: Invented by Criminals, Secured by ???</a>" as a rif on something Reuven Cohen wrote.</div><br /><div>/Hoff</div></div></div>
</content>


    <feedburner:origLink>http://rationalsecurity.typepad.com/blog/2009/03/more-on-clouds-botnets-meatclouds-cloudflux-leapfrog-edos-and-more.html</feedburner:origLink><feedburner:origLink>http://feedproxy.google.com/~r/typepad/nOnJ/~3/MWxCdjeYAfg/more-on-clouds-botnets-meatclouds-cloudflux-leapfrog-edos-and-more.html</feedburner:origLink></entry>
    <entry>
        <title>Source Boston - Video Interviews of Security Rockstars...</title>
        <link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/feedburner/rarz/~3/AkdHzs3jv_Q/source-boston-video-interviews-of-security-rockstars.html" />
        <link rel="replies" type="text/html" href="http://rationalsecurity.typepad.com/blog/2009/03/source-boston-video-interviews-of-security-rockstars.html" thr:count="2" thr:updated="2009-03-14T20:53:39-04:00" />
        <id>tag:typepad.com,2003:post-64065903</id>
        <published>2009-03-13T18:57:04-04:00</published>
        <updated>2009-03-16T13:17:24-04:00</updated>
        <summary>Source Boston has officially wound down, but I'm still on Cloud 9 (sorry) following the amazing sessions and interaction I had with my fellow attendees and speakers. My presentation was well received and with Marcus Ranum, Dan Geer, and Adam...</summary>
        <author>
            <name>beaker</name>
        </author>
        <category scheme="http://www.sixapart.com/ns/types#category" term="Security Conferences" />
        
        <category scheme="http://sixapart.com/ns/types#tag" term="Adam Shostack" />
        <category scheme="http://sixapart.com/ns/types#tag" term="Amrit Williams" />
        <category scheme="http://sixapart.com/ns/types#tag" term="Chris Hoff" />
        <category scheme="http://sixapart.com/ns/types#tag" term="Chris Weber" />
        <category scheme="http://sixapart.com/ns/types#tag" term="Chris Wysopal" />
        <category scheme="http://sixapart.com/ns/types#tag" term="Christien Rioux" />
        <category scheme="http://sixapart.com/ns/types#tag" term="Christofer Hoff" />
        <category scheme="http://sixapart.com/ns/types#tag" term="Dam Kaminsky" />
        <category scheme="http://sixapart.com/ns/types#tag" term="David Mortman" />
        <category scheme="http://sixapart.com/ns/types#tag" term="Jeremiah Grossman" />
        <category scheme="http://sixapart.com/ns/types#tag" term="Jose Nazario" />
        <category scheme="http://sixapart.com/ns/types#tag" term="Peter Kuper" />
        <category scheme="http://sixapart.com/ns/types#tag" term="Rational Security" />
        <category scheme="http://sixapart.com/ns/types#tag" term="Rational Survivability" />
        <category scheme="http://sixapart.com/ns/types#tag" term="Rob Cheyne" />
        <category scheme="http://sixapart.com/ns/types#tag" term="Source Boston" />
        <category scheme="http://sixapart.com/ns/types#tag" term="Source Conference" />
        <category scheme="http://sixapart.com/ns/types#tag" term="Zach Lanier" />
        
<content type="xhtml" xml:lang="en-US" xml:base="http://rationalsecurity.typepad.com/blog/">
<div xmlns="http://www.w3.org/1999/xhtml"><p><a href="http://rationalsecurity.typepad.com/.a/6a00d83451be3669e2011168f2dbe4970c-pi" style="float: left;"><img alt="Sourcelogo" border="0" class="at-xid-6a00d83451be3669e2011168f2dbe4970c " src="http://rationalsecurity.typepad.com/.a/6a00d83451be3669e2011168f2dbe4970c-800wi" style="margin: 0px 5px 5px 0px;" title="Sourcelogo" /></a>
 Source Boston has officially wound down, but I'm still on Cloud 9 (sorry) following the amazing sessions and interaction I had with my fellow attendees and speakers.</p><br /><div>My presentation was well received and with Marcus Ranum, Dan Geer, and Adam Shostack sitting six feet in front of me, I didn't choke as badly as I could have.  I had a ton of fun giving this first run preso and got a lot of great feedback and questions.<br /><br /><div>One of the most excellent things I got to do was spend some time walking about with Zach Lanier (<a href="http://www.twitter.com/quine">@quine</a> on Twitter) and interview many of the vendors and speakers extemporaneously on various subjects.</div><br /><div>I'll be updating this post with links to the interviews as I get them cleaned up and uploaded to YouTube...</div><br /><div>Here's a sampling of what you can expect:</div><div><ul>
<li>David Mortman, "I Can Haz Privacy"</li>
<li>Dmitry McKay, LogLogic</li>
<li>Chris Wysopal - Veracode </li>
<li>Peter Kuper - "Silver Linings"</li>
<li><a href="http://www.youtube.com/watch?v=k-bmmKC2T5M">Jose Nazario, Arbor, "Politically Motivated DDoS Attacks" </a></li>
<li>Christien Rioux, Source</li>
<li>Jeremiah Grossman, Whitehat Security, "Get Rich or Die Trying, Making Money the Black Hat Way"</li>
<li><span>Amrit Williams, BigFix, "The Economics of CyberCrime &amp; the Law of Malware Probability" </span> </li>
<li><span>Adam Shostack, Microsoft, "The Crisis In Information Security" </span> </li>
<li>Dan Kaminsky, IOActive, "DNS - Toward a Secure Infrastructure" </li>
<li><span>Chris Weber, Casaba Security, "Exploiting Unicode-Enabled Software" </span> </li>
<li>Rob Cheyne, SafeLight, "The End Of Our Rope: The On-Going Discussion Between Business &amp; Security" </li>
</ul>
<span>You'll laugh, you'll cry, you'll wonder why people gave me this task...</span></div><br /><div><span>But seriously, we discuss such mega-issues such as DDoS, Snuggies, Bedazzlers, Zombies and Estonian dissident groups (and that's in just ONE of the talks.) </span> <br /></div><br /><div>I think I've found something I absolutely LOVE doing -- vlogging (video blogging) and will try and do more of it.</div><br /><div>Check back for updates to the links over the weekend.</div><br /><div>/Hoff</div><br /></div></div>
</content>


    <feedburner:origLink>http://rationalsecurity.typepad.com/blog/2009/03/source-boston-video-interviews-of-security-rockstars.html</feedburner:origLink><feedburner:origLink>http://feedproxy.google.com/~r/typepad/nOnJ/~3/-Jxf3gBVOFc/source-boston-video-interviews-of-security-rockstars.html</feedburner:origLink></entry>
    <entry>
        <title>Oh Noes: We Can't Monitor/Protect Against Intra-VM Traffic!</title>
        <link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/feedburner/rarz/~3/dBh3LshEN1M/oh-noes-we-cant-monitorprotect-against-intra-vm-traffic.html" />
        <link rel="replies" type="text/html" href="http://rationalsecurity.typepad.com/blog/2009/03/oh-noes-we-cant-monitorprotect-against-intra-vm-traffic.html" thr:count="3" thr:updated="2009-03-12T23:08:49-04:00" />
        <id>tag:typepad.com,2003:post-63882217</id>
        <published>2009-03-10T09:39:32-04:00</published>
        <updated>2009-03-10T09:59:50-04:00</updated>
        <summary>I got a press release in my inbox this morning that made me cringe. It came from a vendor who produces a "purpose-built virtual firewall." The press release details a customer case study that I found typical of how security...</summary>
        <author>
            <name>beaker</name>
        </author>
        <category scheme="http://www.sixapart.com/ns/types#category" term="Virtualization" />
        
        <category scheme="http://sixapart.com/ns/types#tag" term="Chris Hoff" />
        <category scheme="http://sixapart.com/ns/types#tag" term="Christofer Hoff" />
        <category scheme="http://sixapart.com/ns/types#tag" term="Rational Security" />
        <category scheme="http://sixapart.com/ns/types#tag" term="Rational Survivability" />
        <category scheme="http://sixapart.com/ns/types#tag" term="VirtSec" />
        <category scheme="http://sixapart.com/ns/types#tag" term="Virtual Firewall" />
        <category scheme="http://sixapart.com/ns/types#tag" term="Virtual Networking" />
        <category scheme="http://sixapart.com/ns/types#tag" term="Virtual Security" />
        <category scheme="http://sixapart.com/ns/types#tag" term="Virtualization" />
        <category scheme="http://sixapart.com/ns/types#tag" term="Virtualization Security" />
        
<content type="xhtml" xml:lang="en-US" xml:base="http://rationalsecurity.typepad.com/blog/">
<div xmlns="http://www.w3.org/1999/xhtml"><p><span style="font-size: 13px; font-family: Arial; "><span style="font-family: Times; font-size: 16px; "><a href="http://rationalsecurity.typepad.com/.a/6a00d83451be3669e201127945372028a4-pi" style="float: left;"><img alt="Angryguy" class="at-xid-6a00d83451be3669e201127945372028a4 " src="http://rationalsecurity.typepad.com/.a/6a00d83451be3669e201127945372028a4-200wi" style="width: 200px; margin: 0px 5px 5px 0px;" /></a>
 </span>I got a press release in my inbox this morning that made me cringe.  It came from a vendor who produces a "purpose-built virtual firewall."</span></p><p><span><div><span style="font-size: 13px; font-family: 'Trebuchet MS'; ">The press release details a customer case study that I found typical of how security solutions are being marketed in the virtualization space today, which again is really more about visibility than pure "security" and preys mostly on poor planning and fundamental issues stemming from treating "security" like a band-aid instead of an element of enterprise architecture.</span></div><span style="font-size: 13px; font-family: 'Trebuchet MS'; "><br /></span><div><span style="font-size: 13px; font-family: 'Trebuchet MS'; ">When we start to cross the streams as to the realities of virtualization, the security implications thereof and making promises to solve problems with products which may or may not be deserving of investment given an assessment of risk, especially in today's trying economic climate, it makes me cranky.</span></div><span style="font-size: 13px; font-family: 'Trebuchet MS'; "><br /></span><div><span style="font-size: 13px; font-family: 'Trebuchet MS'; ">I'm just tiring of the mixing of metaphors in the marketing of these "solutions."</span></div><span style="font-size: 13px; font-family: 'Trebuchet MS'; "><br /></span><div><span style="font-size: 13px; font-family: 'Trebuchet MS'; ">I was specifically annoyed by a couple of statements in the press release and since I haven't had my coffee, I thought I'd point out a few to further underscore what I present in my </span><a href="http://rationalsecurity.typepad.com/blog/2008/08/complete-slides.html"><span style="font-size: 13px; font-family: 'Trebuchet MS'; ">Four Horsemen</span></a><span style="font-size: 13px; font-family: 'Trebuchet MS'; "> presentation regarding where we are in the solution continuum today.</span></div><span style="font-size: 13px; font-family: 'Trebuchet MS'; "><br /></span><div><span style="font-size: 13px; font-family: 'Trebuchet MS'; ">To wit:<br /></span><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><p><span style="font-size: 14px; line-height: normal; -webkit-border-horizontal-spacing: 2px; -webkit-border-vertical-spacing: 2px; "><font size="2" style="font-size: 11pt; "><span style="font-size: 13px; "><span style="font-style: italic;"><span style="font-weight: bold;"><span style="font-family: Arial;">[Customer]</span></span></span></span><span style="font-size: 13px; "><span style="font-style: italic;"><span style="font-weight: bold;"><span style="font-family: Arial;"> </span></span></span></span><span style="font-size: 13px; "><span style="font-style: italic;"><span style="font-weight: bold;"><span style="font-family: Arial;">has selected the [Vendor's] virtual firewall to secure its virtual environment and mitigate an attack before it could hit their network. </span></span></span></span></font></span></p></blockquote><span style="font-size: 15px; line-height: normal; -webkit-border-horizontal-spacing: 2px; -webkit-border-vertical-spacing: 2px; "><span style="font-size: 13px; line-height: 15px; -webkit-border-horizontal-spacing: 0px; -webkit-border-vertical-spacing: 0px; "><span style="line-height: 15px; -webkit-border-horizontal-spacing: 0px; -webkit-border-vertical-spacing: 0px; font-size: 13px; font-family: 'Trebuchet MS'; ">Given the fact that to get to a VM you generally have to (1) utilize the physical network and (2) transit the vSwitch in the VMM, the reality is that an attack has already "hit their network" long before it gets to the VM or the virtual firewall, at least given today's available offerings.  There is no magic security fairy dust that will mitigate an attack presciently.</span></span></span></div><div><span style="font-family: 'Trebuchet MS'; font-size: 13px; line-height: 15px;"><br /></span></div><div><span style="font-size: 15px; line-height: normal; -webkit-border-horizontal-spacing: 2px; -webkit-border-vertical-spacing: 2px; "><span style="font-size: 13px; line-height: 15px; -webkit-border-horizontal-spacing: 0px; -webkit-border-vertical-spacing: 0px; "><span style="line-height: 15px; -webkit-border-horizontal-spacing: 0px; -webkit-border-vertical-spacing: 0px; font-size: 13px; font-family: 'Trebuchet MS'; ">If you put VM's into production that are already infected, you have other problems to solve...</span><span style="line-height: 15px; -webkit-border-horizontal-spacing: 0px; -webkit-border-vertical-spacing: 0px; font-size: 13px; font-family: 'Trebuchet MS'; "><span style="font-size: 15px; line-height: normal; -webkit-border-horizontal-spacing: 2px; -webkit-border-vertical-spacing: 2px; " /></span></span></span></div><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><p><span style="font-size: 14px; line-height: normal; -webkit-border-horizontal-spacing: 2px; -webkit-border-vertical-spacing: 2px; "><span style="line-height: normal; -webkit-border-horizontal-spacing: 2px; -webkit-border-vertical-spacing: 2px; font-size: 13px; "><span style="font-style: italic;"><span style="font-weight: bold;"><span style="font-family: Arial;">“</span></span></span></span><span style="line-height: normal; -webkit-border-horizontal-spacing: 2px; -webkit-border-vertical-spacing: 2px; font-size: 13px; "><span style="font-style: italic;"><span style="font-weight: bold;"><span style="font-family: Arial;"><span /></span></span></span></span><font size="2" style="font-size: 11pt; "><span style="font-size: 13px; "><span style="font-style: italic;"><span style="font-weight: bold;"><span style="font-family: Arial;">After moving our production applications to a virtualized environment we realized that we lacked security; I had no visibility into what was going on between VMs and a virtual attack could take down our network,” said [Customer.]  “We sought the same level of security for our virtual environment that we had with our physical network.”</span></span></span></span></font></span></p></blockquote><span style="font-size: 15px; line-height: normal; -webkit-border-horizontal-spacing: 2px; -webkit-border-vertical-spacing: 2px; "><span style="line-height: 15px; -webkit-border-horizontal-spacing: 0px; -webkit-border-vertical-spacing: 0px; font-size: 13px; font-family: 'Trebuchet MS'; ">This indicates a lack of proper risk management and planning on the part of the [Customer.]  Further, it underscores an example I use in the Four Horsemen which concerns which tools in a multi-server physical deployment did the [Customer] use to monitor/protect in-line traffic between these physical machines? </span></span></span></p><p><span><span style="font-size: 15px; line-height: normal; -webkit-border-horizontal-spacing: 2px; -webkit-border-vertical-spacing: 2px; "><span style="line-height: 15px; -webkit-border-horizontal-spacing: 0px; -webkit-border-vertical-spacing: 0px; font-size: 13px; font-family: 'Trebuchet MS'; ">The {Customer] must have done this since the press release suggests they demand the "...same level of security for [their] virtual environment that [they] had with [their] physical network."</span></span><span style="font-size: 13px; font-family: 'Trebuchet MS'; "><br /></span><div><span style="font-family: 'Trebuchet MS'; font-size: 13px; line-height: 15px;"><br /></span></div><div><span style="font-size: 15px; line-height: normal; -webkit-border-horizontal-spacing: 2px; -webkit-border-vertical-spacing: 2px; "><span style="line-height: 15px; -webkit-border-horizontal-spacing: 0px; -webkit-border-vertical-spacing: 0px; font-size: 13px; font-family: 'Trebuchet MS'; ">Did the [Customer] have each physical server on it's own VLAN/subnet, isolated with firewalls?  Did he SPAN every single port to an IDS/IPS?  If not, what's the difference here?  The Hypervisor?  What protection mechanisms has the fancy virtual firewall put in place to protect it?  None.</span></span><div><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><p><span style="line-height: normal; -webkit-border-horizontal-spacing: 2px; -webkit-border-vertical-spacing: 2px; font-size: 13px; "><span style="font-style: italic; font-size: 14px; "><span style="font-weight: bold; font-size: 13px; font-family: Arial; ">[Customer] was increasingly concerned about the risks of virtual networks, which range from security policy violations such as mixing trusted and un-trusted systems to malware exploits that can propagate undetected within a virtual network. </span></span></span></p></blockquote><span style="font-size: 15px; line-height: normal; -webkit-border-horizontal-spacing: 2px; -webkit-border-vertical-spacing: 2px; "><span style="line-height: 15px; -webkit-border-horizontal-spacing: 0px; -webkit-border-vertical-spacing: 0px; font-size: 13px; font-family: 'Trebuchet MS'; ">Based upon the second paragraph above where the [Customer] admitted they put their virtualized environment into production without visibility or security, they clearly weren't that concerned with the risks.</span></span></div><div><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><p><span style="line-height: normal; -webkit-border-horizontal-spacing: 2px; -webkit-border-vertical-spacing: 2px; font-size: 13px; "><span style="font-style: italic;"><span style="font-family: Arial;"><span style="font-weight: bold;">A large amount of data center network traffic was moving between VMs and [Customer] had no visibility or control over the communication on the virtual network.</span></span></span></span></p></blockquote><span style="font-size: 13px; font-family: 'Trebuchet MS'; ">So if there were no security or visibility tools in place, how was it determined that traffic was moving between VM's?</span></div><div><span style="font-family: 'Trebuchet MS'; font-size: 13px;"><br /></span></div><div><span style="font-size: 13px; font-family: 'Trebuchet MS'; ">Does this mean that all the customer's VM's were in a single VLAN and not segmented? If not and vSwitch configurations via port groups and VLANs were configured around VM criticality, role or function, then they certainly had some insight into what was moving between VM's and the "data center," right?</span></div><span style="font-size: 13px; font-family: 'Trebuchet MS'; "><br /></span><div><span style="font-size: 13px; font-family: 'Trebuchet MS'; ">I must be confused. </span></div></div></span></p><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><p><span style="line-height: normal; -webkit-border-horizontal-spacing: 2px; -webkit-border-vertical-spacing: 2px; font-size: 13px; font-family: 'Trebuchet MS'; "><span style="font-style: italic;"><span style="font-family: Arial;"><span style="font-weight: bold;">[Customer's] traditional network security tools could not monitor, analyze or troubleshoot inter-VM traffic because communications between VMs on the same physical host never touch the traditional network</span></span>. </span></span></p></blockquote><p><span><div><div><span style="font-size: 15px; line-height: normal; -webkit-border-horizontal-spacing: 2px; -webkit-border-vertical-spacing: 2px; "><span style="line-height: 15px; -webkit-border-horizontal-spacing: 0px; -webkit-border-vertical-spacing: 0px; font-size: 13px; font-family: 'Trebuchet MS'; ">Assuming that the VM's weren't in a single VLAN/portgroup on a single vSwitch and instead were segmented via VLANs/subnets, then the only way to get traffic from VLAN/IP Subnet A to VLAN/IP Subnet B (and thus VM A to VM B in these VLAN's) is though a layer 3 routing process which generally means traffic exits the virtual network and hits the physical network...where said "traditional security tools" could see it.</span></span></div><span style="font-size: 13px; font-family: 'Trebuchet MS'; "><br /></span><div><span style="font-size: 13px; font-family: 'Trebuchet MS'; ">Of course, this doesn't help intra-VM traffic on the same portgroup/VLAN/vSwitch, but that's not what they pointed to above, but assuming they don't look at inter-machine traffic in their physical network on the same VLAN, again I ask what's the difference?</span></div></div></span></p><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><p><span style="line-height: normal; -webkit-border-horizontal-spacing: 2px; -webkit-border-vertical-spacing: 2px; font-size: 13px; "><span style="font-style: italic;"><span style="font-family: Arial;"><span style="font-weight: bold;">VMs were able to communicate with each other without observation or policy-based inspection and filtering, which left them highly vulnerable to malicious exploits. Additionally, worms and viruses could further spread among physical hosts via unintentional VMotion of an infected VM.</span></span></span></span></p></blockquote><p><span style="font-size: 15px; line-height: normal; -webkit-border-horizontal-spacing: 2px; -webkit-border-vertical-spacing: 2px; "><span style="line-height: 15px; -webkit-border-horizontal-spacing: 0px; -webkit-border-vertical-spacing: 0px; font-size: 13px; font-family: 'Trebuchet MS'; ">Back to my point above about how the [Customer] monitored traffic between physical hosts...if you don't do it in physical environments, why the fret in the virtual?</span></span></p><div><span style="font-size: 15px; line-height: normal; -webkit-border-horizontal-spacing: 2px; -webkit-border-vertical-spacing: 2px; "><span style="line-height: 15px; -webkit-border-horizontal-spacing: 0px; -webkit-border-vertical-spacing: 0px; font-size: 13px; font-family: 'Trebuchet MS'; ">Oh and "unintentional VMotion!?" ZOMG!  For a VM to be "infected," excluding direct physical access, wouldn't the threat vector be the network in the first place?  </span></span></div><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><p><span style="line-height: normal; -webkit-border-horizontal-spacing: 2px; -webkit-border-vertical-spacing: 2px; font-size: 13px; "><span style="font-style: italic;"><span style="font-family: Arial;"><span style="font-weight: bold;">The [Vendor] virtual firewall was specifically created to mitigate the risks of virtual networks, while maintaining the ROI of virtualization.</span></span></span></span></p></blockquote><div><span><div><div><div><span style="font-family: arial; font-size: 14px; line-height: normal; -webkit-border-horizontal-spacing: 2px; -webkit-border-vertical-spacing: 2px; "><div><span style="font-size: 15px;"><span style="line-height: 15px; -webkit-border-horizontal-spacing: 0px; -webkit-border-vertical-spacing: 0px; font-size: 13px; font-family: 'Trebuchet MS'; ">What "risks of virtual networks" does this product mitigate in the absence of vulnerability or clearly defined threats that aren't faced in the physical realm?  Let me tell you.  It goes back to the very valid claim that you get better visibility given the integration with the virtualization platform configuration managers to call attention to when CHANGE occurs.</span><span style="font-size: 13px; font-family: 'Trebuchet MS'; "><br /></span></span></div><div><span style="line-height: 15px; -webkit-border-horizontal-spacing: 0px; -webkit-border-vertical-spacing: 0px; font-size: 13px; font-family: 'Trebuchet MS'; "><br /></span></div><div><span style="line-height: 15px; -webkit-border-horizontal-spacing: 0px; -webkit-border-vertical-spacing: 0px; font-size: 13px; font-family: 'Trebuchet MS'; ">This is the real value of products like this from [Vendor.]  In the long run, the big boys who make mature firewalls and IPS products will get to harness API's like VMsafe and combined with the compartmentalization and segmentation capabilities of vShield Zones leaves a very short runway for products like this.</span></div><div><span style="line-height: 15px; -webkit-border-horizontal-spacing: 0px; -webkit-border-vertical-spacing: 0px; font-size: 13px; font-family: 'Trebuchet MS'; "><br /></span></div><div><span style="line-height: 15px; -webkit-border-horizontal-spacing: 0px; -webkit-border-vertical-spacing: 0px; font-size: 13px; font-family: 'Trebuchet MS'; ">I'm not suggesting that products like this from [Vendor] don't offer value and solve an immediate pain point. I'd even consider deploying them to solve very specific problems I might have, but then again, I know what problem I'd be trying to solve. ROI?  Oy.</span></div><div><span style="line-height: 15px; -webkit-border-horizontal-spacing: 0px; -webkit-border-vertical-spacing: 0px; font-size: 13px; font-family: 'Trebuchet MS'; "><br /></span></div><div><span style="line-height: 15px; -webkit-border-horizontal-spacing: 0px; -webkit-border-vertical-spacing: 0px; font-size: 13px; font-family: 'Trebuchet MS'; ">However, unlike the picture painted of the [Customer] above, I plan a little better and understand the impact virtualization has on my security posture and how that factors into my assessment and management of risk BEFORE I put it into production.  You should too.</span></div><span style="line-height: normal; -webkit-border-horizontal-spacing: 2px; -webkit-border-vertical-spacing: 2px; font-size: 13px; font-family: 'Trebuchet MS'; "><br /></span><div><span style="font-size: 13px; font-family: 'Trebuchet MS'; ">&lt;/rant&gt;</span></div><span style="line-height: normal; -webkit-border-horizontal-spacing: 2px; -webkit-border-vertical-spacing: 2px; font-size: 13px; font-family: 'Trebuchet MS'; "><br /></span><div><span style="font-size: 13px; font-family: Arial; "><span style="font-style: italic;">{Ed: I use 'intra-' instead of 'inter-' to reflect the "internal" passing of traffic between VM's using the vSwitch. Should traffic exit the vSwitch/host and hit the network as part of interchange between two VM's, I'd count this as 'inter-" VM traffic.}</span></span></div><div><span style="font-size: 15px;"><br /></span></div></span></div></div></div></span></div></div>
</content>


    <feedburner:origLink>http://rationalsecurity.typepad.com/blog/2009/03/oh-noes-we-cant-monitorprotect-against-intra-vm-traffic.html</feedburner:origLink><feedburner:origLink>http://feedproxy.google.com/~r/typepad/nOnJ/~3/c24MCQcKp9E/oh-noes-we-cant-monitorprotect-against-intra-vm-traffic.html</feedburner:origLink></entry>
    <entry>
        <title>Sun vs. Cisco?  I'm Getting My Popcorn...</title>
        <link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/feedburner/rarz/~3/p6hpita0pmA/sun-vs-cisco-im-getting-my-popcorn.html" />
        <link rel="replies" type="text/html" href="http://rationalsecurity.typepad.com/blog/2009/03/sun-vs-cisco-im-getting-my-popcorn.html" thr:count="5" thr:updated="2009-03-11T11:10:14-04:00" />
        <id>tag:typepad.com,2003:post-63863749</id>
        <published>2009-03-09T20:49:20-04:00</published>
        <updated>2009-03-09T22:16:10-04:00</updated>
        <summary>Scott Lowe wrote an interesting blog today wondering if Sun was preparing to take on Cisco in the virtualization space, referencing the development of virtualized networking functionality featuring the novel combination of commodity hardware and open source software to unseat...</summary>
        <author>
            <name>beaker</name>
        </author>
        <category scheme="http://www.sixapart.com/ns/types#category" term="Virtualization" />
        
        <category scheme="http://sixapart.com/ns/types#tag" term="Chris Hoff" />
        <category scheme="http://sixapart.com/ns/types#tag" term="Christofer Hoff" />
        <category scheme="http://sixapart.com/ns/types#tag" term="Christopher Hoff" />
        <category scheme="http://sixapart.com/ns/types#tag" term="Cisco" />
        <category scheme="http://sixapart.com/ns/types#tag" term="HP" />
        <category scheme="http://sixapart.com/ns/types#tag" term="IBM" />
        <category scheme="http://sixapart.com/ns/types#tag" term="Microsoft" />
        <category scheme="http://sixapart.com/ns/types#tag" term="Rational Security" />
        <category scheme="http://sixapart.com/ns/types#tag" term="Rational Survivability" />
        <category scheme="http://sixapart.com/ns/types#tag" term="Scott Lowe" />
        <category scheme="http://sixapart.com/ns/types#tag" term="Sun" />
        <category scheme="http://sixapart.com/ns/types#tag" term="Unified Computing" />
        
<content type="xhtml" xml:lang="en-US" xml:base="http://rationalsecurity.typepad.com/blog/">
<div xmlns="http://www.w3.org/1999/xhtml"><p><a href="http://rationalsecurity.typepad.com/.a/6a00d83451be3669e2011279443eee28a4-popup" onclick="window.open( this.href, '_blank', 'width=640,height=480,scrollbars=no,resizable=no,toolbar=no,directories=no,location=no,menubar=no,status=no,left=0,top=0' ); return false" style="float: right;"><img alt="Popcorn" class="at-xid-6a00d83451be3669e2011279443eee28a4 " src="http://rationalsecurity.typepad.com/.a/6a00d83451be3669e2011279443eee28a4-200wi" style="width: 200px; margin: 0px 0px 5px 5px;" /></a>
 Scott Lowe wrote an interesting blog today wondering if <a href="http://blog.scottlowe.org/2009/03/09/is-sun-preparing-to-take-on-cisco/">Sun was preparing to take on Cisco in the virtualization space</a>, referencing the development of virtualized networking functionality featuring the novel combination of commodity hardware and open source software to unseat the Jolly Green Giant:</p><div><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><p><span style="color: #404040; font-family: Verdana; font-size: 12px; line-height: 16px; ">A while back in <a href="http://blog.scottlowe.org/2009/01/07/virtualization-short-take-25/" style="text-decoration: none; color: #006a80; border-bottom-width: 1px; border-bottom-style: solid; border-bottom-color: #cfe2e5; ">Virtualization Short Take #25</a> I briefly mentioned Sun’s Crossbow network virtualization software, which brings new possibilities to the Solaris networking world. Not being a Solaris expert, it was hard for me at the time to really understand why Solaris fans were so excited about it; since then, though, I’ve come to understand that Crossbow brings to Solaris the same kind of full-blown virtual network interfaces and such that I use daily with VMware ESX. Now I’m beginning to understand why people are so thrilled!</span></p></blockquote><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><p><span style="color: #404040; font-family: Verdana; font-size: 12px; line-height: 16px; ">In any case, an astute reader picked up on my mention of Crossbow and pointed me to <a href="http://blogs.sun.com/jonathan/entry/three_things_on_sun_in" style="text-decoration: none; color: #006a80; border-bottom-width: 1px; border-bottom-style: solid; border-bottom-color: #cfe2e5; ">this article</a> by Jonathan Schwartz of Sun, and in particular this phrase:</span></p></blockquote><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><p><span style="color: #808080; font-family: Verdana; font-size: 12px; line-height: 16px; ">You’re going to see an accelerating series of announcements over the coming year, from amplifying our open source storage offerings, to building out an equivalent portfolio of products in the networking space…</span></p></blockquote></blockquote><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><p><span style="color: #404040; font-family: Verdana; font-size: 12px; line-height: 16px; ">That seemingly innocuous mention was then coupled with <a href="http://blogs.sun.com/sunay/entry/crossbow_enables_an_open_networking" style="text-decoration: none; color: #006a80; border-bottom-width: 1px; border-bottom-style: solid; border-bottom-color: #cfe2e5; ">this blog post</a> and the result was this question: is Sun preparing to take on Cisco? Is Sun getting ready to try to use commodity hardware and open source software to penetrate the networking market in the same way that they are using commodity hardware and open source software to try to further penetrate the storage market with their <a href="http://www.sun.com/storagetek/open.jsp" style="text-decoration: none; color: #006a80; border-bottom-width: 1px; border-bottom-style: solid; border-bottom-color: #cfe2e5; ">open storage products</a> (in particular, the 7000 series)?</span></p></blockquote><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><p><span style="color: #404040; font-family: Verdana; font-size: 12px; line-height: 16px; ">It’s an interesting thought, to say the least. Going up against Cisco is a bold move, though, and I question Sun’s staying power in that sort of battle. Of course, <span style="font-weight: bold;">with Cisco potentially distracted by the swirling rumors regarding the networking giant’s entry into the server market, now may be the best time to make this move.</span></span></p></blockquote><span style="color: #404040; font-family: Verdana; font-size: 12px; font-weight: bold; line-height: 16px;"><span style="color: #000000; font-family: 'Trebuchet MS'; font-size: 13px; font-weight: normal; line-height: 15px; ">It's really the last paragraph that is of interest to me, specifically the boldfaced sentence I highlighted.  I think the "rumors" have pretty much been substantiated by the mainstream press, so let's assume "California" is going to happen.</span><br /></span><br /><div>Let's make a couple of things really, really clear:</div><div><ol>
<li>I don't know how anyone can think that Cisco is "distracted" by bringing to market the logical extension of virtualized infrastructure -- the compute function -- as anything other than a shrewd business decision to offer a complete end-to-end solution to customers.  I talked about it here in blog post titled "<a href="http://rationalsecurity.typepad.com/blog/2009/02/cisco-is-not-getting-into-the-server-business.html">Cisco Is NOT Getting Into the Server Business...</a>" This is an Enterprise Architecture play, pure and simple.</li>
<p>
</p><li>Honestly, if we're discussing commoditization, a server is a server is a server, whether it's in a blade form factor or not, and it's not like Cisco has to worry about building things from scratch. The availability of OEM/ODM components (raw or otherwise) means they don't have to start from scratch.  Oh yes, I know HP spent a bazillion dollars on C-Class fan engineering and IBM's BCHT is teh awesome and...</li>
<p>
</p><li>The whole game is Unified Computing; bringing together enterprise class compute, network and storage as a solution with integrated virtualization, management and intelligence; you take the biggest pain point out of the equation -- integration -- and you drive down cost while increasing utility, agility and efficiency.</li>
<p>
</p><li>If you look at what "California" is slated to deliver it's hard to see how Sun would compete: A blade based chassis with integrated Nexus converged networking/storage, integrated virtualization from VMware (with Nexus/VN-Link,) and management from BMC.  You know, Enterprise stuff, not integration hodge podge. </li>
<p>
</p></ol>
So, I ask, does this look like a distraction to you? <br /></div><br /><div>I'm not knocking Sun (or Scott to be clear,) but if I were they, I'd be much more worried about HP or IBM or even Microsoft and Redhat.</div><br /><div>I'm grabbing my popcorn, but this battle might be over before the kernels (ha!) start popping.</div><br /><div>/Hoff</div></div></div>
</content>


    <feedburner:origLink>http://rationalsecurity.typepad.com/blog/2009/03/sun-vs-cisco-im-getting-my-popcorn.html</feedburner:origLink><feedburner:origLink>http://feedproxy.google.com/~r/typepad/nOnJ/~3/Pj1ZjNwGcO0/sun-vs-cisco-im-getting-my-popcorn.html</feedburner:origLink></entry>
    <entry>
        <title>Cloud Computing Not Ready For Prime Time?</title>
        <link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/feedburner/rarz/~3/F-GFvuurldg/cloud-computing-not-ready-for-prime-time.html" />
        <link rel="replies" type="text/html" href="http://rationalsecurity.typepad.com/blog/2009/03/cloud-computing-not-ready-for-prime-time.html" thr:count="4" thr:updated="2009-03-11T09:46:24-04:00" />
        <id>tag:typepad.com,2003:post-63835795</id>
        <published>2009-03-09T10:55:37-04:00</published>
        <updated>2009-03-09T11:11:25-04:00</updated>
        <summary>I just read another in a never-ending series of articles that takes a polarized view of Cloud Computing and its readiness for critical applications and data. In the ComputerWorld article titled "Cloud computing not ready for critical apps,", Craig Steadman...</summary>
        <author>
            <name>beaker</name>
        </author>
        <category scheme="http://www.sixapart.com/ns/types#category" term="Cloud Computing" />
        <category scheme="http://www.sixapart.com/ns/types#category" term="Cloud Security" />
        
        <category scheme="http://sixapart.com/ns/types#tag" term="Chris Hoff" />
        <category scheme="http://sixapart.com/ns/types#tag" term="Christofer Hoff" />
        <category scheme="http://sixapart.com/ns/types#tag" term="Christopher Hoff" />
        <category scheme="http://sixapart.com/ns/types#tag" term="Cloud Computing" />
        <category scheme="http://sixapart.com/ns/types#tag" term="Cloud Security" />
        <category scheme="http://sixapart.com/ns/types#tag" term="ComputerWorld" />
        <category scheme="http://sixapart.com/ns/types#tag" term="Pixily" />
        <category scheme="http://sixapart.com/ns/types#tag" term="Rational Security" />
        <category scheme="http://sixapart.com/ns/types#tag" term="Rational Survivabiity" />
        
<content type="xhtml" xml:lang="en-US" xml:base="http://rationalsecurity.typepad.com/blog/">
<div xmlns="http://www.w3.org/1999/xhtml"><p>I just read another in a never-ending series of articles that takes a polarized view of Cloud Computing and its readiness for critical applications and data.</p><div><div>In the ComputerWorld article titled "<a href="http://www.computerworld.com/action/article.do?command=viewArticleBasic&amp;taxonomyName=knowledge_center&amp;articleId=335283&amp;taxonomyId=1&amp;intsrc=kc_top">Cloud computing not ready for critical apps,</a>", Craig Steadman and Patrick Thibodeau present some very telling quotes from CIO's of some large enterprises regarding their reticence toward utilizing "Cloud Computing" and it's readiness for their mission critical needs.</div><br /><div>The reasons are actually quite compelling, and I speak to them (and more) in my latest Cloud Computing presentation which I am giving at <a href="http://www.sourceconference.com/index.php/source-boston-2009/boston-2009-sessions">Source Boston</a> this week:</div><center><br /><div><a href="http://rationalsecurity.typepad.com/.a/6a00d83451be3669e2011168cdf134970c-pi" style="display: inline;"><img alt="Frogs-Draft.056" class="at-xid-6a00d83451be3669e2011168cdf134970c " src="http://rationalsecurity.typepad.com/.a/6a00d83451be3669e2011168cdf134970c-500wi" /></a>
 <br /></div><br /></center><div>Reliability, availability and manageability are all potential show-stoppers for the CIO's in this article, but these are issues of economic and adoptive context that don't present the entire picture. </div><br /><div>What do I mean?</div><br /><div>At the <a href="http://www.slacloudgroup.com/">New England Cloud Computing Users' Group</a>, a Cloud-based <span style="font-weight: bold;"><span style="font-style: italic;">startup</span></span> called <a href="http://www.pixily.com/">Pixily</a> presented on their use of Amazon's AWS services. They painted an eye-opening business case which detailed the agility and tremendous cost savings that the "Cloud" offers.  "The Cloud" provides them with reduced time-to-market, no up-front capital expenditures and allows them to focus on their core competencies. </div><br /><div>All awesome stuff.</div><br /><div>I asked them about how their use of AWS and what amounted to a sole-source service provider did to their disaster recovery, redundancy/resiliency and risk management processes.  They had to admit that the day they went live with feature coverage on the front page of several newspapers also happened to be the day that Amazon suffered an 8 hour outage, and thus, so did they.</div><br /><div><span style="font-weight: bold;">Now, for a startup, the benefits often outweigh the risks associated for downtime and vendor lock-in. For an established enterprise with cutthroat service levels, regulatory pressures and demanding customers who won't/can't tolerate outages, this is not the case.</span></div><br /><div>Today we're suffering from issues surrounding the fact that emerging offerings in Cloud Computing are simply not mature if what you're looking for involves the holistic and cohesive management, reliability, resilience and transparency across suppliers of Cloud services.</div><br /><div>We will get there as adoption increases and businesses start to lean on providers to create and adopt standards that answer the issues above, but today if you're an enterprise who needs five 9's, you may come to the same conclusion as the CIO's in the CW article.  If you're an SME/SMB/Startup, you may find everything you need in the Cloud.</div><br /><div>It's important, however, to keep a balanced, realistic and contextual perspective when addressing Cloud Computing and its readiness -- and yours -- for critical applications.  Polarizing the discussion to one hyperbolic end or the other is not really helpful.</div><br /><div>/Hoff</div><br /></div></div>
</content>


    <feedburner:origLink>http://rationalsecurity.typepad.com/blog/2009/03/cloud-computing-not-ready-for-prime-time.html</feedburner:origLink><feedburner:origLink>http://feedproxy.google.com/~r/typepad/nOnJ/~3/Fi3bmhjGp1w/cloud-computing-not-ready-for-prime-time.html</feedburner:origLink></entry>
    <entry>
        <title>If Virtualization is a Religion, Does That Make Cloud a Cult?</title>
        <link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/feedburner/rarz/~3/VFPqPcv_PHU/if-virtualization-is-a-religion-does-that-make-cloud-a-cult.html" />
        <link rel="replies" type="text/html" href="http://rationalsecurity.typepad.com/blog/2009/03/if-virtualization-is-a-religion-does-that-make-cloud-a-cult.html" thr:count="0" />
        <id>tag:typepad.com,2003:post-63831595</id>
        <published>2009-03-09T09:20:16-04:00</published>
        <updated>2009-03-09T10:07:44-04:00</updated>
        <summary>I had just finished reading Virtual Gipsy's post titled "VMware as religion" when my RSS reader featured a referential post from VM/ETC's Rich titled "vTheology: the study of virtualization as religion." While I appreciated the humor surrounding the topic, I...</summary>
        <author>
            <name>beaker</name>
        </author>
        <category scheme="http://www.sixapart.com/ns/types#category" term="Cloud Computing" />
        <category scheme="http://www.sixapart.com/ns/types#category" term="Cloud Security" />
        <category scheme="http://www.sixapart.com/ns/types#category" term="Virtualization" />
        
        <category scheme="http://sixapart.com/ns/types#tag" term="Chris Hoff" />
        <category scheme="http://sixapart.com/ns/types#tag" term="Christofer Hoff" />
        <category scheme="http://sixapart.com/ns/types#tag" term="Cloud" />
        <category scheme="http://sixapart.com/ns/types#tag" term="Cloud Computing" />
        <category scheme="http://sixapart.com/ns/types#tag" term="Cloud Cult" />
        <category scheme="http://sixapart.com/ns/types#tag" term="Rational Security" />
        <category scheme="http://sixapart.com/ns/types#tag" term="Rational Survivability" />
        <category scheme="http://sixapart.com/ns/types#tag" term="Virtual Gypsy" />
        <category scheme="http://sixapart.com/ns/types#tag" term="Virtualization" />
        <category scheme="http://sixapart.com/ns/types#tag" term="VM/ETC" />
        
<content type="xhtml" xml:lang="en-US" xml:base="http://rationalsecurity.typepad.com/blog/">
<div xmlns="http://www.w3.org/1999/xhtml"><p><a href="http://rationalsecurity.typepad.com/.a/6a00d83451be3669e2011168cdd265970c-pi" style="float: right;"><img alt="Skyfalling-angled" class="at-xid-6a00d83451be3669e2011168cdd265970c " src="http://rationalsecurity.typepad.com/.a/6a00d83451be3669e2011168cdd265970c-150wi" style="width: 150px; margin: 0px 0px 5px 5px;" /></a>
 I had just finished reading Virtual Gipsy's post titled "<a href="http://www.virtualgipsy.com/2009/03/vmware-as-religion/">VMware as religion</a>" when my RSS reader featured a referential post from VM/ETC's Rich titled "<a href="http://vmetc.com/2009/03/08/vtheology-the-study-of-virtualization-as-a-religion/">vTheology: the study of virtualization as religion.</a>"</p><div>While I appreciated the humor surrounding the topic, I try never to mix friends politics, and religion* so I'll not wade into the deep end on this one except to suggest what my title asks: </div><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><p><span style="font-weight: bold;">If virtualization is a religion, does that make cloud a cult?</span></p></blockquote><div>If so, to whom do I send my tidings?  Who is the Cardinal of the Cloud?  The Pope of PaaS?  The Shaman of Service?</div><br /><div>...and where's my <a href="http://en.wikipedia.org/wiki/Heaven's_Gate_(cult)">phenobarbital, vodka and purple cape?</a></div><br /><div>/Hoff</div><br /><div>*...and truth be told, I'm not feeling particularly witty this morning.</div></div>
</content>


    <feedburner:origLink>http://rationalsecurity.typepad.com/blog/2009/03/if-virtualization-is-a-religion-does-that-make-cloud-a-cult.html</feedburner:origLink><feedburner:origLink>http://feedproxy.google.com/~r/typepad/nOnJ/~3/LUVMlkE1B6U/if-virtualization-is-a-religion-does-that-make-cloud-a-cult.html</feedburner:origLink></entry>
    <entry>
        <title>Incomplete Thought: Offensive Computing - The Empire Strikes Back</title>
        <link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/feedburner/rarz/~3/fM4Damz7qe0/incomplete-thought-offensive-computing-the-empire-strikes-back.html" />
        <link rel="replies" type="text/html" href="http://rationalsecurity.typepad.com/blog/2009/03/incomplete-thought-offensive-computing-the-empire-strikes-back.html" thr:count="10" thr:updated="2009-03-09T15:14:59-04:00" />
        <id>tag:typepad.com,2003:post-63687555</id>
        <published>2009-03-05T11:23:42-05:00</published>
        <updated>2009-03-05T11:33:29-05:00</updated>
        <summary>Yesterday at IANS, Greg Shipley gave a great keynote that focused on a lot of things we do today in InfoSec that aren't necessarily as effective as they should be. Greg called for a change in our behavior as a...</summary>
        <author>
            <name>beaker</name>
        </author>
        <category scheme="http://www.sixapart.com/ns/types#category" term="Offensive Computing" />
        
        <category scheme="http://sixapart.com/ns/types#tag" term="Chris Hoff" />
        <category scheme="http://sixapart.com/ns/types#tag" term="Christofer Hoff" />
        <category scheme="http://sixapart.com/ns/types#tag" term="Greg Shipley" />
        <category scheme="http://sixapart.com/ns/types#tag" term="IANS" />
        <category scheme="http://sixapart.com/ns/types#tag" term="Marcus Ranum" />
        <category scheme="http://sixapart.com/ns/types#tag" term="Offensive Computing" />
        <category scheme="http://sixapart.com/ns/types#tag" term="Rational Security" />
        <category scheme="http://sixapart.com/ns/types#tag" term="Rational Survivability" />
        <category scheme="http://sixapart.com/ns/types#tag" term="Richard Bejtlich" />
        <category scheme="http://sixapart.com/ns/types#tag" term="Rocky DeStefano" />
        
<content type="xhtml" xml:lang="en-US" xml:base="http://rationalsecurity.typepad.com/blog/">
<div xmlns="http://www.w3.org/1999/xhtml"><p><a href="http://rationalsecurity.typepad.com/.a/6a00d83451be3669e2011168c33451970c-popup" onclick="window.open( this.href, '_blank', 'width=640,height=480,scrollbars=no,resizable=no,toolbar=no,directories=no,location=no,menubar=no,status=no,left=0,top=0' ); return false" style="float: left;"><img alt="Failure" class="at-xid-6a00d83451be3669e2011168c33451970c " src="http://rationalsecurity.typepad.com/.a/6a00d83451be3669e2011168c33451970c-150wi" style="width: 150px; margin: 0px 5px 5px 0px;" /></a>
 Yesterday at <a href="http://www.ianetsec.com">IANS</a>, Greg Shipley gave a great keynote that focused on a lot of things we do today in InfoSec that aren't necessarily as effective as they should be. Greg called for a change in our behavior as a community to address the gaps we have.</p><div>In the Q&amp;A section, it occurred to me that for the sake of argument, I would ask Greg about his thoughts on changing our behavior and position in dealing with security and our adversaries by positing that instead of always playing defense, we should play some offense.</div><br /><div>I didn't constrain what I meant by "offense" other to suggest that it could include "active countermeasures," but what is obvious is that people immediately throw up walls around being "offensive" without spending much time defining what it actually means.<br /></div><br /><div>I've <a href="http://rationalsecurity.typepad.com/blog/offensive_computing/">written</a> and spoken about this before, but it's a rather contentious issue. It gets shelved pretty quickly by most but it really shouldn't in my opinion.<br /></div><br /><div>In a follow-on discussion after the keynote, Marcus Ranum, Richard Bejtlich, Rocky DeStefano and I were standing around shooting the, uh, stuff, when I brought this up again.</div><br /><div>We had a really interesting dialog wherein we explored what "offensive computing" meant to each of us and it was clear that simply playing defense alone would never allow us to do anything more than spend money and hope.</div><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><p><span style="font-weight: bold;">There's not been a war yet that has been won with defense alone, so why do we expect we can win this one by simply piling on more barbed wire when the enemy is dropping smart bombs? This is the definition of insanity and a behavior that we don't talk about changing.<br /><br />"Don't spend money on AV because it's not effective" is an interesting behavioral change from the perspective of how you invest. Don't lay down and take it up the assets by only playing defense is another.</span></p></blockquote><div>I'm being intentionally vague, obtuse and non-specific when it comes to defining what I mean by "offensive," but we're at a point in time where at a minimum we have the technology and capability to add a little "offense" to our defense.  </div><br /><div><span style="font-weight: bold;">You want a change in behavior?  How about not playing the victim?</span></div><br /><div>What are your thoughts on "offensive computing?"  </div><br /><div>/Hoff</div></div>
</content>


    <feedburner:origLink>http://rationalsecurity.typepad.com/blog/2009/03/incomplete-thought-offensive-computing-the-empire-strikes-back.html</feedburner:origLink><feedburner:origLink>http://feedproxy.google.com/~r/typepad/nOnJ/~3/YTR-rk-zHvc/incomplete-thought-offensive-computing-the-empire-strikes-back.html</feedburner:origLink></entry>
    <entry>
        <title>Ron Popeil and Cloud Computing In Poetic Review...</title>
        <link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/feedburner/rarz/~3/Ml74uz0m6gY/ron-popeil-and-cloud-computing-in-poetic-review.html" />
        <link rel="replies" type="text/html" href="http://rationalsecurity.typepad.com/blog/2009/02/ron-popeil-and-cloud-computing-in-poetic-review.html" thr:count="0" />
        <id>tag:typepad.com,2003:post-63437823</id>
        <published>2009-02-27T15:34:43-05:00</published>
        <updated>2009-02-27T16:13:41-05:00</updated>
        <summary>The uptake of computing using the cloud, would make the king of all marketeers -- Ron Popeil -- proud He's the guy who came out with the canned spray on hair, the oven you set and forget without care He...</summary>
        <author>
            <name>beaker</name>
        </author>
        <category scheme="http://www.sixapart.com/ns/types#category" term="Cloud Computing" />
        <category scheme="http://www.sixapart.com/ns/types#category" term="Cloud Security" />
        <category scheme="http://www.sixapart.com/ns/types#category" term="Jackassery" />
        <category scheme="http://www.sixapart.com/ns/types#category" term="Poetry" />
        
        <category scheme="http://sixapart.com/ns/types#tag" term="Chris Hoff" />
        <category scheme="http://sixapart.com/ns/types#tag" term="Christofer Hoff" />
        <category scheme="http://sixapart.com/ns/types#tag" term="Cloud" />
        <category scheme="http://sixapart.com/ns/types#tag" term="Cloud Computing" />
        <category scheme="http://sixapart.com/ns/types#tag" term="Cloud Poetry" />
        <category scheme="http://sixapart.com/ns/types#tag" term="Cloud Security" />
        <category scheme="http://sixapart.com/ns/types#tag" term="Rational Security" />
        <category scheme="http://sixapart.com/ns/types#tag" term="Rational Survivability" />
        
<content type="xhtml" xml:lang="en-US" xml:base="http://rationalsecurity.typepad.com/blog/">
<div xmlns="http://www.w3.org/1999/xhtml"><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><p><a href="http://rationalsecurity.typepad.com/.a/6a00d83451be3669e20111689d54c5970c-popup" onclick="window.open( this.href, '_blank', 'width=640,height=480,scrollbars=no,resizable=no,toolbar=no,directories=no,location=no,menubar=no,status=no,left=0,top=0' ); return false" style="float: right;"><img alt="Popeil" class="at-xid-6a00d83451be3669e20111689d54c5970c " src="http://rationalsecurity.typepad.com/.a/6a00d83451be3669e20111689d54c5970c-200wi" style="width: 200px; margin: 0px 0px 5px 5px;" /></a>
 </p><p><span style="font-family: Helvetica; font-size: 12px; line-height: normal; ">The uptake of computing</span><br /><span style="font-family: Helvetica; font-size: 12px; line-height: normal; ">using the cloud,</span><br /><span style="font-family: Helvetica; font-size: 12px; line-height: normal; ">would make the king of all marketeers</span><br /><span style="font-family: Helvetica; font-size: 12px; line-height: normal; ">-- Ron Popeil -- proud</span></p></blockquote><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><p><span style="font-family: Helvetica; font-size: 12px; line-height: normal; ">He's the guy who came out</span><br /><span style="font-family: Helvetica; font-size: 12px; line-height: normal; ">with the canned spray on hair,</span><br /><span style="font-family: Helvetica; font-size: 12px; line-height: normal; ">the oven you set and forget</span><br /><span style="font-family: Helvetica; font-size: 12px; line-height: normal; ">without care</span></p></blockquote></blockquote>
<p /><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><p><span style="font-family: Helvetica; font-size: 12px; line-height: normal; ">He had the bass fishing rod</span><br /><span style="font-family: Helvetica; font-size: 12px; line-height: normal; ">you could fit in your pocket,</span><br /><span style="font-family: Helvetica; font-size: 12px; line-height: normal; ">the Veg-O-Matic appliance</span><br /><span style="font-family: Helvetica; font-size: 12px; line-height: normal; ">with which you could chop it</span></p></blockquote></blockquote></blockquote>
<p /><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><p><span style="font-family: Helvetica; font-size: 12px; line-height: normal; ">Mr. Microphone, it seems, </span><br /><span style="font-family: Helvetica; font-size: 12px; line-height: normal; ">was ahead of its time</span><br /><span style="font-family: Helvetica; font-size: 12px; line-height: normal; ">Karaoke meets Facebook</span><br /><span style="font-family: Helvetica; font-size: 12px; line-height: normal; ">Oh, how divine!</span></p></blockquote></blockquote></blockquote></blockquote>
<p /><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><p><span style="font-family: Helvetica; font-size: 12px; line-height: normal; ">The smokeless ashtray,</span><br /><span style="font-family: Helvetica; font-size: 12px; line-height: normal; ">the Cap Snaffler, drain buster</span><br /><span style="font-family: Helvetica; font-size: 12px; line-height: normal; ">selling you all of the crap</span><br /><span style="font-family: Helvetica; font-size: 12px; line-height: normal; ">Infomercials could muster</span></p></blockquote></blockquote></blockquote></blockquote></blockquote>
<p /><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><p><span style="font-family: Helvetica; font-size: 12px; line-height: normal; ">His inventions solved problems</span><br /><span style="font-family: Helvetica; font-size: 12px; line-height: normal; ">some common, some new</span><br /><span style="font-family: Helvetica; font-size: 12px; line-height: normal; ">If you ordered them quickly</span><br /><span style="font-family: Helvetica; font-size: 12px; line-height: normal; ">he might send you two!</span></p></blockquote></blockquote></blockquote></blockquote>
<p /><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><p><span style="font-family: Helvetica; font-size: 12px; line-height: normal; ">Back to the Cloud</span><br /><span style="font-family: Helvetica; font-size: 12px; line-height: normal; ">and how it's related</span><br /><span style="font-family: Helvetica; font-size: 12px; line-height: normal; ">to the many wonders</span><br /><span style="font-family: Helvetica; font-size: 12px; line-height: normal; ">that Sir Ron has created</span></p></blockquote></blockquote></blockquote>
<p /><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><p><span style="font-family: Helvetica; font-size: 12px; line-height: normal; ">The cloud fulfills promises</span><br /><span style="font-family: Helvetica; font-size: 12px; line-height: normal; ">that IT has made:</span><br /><span style="font-family: Helvetica; font-size: 12px; line-height: normal; ">agility, better service</span><br /><span style="font-family: Helvetica; font-size: 12px; line-height: normal; ">at a lower pay grade</span></p></blockquote></blockquote>
<p /><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><p><span style="font-family: Helvetica; font-size: 12px; line-height: normal; ">You can scale up, scale down</span><br /><span style="font-family: Helvetica; font-size: 12px; line-height: normal; ">pay for just what you use</span><br /><span style="font-family: Helvetica; font-size: 12px; line-height: normal; ">Elastic infrastructure</span><br /><span style="font-family: Helvetica; font-size: 12px; line-height: normal; ">what you get's what you choose</span></p></blockquote>
<p style="margin: 0.0px 0.0px 0.0px 0.0px; font: 12.0px Helvetica">We've got public and private,</p>
<p style="margin: 0.0px 0.0px 0.0px 0.0px; font: 12.0px Helvetica">outside and in,</p>
<p style="margin: 0.0px 0.0px 0.0px 0.0px; font: 12.0px Helvetica">on-premise, off-premise</p>
<p style="margin: 0.0px 0.0px 0.0px 0.0px; font: 12.0px Helvetica">thick platforms or thin</p>
<p /><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><p><span style="font-family: Helvetica; font-size: 12px; line-height: normal; ">The offerings are flooding</span><br /><span style="font-family: Helvetica; font-size: 12px; line-height: normal; ">the wires en masse</span><br /><span style="font-family: Helvetica; font-size: 12px; line-height: normal; ">Everything, it now seems,</span><br /><span style="font-family: Helvetica; font-size: 12px; line-height: normal; ">is some sort of *aaS</span></p></blockquote>
<p /><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><p><span style="font-family: Helvetica; font-size: 12px; line-height: normal; ">You've got infrastructure,</span><br /><span style="font-family: Helvetica; font-size: 12px; line-height: normal; ">platforms, software and storage.</span><br /><span style="font-family: Helvetica; font-size: 12px; line-height: normal; ">Integration, SOA </span><br /><span style="font-family: Helvetica; font-size: 12px; line-height: normal; ">with full vendor whoreage</span></p></blockquote></blockquote>
<p /><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><p><span style="font-family: Helvetica; font-size: 12px; line-height: normal; ">Some folks equate</span><br /><span style="font-family: Helvetica; font-size: 12px; line-height: normal; ">virtualization with cloud</span><br /><span style="font-family: Helvetica; font-size: 12px; line-height: normal; ">The platform providers</span><br /><span style="font-family: Helvetica; font-size: 12px; line-height: normal; ">shout this vision out loud</span></p></blockquote></blockquote></blockquote>
<p /><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><p><span style="font-family: Helvetica; font-size: 12px; line-height: normal; ">'Course the OS contingent</span><br /><span style="font-family: Helvetica; font-size: 12px; line-height: normal; ">has something to say</span><br /><span style="font-family: Helvetica; font-size: 12px; line-height: normal; ">that cloud and virt</span><br /><span style="font-family: Helvetica; font-size: 12px; line-height: normal; ">is part of their play</span></p></blockquote></blockquote></blockquote></blockquote>
<p /><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><p><span style="font-family: Helvetica; font-size: 12px; line-height: normal; ">However you see it,</span><br /><span style="font-family: Helvetica; font-size: 12px; line-height: normal; ">and whatever its form</span><br /><span style="font-family: Helvetica; font-size: 12px; line-height: normal; ">the Cloud's getting bigger</span><br /><span style="font-family: Helvetica; font-size: 12px; line-height: normal; ">it's starting to storm</span></p></blockquote></blockquote></blockquote></blockquote></blockquote>
<p /><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><p><span style="font-family: Helvetica; font-size: 12px; line-height: normal; ">Raining down on us all</span><br /><span style="font-family: Helvetica; font-size: 12px; line-height: normal; ">is computational glory</span><br /><span style="font-family: Helvetica; font-size: 12px; line-height: normal; ">but I wonder, dear friends,</span><br /><span style="font-family: Helvetica; font-size: 12px; line-height: normal; ">'bout the end of this story</span></p></blockquote></blockquote></blockquote></blockquote>
<p /><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><p><span style="font-family: Helvetica; font-size: 12px; line-height: normal; ">Will the Cloud truly bring value?</span><br /><span style="font-family: Helvetica; font-size: 12px; line-height: normal; ">Solve problems that matter?</span><br /><span style="font-family: Helvetica; font-size: 12px; line-height: normal; ">Or is it about </span><br /><span style="font-family: Helvetica; font-size: 12px; line-height: normal; ">vendors' wallets a-fatter?</span></p></blockquote></blockquote></blockquote>
<p /><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><p><span style="font-family: Helvetica; font-size: 12px; line-height: normal; ">*I* think the Cloud</span><br /><span style="font-family: Helvetica; font-size: 12px; line-height: normal; ">has wonderful promise</span><br /><span style="font-family: Helvetica; font-size: 12px; line-height: normal; ">If the low-hanging IT fruit</span><br /><span style="font-family: Helvetica; font-size: 12px; line-height: normal; ">can be lifted 'way from us</span></p></blockquote></blockquote>
<p /><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><p><span style="font-family: Helvetica; font-size: 12px; line-height: normal; ">The Cloud is a function</span><br /><span style="font-family: Helvetica; font-size: 12px; line-height: normal; ">that's forging new thought</span><br /><span style="font-family: Helvetica; font-size: 12px; line-height: normal; ">Pushing the boundaries</span><br /><span style="font-family: Helvetica; font-size: 12px; line-height: normal; ">and theories we've bought</span></p></blockquote>
<p style="margin: 0.0px 0.0px 0.0px 0.0px; font: 12.0px Helvetica">It's profoundly game changing</p>
<p style="margin: 0.0px 0.0px 0.0px 0.0px; font: 12.0px Helvetica">and as long as we focus</p>
<p style="margin: 0.0px 0.0px 0.0px 0.0px; font: 12.0px Helvetica">and don't buy into the </p>
<p style="margin: 0.0px 0.0px 0.0px 0.0px; font: 12.0px Helvetica">hyped hocus pocus</p>
<p /><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><p><span style="font-family: Helvetica; font-size: 12px; line-height: normal; ">So before we end up</span><br /><span style="font-family: Helvetica; font-size: 12px; line-height: normal; ">with a Cloud that "slices and dices"</span><br /><span style="font-family: Helvetica; font-size: 12px; line-height: normal; ">that never gets dull,</span><br /><span style="font-family: Helvetica; font-size: 12px; line-height: normal; ">mashes, grates, grinds and rices</span></p></blockquote>
<p style="margin: 0.0px 0.0px 0.0px 0.0px; font: 12.0px Helvetica">It's important to state</p>
<p style="margin: 0.0px 0.0px 0.0px 0.0px; font: 12.0px Helvetica">what problem we're solving</p>
<p style="margin: 0.0px 0.0px 0.0px 0.0px; font: 12.0px Helvetica">so the Cloud doesn't end up</p>
<p style="margin: 0.0px 0.0px 0.0px 0.0px; font: 12.0px Helvetica">with its value de-evolving</p>
<p style="margin: 0.0px 0.0px 0.0px 0.0px; font: 12.0px Helvetica; min-height: 14.0px" />
<p style="margin: 0.0px 0.0px 0.0px 0.0px; font: 12.0px Helvetica; min-height: 14.0px"><br />----</p><p style="margin: 0.0px 0.0px 0.0px 0.0px; font: 12.0px Helvetica; min-height: 14.0px" /><p style="margin: 0.0px 0.0px 0.0px 0.0px; font: 12.0px Helvetica; min-height: 14.0px">BTW, if you want to see more of my Cloud and Security poems, just check <a href="http://rationalsecurity.typepad.com/blog/poetry/">here</a>.</p><p style="margin: 0.0px 0.0px 0.0px 0.0px; font: 12.0px Helvetica; min-height: 14.0px" /><p /></div>
</content>


    <feedburner:origLink>http://rationalsecurity.typepad.com/blog/2009/02/ron-popeil-and-cloud-computing-in-poetic-review.html</feedburner:origLink><feedburner:origLink>http://feedproxy.google.com/~r/typepad/nOnJ/~3/_74B6kaQV-I/ron-popeil-and-cloud-computing-in-poetic-review.html</feedburner:origLink></entry>
    <entry>
        <title>I'm Sorry, But Did Someone Redefine "Open" and "Interoperable" and Not Tell Me?</title>
        <link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/feedburner/rarz/~3/OoNNkpzyJaU/im-sorry-but-did-someone-redefine-open-and-interoperable-and-not-tell-me.html" />
        <link rel="replies" type="text/html" href="http://rationalsecurity.typepad.com/blog/2009/02/im-sorry-but-did-someone-redefine-open-and-interoperable-and-not-tell-me.html" thr:count="3" thr:updated="2009-02-27T09:07:07-05:00" />
        <id>tag:typepad.com,2003:post-63387799</id>
        <published>2009-02-26T14:07:26-05:00</published>
        <updated>2009-02-26T14:19:29-05:00</updated>
        <summary>I've got a problem with the escalation of VMware's marketing abuse of the terms "open," "interoperable," and "standards." I'm a fan of VMware, but this is getting silly. When a vendor like VMware crafts an architecture, creates a technology platform,...</summary>
        <author>
            <name>beaker</name>
        </author>
        <category scheme="http://www.sixapart.com/ns/types#category" term="Cloud Computing" />
        <category scheme="http://www.sixapart.com/ns/types#category" term="Cloud Security" />
        <category scheme="http://www.sixapart.com/ns/types#category" term="Microsoft" />
        <category scheme="http://www.sixapart.com/ns/types#category" term="Virtualization" />
        <category scheme="http://www.sixapart.com/ns/types#category" term="VMWare" />
        
        <category scheme="http://sixapart.com/ns/types#tag" term="Azure" />
        <category scheme="http://sixapart.com/ns/types#tag" term="Chris Hoff" />
        <category scheme="http://sixapart.com/ns/types#tag" term="Christofer Hoff" />
        <category scheme="http://sixapart.com/ns/types#tag" term="Cloud" />
        <category scheme="http://sixapart.com/ns/types#tag" term="Cloud Computing" />
        <category scheme="http://sixapart.com/ns/types#tag" term="Cloud Security" />
        <category scheme="http://sixapart.com/ns/types#tag" term="Microsoft" />
        <category scheme="http://sixapart.com/ns/types#tag" term="Rational Security" />
        <category scheme="http://sixapart.com/ns/types#tag" term="Rational Survivability" />
        <category scheme="http://sixapart.com/ns/types#tag" term="vCloud" />
        <category scheme="http://sixapart.com/ns/types#tag" term="Virtualization" />
        <category scheme="http://sixapart.com/ns/types#tag" term="Virtualization Security" />
        <category scheme="http://sixapart.com/ns/types#tag" term="VMware" />
        <category scheme="http://sixapart.com/ns/types#tag" term="vSphere" />
        
<content type="xhtml" xml:lang="en-US" xml:base="http://rationalsecurity.typepad.com/blog/">
<div xmlns="http://www.w3.org/1999/xhtml"><p style="margin: 0.0px 0.0px 0.0px 0.0px; line-height: 15.0px; font: 13.0px Trebuchet MS"><span style="line-height: 15px; "><a href="http://rationalsecurity.typepad.com/.a/6a00d83451be3669e20112790f733e28a4-pi" style="float: right;"><img alt="3-stooges-football" class="at-xid-6a00d83451be3669e20112790f733e28a4" src="http://rationalsecurity.typepad.com/.a/6a00d83451be3669e20112790f733e28a4-200wi" style="width: 200px; margin: 0px 0px 5px 5px;" /></a>
 </span>I've got a problem with the escalation of VMware's marketing abuse of the terms "open," "interoperable," and "standards."  I'm a fan of VMware, but this is getting silly.</p>
<p style="margin: 0.0px 0.0px 0.0px 0.0px; line-height: 15.0px; font: 13.0px Trebuchet MS; min-height: 15.0px"><span style="margin-top: 0px; margin-right: 0px; margin-bottom: 0px; margin-left: 0px; line-height: 15px; font: normal normal normal 13px/normal 'Trebuchet MS'; min-height: 15px; font-size: 13px; font-family: 'Trebuchet MS'; "><br /></span></p>
<p style="margin: 0.0px 0.0px 0.0px 0.0px; line-height: 15.0px; font: 13.0px Trebuchet MS"><span style="margin-top: 0px; margin-right: 0px; margin-bottom: 0px; margin-left: 0px; line-height: 15px; font: normal normal normal 13px/normal 'Trebuchet MS'; font-size: 13px; font-family: 'Trebuchet MS'; ">When a vendor like VMware crafts an architecture, creates a technology platform, defines an API, gets providers to subscribe to offering it as a service and does so with the full knowledge that it REQUIRES their platform to <span style="text-decoration: underline;">really</span> function, and THEN calls it "open" and "interoperable," because an API exists, it is intellectually dishonest and about as transparent as saran wrap to call that a "standard" to imply it is available regardless of platform.</span></p>
<p style="margin: 0.0px 0.0px 0.0px 0.0px; line-height: 15.0px; font: 13.0px Trebuchet MS; min-height: 15.0px"><span style="margin-top: 0px; margin-right: 0px; margin-bottom: 0px; margin-left: 0px; line-height: 15px; font: normal normal normal 13px/normal 'Trebuchet MS'; min-height: 15px; font-size: 13px; font-family: 'Trebuchet MS'; "><br /></span></p><p style="margin: 0.0px 0.0px 0.0px 0.0px; line-height: 15.0px; font: 13.0px Trebuchet MS; min-height: 15.0px">We are talking about philosophically and diametrically-opposed strategies between virtualization platform players here, not minor deltas along the bumpy roadmap highway.  What's at stake is fundamentally the success or failure of these companies.  Trying to convince the world that VMware, Microsoft, Citrix, etc. are going to huddle for a group hug is, well, insulting.</p><p style="margin: 0.0px 0.0px 0.0px 0.0px; line-height: 15.0px; font: 13.0px Trebuchet MS; min-height: 15.0px" />
<p style="margin: 0.0px 0.0px 0.0px 0.0px; line-height: 15.0px; font: 13.0px Trebuchet MS"><span style="margin-top: 0px; margin-right: 0px; margin-bottom: 0px; margin-left: 0px; line-height: 15px; font: normal normal normal 13px/normal 'Trebuchet MS'; font-size: 13px; font-family: 'Trebuchet MS'; ">This r</span><a href="http://www.theregister.co.uk/2009/02/26/vmware_onetrick_pony/"><span style="text-decoration: underline; color: #0018f5; font-size: 13px; font-family: 'Trebuchet MS'; ">ecent article in the Register</span></a><span style="margin-top: 0px; margin-right: 0px; margin-bottom: 0px; margin-left: 0px; line-height: 15px; font: normal normal normal 13px/normal 'Trebuchet MS'; font-size: 13px; font-family: 'Trebuchet MS'; "> espousing VMware's strategy really highlighted some of these issues as it progressed. Here's the first bit which I agree with:</span></p><p style="margin: 0.0px 0.0px 0.0px 0.0px; line-height: 15.0px; font: 13.0px Trebuchet MS" /><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><p><span style="line-height: normal; "><span style="font-style: italic;">There is, they fervently say, no other enterprise server and data centre virtualisation play in town. Businesses wanting to virtualise their servers inside a virtualising data centre infrastructure have to dance according to VMware's tune. Microsoft's Hyper-V music isn't ready, they say, and open source virtualisation is lagging and doesn't have enterprise credibility.</span></span></p></blockquote><p style="margin: 0.0px 0.0px 0.0px 0.0px; line-height: 15.0px; font: 13.0px Trebuchet MS" /><p style="margin: 0.0px 0.0px 0.0px 0.0px; line-height: 15.0px; font: 13.0px Trebuchet MS">Short of the hyperbole, I'd agree with most of that.  We can easily start a religious debate here, but let's not for now.  It gets smelly where the article starts talking about vCloud which, given VMware's protectionist stance based on fair harbor tactics, amounts to nothing more (still) than a vision.  None of the providers will talk about it because they are under NDA.  We don't really know what vCloud means yet: </p><p style="margin: 0.0px 0.0px 0.0px 0.0px; line-height: 15.0px; font: 13.0px Trebuchet MS" />
<blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><p><span style="line-height: normal; "><span style="font-style: italic;">Singing the vcloud API <span style="text-decoration: underline;">standard</span> song is very astute. It reassures all people already on board and climbing on board the VMware bandwagon that VMware is <span style="text-decoration: underline;">open</span> and not looking to lock them in. Even if Microsoft doesn't join in this <span style="text-decoration: underline;">standardisation</span> effort with a whole heart, it doesn't matter so long as VMware gets enough critical mass.</span></span></p></blockquote><p><span><span style="font-weight: bold;">How do you describe having to use VMware's platform and API as VMware "...not looking to lock them in?" Of course they are!  </span></span></p><div>To fully leverage the power of the InterCloud in this model, it really amounts to either an ALL VMware solution or settling for basic connectors for coarse-grained networked capability.<br /></div><div><span><br /></span></div><div><span>Unless you have feature-parity or true standardization at the hypervisor and management layers, it's really about interconnectivity not interoperability.  Let's be honest about this.<br /></span><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><p><span style="line-height: normal; "><span style="font-style: italic;">By having external cloud suppliers and internal cloud users believe that cloud federation through VMware's vCloud infrastructure is realistic then the two types of cloud user will bolster and reassure each other. They want it to happen and, if it does, then Hyper-V is locked out unless it plays by the VMware-driven and VMware partner-supported cloud standardisation rules, in which case MIcrosoft's cloud customers are open to competitive attack. It's unlikely to happen.</span></span></p></blockquote>


<p style="margin: 0.0px 0.0px 0.0px 0.0px; line-height: 21.0px; font: 14.0px Trebuchet MS; min-height: 16.0px"><span style="font-size: 13px; ">"Federation" in this context really only applies to lessening/evaporating the difference between public and private clouds, not clouds running on different platforms.  That's, um, "lock-in."</span></p>
<p style="margin: 0.0px 0.0px 0.0px 0.0px; line-height: 15.0px; font: 13.0px Trebuchet MS; min-height: 15.0px"><span style="margin-top: 0px; margin-right: 0px; margin-bottom: 0px; margin-left: 0px; line-height: 15px; font: normal normal normal 13px/normal 'Trebuchet MS'; min-height: 15px; font-size: 13px; font-family: 'Trebuchet MS'; "><br /></span></p>
<p style="margin: 0.0px 0.0px 0.0px 0.0px; line-height: 15.0px; font: 13.0px Trebuchet MS"><span style="margin-top: 0px; margin-right: 0px; margin-bottom: 0px; margin-left: 0px; line-height: 15px; font: normal normal normal 13px/normal 'Trebuchet MS'; font-size: 13px; font-family: 'Trebuchet MS'; "><span style="font-weight: bold;">Standards are great, especially when they're yours.</span> Now we're starting to play games.  VMware should basically just kick their competitors in the nuts and say this to us all:</span></p>
<blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><p><span style="line-height: normal; "><span style="font-weight: bold;">"If you standardize on VMware, you get to leverage the knowledge, skills, and investment you've already made -- regardless of whether you're talking public vs. private.  We will make our platforms, API's and capabilities as available as possible.  If the other vendors want to play, great.  If not, your choice as a customer will determine if that was a good decision for them or not."</span></span><span style="font-weight: bold;"><br /></span></p></blockquote>
<p style="margin: 0.0px 0.0px 0.0px 0.0px; line-height: 15.0px; font: 13.0px Trebuchet MS; min-height: 15.0px">Instead of dancing around trying to muscle Microsoft into playing nice (which they won't) or insulting our intelligence by handwaving that you're really interested in free love versus world domination, why don't you just call a spade a virtualized spade.</p><p style="margin: 0.0px 0.0px 0.0px 0.0px; line-height: 15.0px; font: 13.0px Trebuchet MS; min-height: 15.0px" /><p style="margin: 0.0px 0.0px 0.0px 0.0px; line-height: 15.0px; font: 13.0px Trebuchet MS" /><p style="margin: 0.0px 0.0px 0.0px 0.0px; line-height: 15.0px; font: 13.0px Trebuchet MS">And by the way, if it weren't for Microsoft, we wouldn't have this virtualization landscape to begin with...not because of the technology contributions to virtualization, but rather because the inefficiencies of single app/OS/hardware affinity using Microsoft OS's DROVE the entire virtualization market in the first place!</p><p style="margin: 0.0px 0.0px 0.0px 0.0px; line-height: 15.0px; font: 13.0px Trebuchet MS" /><p style="margin: 0.0px 0.0px 0.0px 0.0px; line-height: 15.0px; font: 13.0px Trebuchet MS" /><p style="margin: 0.0px 0.0px 0.0px 0.0px; line-height: 15.0px; font: 13.0px Trebuchet MS" /><p style="margin: 0.0px 0.0px 0.0px 0.0px; line-height: 15.0px; font: 13.0px Trebuchet MS">Microsoft is no joke.  They will maneuver to outpace VMware. HyperV and Azure will be a significant threat to VMware in the long term, and this old Microsoft joke will come back to haunt to VMware's abuse of the words above:</p><p style="margin: 0.0px 0.0px 0.0px 0.0px; line-height: 15.0px; font: 13.0px Trebuchet MS" /></div><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><p><span style="line-height: normal; "><span style="font-weight: bold;">Q: How many Microsoft engineers does it take to change a lightbulb?  </span></span><span style="font-weight: bold;"><br /></span><span style="line-height: normal; "><span style="font-weight: bold;">A: None, they just declare darkness a standard.</span></span></p></blockquote><div><p style="margin: 0.0px 0.0px 0.0px 0.0px; line-height: 15.0px; font: 13.0px Trebuchet MS" /><p style="margin: 0.0px 0.0px 0.0px 0.0px; line-height: 15.0px; font: 13.0px Trebuchet MS">is it getting dimmer in here?</p>
<p style="margin: 0.0px 0.0px 0.0px 0.0px; line-height: 15.0px; font: 13.0px Trebuchet MS; min-height: 15.0px"><span style="margin-top: 0px; margin-right: 0px; margin-bottom: 0px; margin-left: 0px; line-height: 15px; font: normal normal normal 13px/normal 'Trebuchet MS'; min-height: 15px; font-size: 13px; font-family: 'Trebuchet MS'; "><br /></span></p>
<p style="margin: 0.0px 0.0px 0.0px 0.0px; line-height: 15.0px; font: 13.0px Trebuchet MS"><span style="margin-top: 0px; margin-right: 0px; margin-bottom: 0px; margin-left: 0px; line-height: 15px; font: normal normal normal 13px/normal 'Trebuchet MS'; font-size: 13px; font-family: 'Trebuchet MS'; ">/Hoff</span></p>
<p style="margin: 0.0px 0.0px 0.0px 0.0px; line-height: 15.0px; font: 13.0px Trebuchet MS; min-height: 15.0px" /></div></div>
</content>


    <feedburner:origLink>http://rationalsecurity.typepad.com/blog/2009/02/im-sorry-but-did-someone-redefine-open-and-interoperable-and-not-tell-me.html</feedburner:origLink><feedburner:origLink>http://feedproxy.google.com/~r/typepad/nOnJ/~3/LnMtfBL9PII/im-sorry-but-did-someone-redefine-open-and-interoperable-and-not-tell-me.html</feedburner:origLink></entry>
    <entry>
        <title>Amazon's Kindle: Some Interesting Security Thoughts</title>
        <link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/feedburner/rarz/~3/hAyvPZlyYok/amazons-kindle-some-interesting-security-thoughts.html" />
        <link rel="replies" type="text/html" href="http://rationalsecurity.typepad.com/blog/2009/02/amazons-kindle-some-interesting-security-thoughts.html" thr:count="11" thr:updated="2009-03-04T11:12:59-05:00" />
        <id>tag:typepad.com,2003:post-63375049</id>
        <published>2009-02-26T10:13:53-05:00</published>
        <updated>2009-02-26T11:00:10-05:00</updated>
        <summary>My Kindle2 showed up yesterday. I un-boxed it, turned it on and within 3 minutes had downloaded my first book and was reading away (Thomas Barnett's "Great Powers," if you must know.) So this morning after I checked my email...</summary>
        <author>
            <name>beaker</name>
        </author>
        <category scheme="http://www.sixapart.com/ns/types#category" term="Amazon.com" />
        
        <category scheme="http://sixapart.com/ns/types#tag" term="Amazon.com" />
        <category scheme="http://sixapart.com/ns/types#tag" term="Chris Hoff" />
        <category scheme="http://sixapart.com/ns/types#tag" term="Christofer Hoff" />
        <category scheme="http://sixapart.com/ns/types#tag" term="Kindle" />
        <category scheme="http://sixapart.com/ns/types#tag" term="Kindle Security" />
        <category scheme="http://sixapart.com/ns/types#tag" term="KindleSec" />
        <category scheme="http://sixapart.com/ns/types#tag" term="Rational Security" />
        <category scheme="http://sixapart.com/ns/types#tag" term="Rational Survivability" />
        
<content type="xhtml" xml:lang="en-US" xml:base="http://rationalsecurity.typepad.com/blog/">
<div xmlns="http://www.w3.org/1999/xhtml"><p>My Kindle2 showed up yesterday. I un-boxed it, turned it on and within 3 minutes had downloaded my first book and was reading away (Thomas Barnett's "Great Powers," if you must know.)</p><div>So this morning after I checked my email on my other indispensable tool/toy, my iPhone, I realized something was missing from the Kindle: a password.</div><br /><div>So you might think "Hoff, why would you need a password for a device that lets you read books?'</div><br /><div>Well, while it's true that the majority of users will simply read "off-the-shelf" books/blogs/magazines they download from Amazon.com's storefront on their Kindles, there are a couple of other interesting scenarios that ran through my mind:</div><div><ol>
<li>To purchase a book using the Kindle, the device is linked to Amazon's One-Click purchase capability.  This means that once I choose to purchase a book, I simply click "Buy" and it's delivered to the device, automagically charging my credit card.  If I lost my device, someone who found it could literally download hundreds of books to the Kindle on my nickel until I am able to do something about it.  This would be short-lived, but really annoying.</li>
<p>
</p><li>It is possible using an Amazon web service to convert documents into the Kindle Format and download them over WhisperNet to your device.  Given how convenient this is for reading, imagine what would happen if some crafty person decided to convert and download a sensitive document to the Kindle and then lose the device.  Imagine if that document contained PII or other confidential/sensitive information?  I wager we'll see a breach notification being issued based on someone losing a Kindle.</li>
</ol>
<div>Yes, I know it's a piece of "consumer" equipment, but look a little further down the line: college students using it for textbooks and all sorts of other communications, business people using it for reading corporate materials, etc...</div><br /><div>I am interested in exploring the following elements in the long term:</div><div><ol>
<li>An option for password-protected access to the device itself.</li>
<li>A content-rating based password-controlled parental rating system for certain materials. My kids already grabbed my Kindle and (see #1 above) downloaded 3 kids books to it.  I may not want them to read certain content.</li>
<li>Remote self-destruct </li>
<li>Encryption of content (at rest, in motion)</li>
<li>Security of Whispernet itself</li>
<li>WiFi (and it's attendant issues)</li>
</ol>
</div><div>I'm sure as I dwell on this, there will be other issues that crop up, but the security wonk in me was in full gear this morning.<br /></div></div><br /><div>You have any other security shortcomings or concerns you've thought of re: the Kindle? <br /></div><br /><div>/Hoff</div></div>
</content>


    <feedburner:origLink>http://rationalsecurity.typepad.com/blog/2009/02/amazons-kindle-some-interesting-security-thoughts.html</feedburner:origLink><feedburner:origLink>http://feedproxy.google.com/~r/typepad/nOnJ/~3/X82FoGxT3rg/amazons-kindle-some-interesting-security-thoughts.html</feedburner:origLink></entry>
    <entry>
        <title>Interesting Read: The World Privacy Forum's Cloud Privacy Report</title>
        <link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/feedburner/rarz/~3/rSSVGniHDzU/interesting-read-the-world-privacy-forums-cloud-privacy-report.html" />
        <link rel="replies" type="text/html" href="http://rationalsecurity.typepad.com/blog/2009/02/interesting-read-the-world-privacy-forums-cloud-privacy-report.html" thr:count="0" />
        <id>tag:typepad.com,2003:post-63355371</id>
        <published>2009-02-25T21:31:11-05:00</published>
        <updated>2009-02-25T21:31:11-05:00</updated>
        <summary>The World Privacy Forum released their "Cloud Privacy Report" written by Robert Gellman two days ago. It's an interesting read that describes the many facets of data privacy concerns in Cloud environments: This report discusses the issue of cloud computing...</summary>
        <author>
            <name>beaker</name>
        </author>
        <category scheme="http://www.sixapart.com/ns/types#category" term="Cloud Computing" />
        <category scheme="http://www.sixapart.com/ns/types#category" term="Cloud Security" />
        <category scheme="http://www.sixapart.com/ns/types#category" term="Privacy" />
        
        <category scheme="http://sixapart.com/ns/types#tag" term="Chris Hoff" />
        <category scheme="http://sixapart.com/ns/types#tag" term="Christofer Hoff" />
        <category scheme="http://sixapart.com/ns/types#tag" term="Cloud" />
        <category scheme="http://sixapart.com/ns/types#tag" term="Cloud Computing" />
        <category scheme="http://sixapart.com/ns/types#tag" term="Cloud Privacy" />
        <category scheme="http://sixapart.com/ns/types#tag" term="Cloud Privacy Report" />
        <category scheme="http://sixapart.com/ns/types#tag" term="Cloud Security" />
        <category scheme="http://sixapart.com/ns/types#tag" term="Rational Security" />
        <category scheme="http://sixapart.com/ns/types#tag" term="Rational Survivability" />
        <category scheme="http://sixapart.com/ns/types#tag" term="Robert Gellman" />
        <category scheme="http://sixapart.com/ns/types#tag" term="World Privacy Forum" />
        
<content type="xhtml" xml:lang="en-US" xml:base="http://rationalsecurity.typepad.com/blog/">
<div xmlns="http://www.w3.org/1999/xhtml"><p>The World Privacy Forum released their "Cloud Privacy Report" written by Robert Gellman two days ago. It's an interesting read that describes the many facets of data privacy concerns in Cloud environments: </p><br /><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><p><span style="line-height: normal; font-size: 13px; font-family: 'Times New Roman'; ">This report discusses the issue of cloud computing and outlines its implications for the privacy of </span><span style="margin-top: 0px; margin-right: 0px; margin-bottom: 0px; margin-left: 40px; border-top-style: none; border-right-style: none; border-bottom-style: none; border-left-style: none; border-width: initial; border-color: initial; padding-top: 0px; padding-right: 0px; padding-bottom: 0px; padding-left: 0px; font-size: 13px; font-family: 'Times New Roman'; "><br /></span><span style="line-height: normal; font-size: 13px; font-family: 'Times New Roman'; ">personal information as well as its implications for the confidentiality of business and </span><span style="margin-top: 0px; margin-right: 0px; margin-bottom: 0px; margin-left: 40px; border-top-style: none; border-right-style: none; border-bottom-style: none; border-left-style: none; border-width: initial; border-color: initial; padding-top: 0px; padding-right: 0px; padding-bottom: 0px; padding-left: 0px; font-size: 13px; font-family: 'Times New Roman'; "><br /></span><span style="line-height: normal; font-size: 13px; font-family: 'Times New Roman'; ">governmental information. The report finds that for some information and for some business </span><span style="margin-top: 0px; margin-right: 0px; margin-bottom: 0px; margin-left: 40px; border-top-style: none; border-right-style: none; border-bottom-style: none; border-left-style: none; border-width: initial; border-color: initial; padding-top: 0px; padding-right: 0px; padding-bottom: 0px; padding-left: 0px; font-size: 13px; font-family: 'Times New Roman'; "><br /></span><span style="line-height: normal; font-size: 13px; font-family: 'Times New Roman'; ">users, sharing may be illegal, may be limited in some ways, or may affect the status or </span><span style="margin-top: 0px; margin-right: 0px; margin-bottom: 0px; margin-left: 40px; border-top-style: none; border-right-style: none; border-bottom-style: none; border-left-style: none; border-width: initial; border-color: initial; padding-top: 0px; padding-right: 0px; padding-bottom: 0px; padding-left: 0px; font-size: 13px; font-family: 'Times New Roman'; "><br /></span><span style="line-height: normal; font-size: 13px; font-family: 'Times New Roman'; ">protections of the information shared. The report discusses how even when no laws or </span><span style="margin-top: 0px; margin-right: 0px; margin-bottom: 0px; margin-left: 40px; border-top-style: none; border-right-style: none; border-bottom-style: none; border-left-style: none; border-width: initial; border-color: initial; padding-top: 0px; padding-right: 0px; padding-bottom: 0px; padding-left: 0px; font-size: 13px; font-family: 'Times New Roman'; "><br /></span><span style="line-height: normal; font-size: 13px; font-family: 'Times New Roman'; ">obligations block the ability of a user to disclose information to a cloud provider, disclosure may </span><span style="margin-top: 0px; margin-right: 0px; margin-bottom: 0px; margin-left: 40px; border-top-style: none; border-right-style: none; border-bottom-style: none; border-left-style: none; border-width: initial; border-color: initial; padding-top: 0px; padding-right: 0px; padding-bottom: 0px; padding-left: 0px; font-size: 13px; font-family: 'Times New Roman'; "><br /></span><span style="line-height: normal; font-size: 13px; font-family: 'Times New Roman'; ">still not be free of consequences. The report finds that information stored by a business or an </span><span style="margin-top: 0px; margin-right: 0px; margin-bottom: 0px; margin-left: 40px; border-top-style: none; border-right-style: none; border-bottom-style: none; border-left-style: none; border-width: initial; border-color: initial; padding-top: 0px; padding-right: 0px; padding-bottom: 0px; padding-left: 0px; font-size: 13px; font-family: 'Times New Roman'; "><br /></span><span style="line-height: normal; font-size: 13px; font-family: 'Times New Roman'; ">individual with a third party may have fewer or weaker privacy or other protections than </span><span style="margin-top: 0px; margin-right: 0px; margin-bottom: 0px; margin-left: 40px; border-top-style: none; border-right-style: none; border-bottom-style: none; border-left-style: none; border-width: initial; border-color: initial; padding-top: 0px; padding-right: 0px; padding-bottom: 0px; padding-left: 0px; font-size: 13px; font-family: 'Times New Roman'; "><br /></span><span style="line-height: normal; font-size: 13px; font-family: 'Times New Roman'; ">information in the possession of the creator of the information. The report, in its analysis and </span><span style="margin-top: 0px; margin-right: 0px; margin-bottom: 0px; margin-left: 40px; border-top-style: none; border-right-style: none; border-bottom-style: none; border-left-style: none; border-width: initial; border-color: initial; padding-top: 0px; padding-right: 0px; padding-bottom: 0px; padding-left: 0px; font-size: 13px; font-family: 'Times New Roman'; "><br /></span><span style="line-height: normal; font-size: 13px; font-family: 'Times New Roman'; ">discussion of relevant laws, finds that both government agencies and private litigants may be </span><span style="margin-top: 0px; margin-right: 0px; margin-bottom: 0px; margin-left: 40px; border-top-style: none; border-right-style: none; border-bottom-style: none; border-left-style: none; border-width: initial; border-color: initial; padding-top: 0px; padding-right: 0px; padding-bottom: 0px; padding-left: 0px; font-size: 13px; font-family: 'Times New Roman'; "><br /></span><span style="line-height: normal; font-size: 13px; font-family: 'Times New Roman'; ">able to obtain information from a third party more easily than from the creator of the </span><span style="margin-top: 0px; margin-right: 0px; margin-bottom: 0px; margin-left: 40px; border-top-style: none; border-right-style: none; border-bottom-style: none; border-left-style: none; border-width: initial; border-color: initial; padding-top: 0px; padding-right: 0px; padding-bottom: 0px; padding-left: 0px; font-size: 13px; font-family: 'Times New Roman'; "><br /></span><span style="line-height: normal; font-size: 13px; font-family: 'Times New Roman'; ">information. A cloud provider’s terms of service, privacy policy, and location may significantly </span><span style="margin-top: 0px; margin-right: 0px; margin-bottom: 0px; margin-left: 40px; border-top-style: none; border-right-style: none; border-bottom-style: none; border-left-style: none; border-width: initial; border-color: initial; padding-top: 0px; padding-right: 0px; padding-bottom: 0px; padding-left: 0px; font-size: 13px; font-family: 'Times New Roman'; "><br /></span><span style="line-height: normal; font-size: 13px; font-family: 'Times New Roman'; ">affect a user’s privacy and confidentiality interests.</span></p></blockquote><p><span style="font-family: 'Times New Roman'; line-height: normal;"><br /></span></p><div><span style="font-family: 'Times New Roman'; line-height: normal;"><span style="font-family: 'Trebuchet MS'; line-height: 15px; ">I plan to spend some time reading through the report in more depth, but I enjoyed my cursory review thus far, especially some of the coverage related to issues such as FCRA, bankruptcy, Cloud provider ownership, disclosure, etc.  Many of these issues are near and dear to my heart.</span><br /></span></div><br /><div>You can download the report <a href="http://www.worldprivacyforum.org/pdf/WPF_Cloud_Privacy_Report.pdf">here</a>.</div><br /><div>/Hoff</div></div>
</content>


    <feedburner:origLink>http://rationalsecurity.typepad.com/blog/2009/02/interesting-read-the-world-privacy-forums-cloud-privacy-report.html</feedburner:origLink><feedburner:origLink>http://feedproxy.google.com/~r/typepad/nOnJ/~3/HO3Ex9h-mew/interesting-read-the-world-privacy-forums-cloud-privacy-report.html</feedburner:origLink></entry>
    <entry>
        <title>Internal v. External/Private v. Public/On-Premise v. Off- Premise: It's all Cloud But How You Get There Is Important.</title>
        <link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/feedburner/rarz/~3/hCmsWt5g-y4/internal-v-externalprivate-v-publiconpremise-v-off-premise-its-all-cloud-but-how-you-get-there-is-im.html" />
        <link rel="replies" type="text/html" href="http://rationalsecurity.typepad.com/blog/2009/02/internal-v-externalprivate-v-publiconpremise-v-off-premise-its-all-cloud-but-how-you-get-there-is-im.html" thr:count="0" />
        <id>tag:typepad.com,2003:post-63283555</id>
        <published>2009-02-24T11:24:05-05:00</published>
        <updated>2009-02-24T14:48:46-05:00</updated>
        <summary>I've written about the really confusing notional definitions that seem to be hung up on where the computing actually happens when you say "Cloud:" in your datacenter or someone else's. It's frustrating to see how people mush together "public, private,...</summary>
        <author>
            <name>beaker</name>
        </author>
        <category scheme="http://www.sixapart.com/ns/types#category" term="Cloud Computing" />
        <category scheme="http://www.sixapart.com/ns/types#category" term="Cloud Security" />
        <category scheme="http://www.sixapart.com/ns/types#category" term="Virtualization" />
        
        <category scheme="http://sixapart.com/ns/types#tag" term="Chris Hoff" />
        <category scheme="http://sixapart.com/ns/types#tag" term="Christofer Hoff" />
        <category scheme="http://sixapart.com/ns/types#tag" term="Cloud" />
        <category scheme="http://sixapart.com/ns/types#tag" term="Cloud Computing" />
        <category scheme="http://sixapart.com/ns/types#tag" term="Cloud Security" />
        <category scheme="http://sixapart.com/ns/types#tag" term="Rational Security" />
        <category scheme="http://sixapart.com/ns/types#tag" term="Rational Survivability" />
        <category scheme="http://sixapart.com/ns/types#tag" term="VirtSec" />
        <category scheme="http://sixapart.com/ns/types#tag" term="Virtualization" />
        <category scheme="http://sixapart.com/ns/types#tag" term="Virtualization Security" />
        
<content type="xhtml" xml:lang="en-US" xml:base="http://rationalsecurity.typepad.com/blog/">
<div xmlns="http://www.w3.org/1999/xhtml"><p><a href="http://rationalsecurity.typepad.com/.a/6a00d83451be3669e20111689586d3970c-popup" onclick="window.open( this.href, '_blank', 'width=640,height=480,scrollbars=no,resizable=no,toolbar=no,directories=no,location=no,menubar=no,status=no,left=0,top=0' ); return false" style="float: right;"><img alt="Datacenter" class="at-xid-6a00d83451be3669e20111689586d3970c " src="http://rationalsecurity.typepad.com/.a/6a00d83451be3669e20111689586d3970c-200wi" style="width: 200px; margin: 0px 0px 5px 5px;" /></a>
 I've written about the really confusing notional definitions that seem to be hung up on where the computing actually happens when you say "Cloud:" in your datacenter or someone else's.  It's frustrating to see how people mush together "public, private, internal, external, on-premise, off-premise" to all mean the same thing.</p><div>They don't, or at least they shouldn't, at least not within the true context of Cloud Computing.</div><br /><div>In the long run, despite all the attempts to clarify what we mean by defining "Cloud Computing" more specifically as it relates to compute location, we're going to continue to call it "Cloud."  It's a sad admission I'm trying to come to grips with.  So I'll jump on this bandwagon and take another approach.<br /></div><div><br /><div>Cloud Computing will simply become ubiquitous in it's many forms and we are all going to end up with a hybrid model of Cloud adoption -- a veritable mash-up of Cloud services spanning the entire gamut of offerings.  We already have today.</div><br /><div>Here are a few, none-exhaustive examples of what a reasonably-sized enterprise can expect from the move to a hybrid Cloud environment:</div><div><ol>
<li>If you're using one or more SaaS vendors who own the entire stack, you'll be using their publicly-exposed Cloud offerings.  They manage the whole kit-and-kaboodle, information and all. </li>
<p>
</p><li>SaaS and PaaS vendors will provide ways of integrating their offerings (some do today) with your "private" enterprise data stores and directory services for better integration and business intelligence.</li>
<p>
</p><li>We'll see the simple evolution of hosting/colocation providers add dynamic scalability and utility billing and really push the Cloud mantra.  </li>
<p>
</p><li>IaaS vendors will provide (ala GoGrid) ways of consolidating and reducing infrastructure footprints in your enterprise datacenters by way of securely interconnecting your private enterprise infrastructure with managed infrastructure in their datacenters. This model simply calls for the offloading of the heavy tin. Management options abound: you manage it, they manage it, you both do...</li>
<p>
</p><li>Other IaaS players will continue to offer a compelling suite of soup-to-nuts services (ala Amazon) that depending upon your needs and requirements, means you have very little (or no) infrastructure to speak of.  You may or may not be constrained by what you can or need to do as you trade of flexibility for conformity here.</li>
<p>
</p><li>Virtualization platform providers will no longer make a distinction in terms of roadmap and product positioning between internal/external or public/private. What is enterprise virtualization today simply becomes "Cloud."  The same services, split along virtualization platform party lines, will become available regardless of location. </li>
<p>
</p><li>This means that vendors who today offer proprietary images and infrastructure will start to drive or be driven to integrate more open standards across their offerings in order to allow for portability, interoperability and inter-Cloud scalability...and to make sure you remain a customer.</li>
<p>
</p><li>Even though the Cloud is supposed to abstract infrastructure from your concern as a customer, brand-associated moving parts will count; customers will look for pure-play vetted integration between the big players (networking, virtualization, storage) in order to fluidly move information and applications into and out of Cloud offerings seamlessly </li>
<p>
</p><li>The notion of storage is going to be turned on its head; the commodity of bit buckets isn't what storage means in the Cloud.  All the chewy goodness will start to bubble to the surface as value-adds come to light: DeDup, backup, metadata, search, convergence with networking, security...</li>
<p>
</p><li>More client side computing will move to the cloud (remember, it doesn't matter whether it's internal or external) with thin client connectivity while powerful smaller-footprint mobile platforms (smartphones/netbooks) with native virtualization layers will also accelerate in uptake</li>
<p>
</p></ol>
Ultimately, what powers your Cloud providers WILL matter.  What companies adopt internally as their virtualization, networking, application delivery, security and storage platforms internally as they move to consolidate and then automate will be a likely choice when evaluating top-rung weighting when they identify what powers many of their Cloud providers' infrastructure.</div><br /><div>If a customer can take all the technology expertise, the organizational and operational practices they have honed as they virtualize their internal infrastructure (virtualization platform, compute, storage, networking, security) and basically be able to seamlessly apply that as a next step as the move to the Cloud(s), it's a win.</div><br /><div>The two biggest elements of a successful cloud: integration and management. Just like always.</div><br /><div>I can't wait.</div><br /><div>/Hoff<br /><br /><div>*Yes, we're concerned that if "stuff" is outside of our direct control, we'll not be able to "secure" it, but that isn't exactly a new concept, nor is it specific to Cloud -- it's just the latest horse we're beating because we haven't made much gains in being able to secure the things that matter most in the ways most effective for doing that.</div></div></div></div>
</content>


    <feedburner:origLink>http://rationalsecurity.typepad.com/blog/2009/02/internal-v-externalprivate-v-publiconpremise-v-off-premise-its-all-cloud-but-how-you-get-there-is-im.html</feedburner:origLink><feedburner:origLink>http://feedproxy.google.com/~r/typepad/nOnJ/~3/9B5sUJ2Xxkc/internal-v-externalprivate-v-publiconpremise-v-off-premise-its-all-cloud-but-how-you-get-there-is-im.html</feedburner:origLink></entry>
    <entry>
        <title>Virtualization &amp; Security: Disruptive Technologies - A Four Part Video Miniseries...</title>
        <link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/feedburner/rarz/~3/8fgg9bR1RQk/virtualization-security-disruptive-technologies-a-four-part-video-miniseries.html" />
        <link rel="replies" type="text/html" href="http://rationalsecurity.typepad.com/blog/2009/02/virtualization-security-disruptive-technologies-a-four-part-video-miniseries.html" thr:count="0" />
        <id>tag:typepad.com,2003:post-63279271</id>
        <published>2009-02-24T09:58:12-05:00</published>
        <updated>2009-02-24T09:58:12-05:00</updated>
        <summary>About nine months ago, Dino Dai Zovi, Rich Mogull and I sat down for about an hour as Dennis Fisher from TechTarget interviewed us in a panel style regarding the topic of virtualization and security. It has just been released...</summary>
        <author>
            <name>beaker</name>
        </author>
        <category scheme="http://www.sixapart.com/ns/types#category" term="Virtualization" />
        
        <category scheme="http://sixapart.com/ns/types#tag" term="Chris Hoff" />
        <category scheme="http://sixapart.com/ns/types#tag" term="Christofer Hoff" />
        <category scheme="http://sixapart.com/ns/types#tag" term="Dino Dai Zovi" />
        <category scheme="http://sixapart.com/ns/types#tag" term="Rational Security" />
        <category scheme="http://sixapart.com/ns/types#tag" term="Rational Survivability" />
        <category scheme="http://sixapart.com/ns/types#tag" term="Rich Mogull" />
        <category scheme="http://sixapart.com/ns/types#tag" term="VirtSec" />
        <category scheme="http://sixapart.com/ns/types#tag" term="Virtualization" />
        <category scheme="http://sixapart.com/ns/types#tag" term="Virtualization Security" />
        
<content type="xhtml" xml:lang="en-US" xml:base="http://rationalsecurity.typepad.com/blog/">
<div xmlns="http://www.w3.org/1999/xhtml"><div>About nine months ago, <a href="http://blog.trailofbits.com/">Dino Dai Zovi</a>, <a href="http://www.securosis.com">Rich Mogull</a> and I sat down for about an hour as Dennis Fisher from <a href="http://searchsecurity.techtarget.com/video/0,297151,sid14_gci1347879,00.html">TechTarget interviewed us</a> in a panel style regarding the topic of virtualization and security.  It has just been released now.<br /></div><br /><div>Considering it was almost a lifetime ago in Internet time, almost all of the content is still fresh and the prognostication is pretty well dead on.</div><br /><div>Enjoy:</div><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><p><br /><a href="http://link.brightcove.com/services/link/bcpid10996160001/bclid11816926001/bctid11860334001">Part 1: The Greatest Threats to Virtualized Environments</a></p><p><a href="http://link.brightcove.com/services/link/bcpid12040036001/bclid11917435001/bctid12068260001">Part 2: The Security Benefits of Virtualization</a></p><p><a href="http://link.brightcove.com/services/link/bcpid12040038001/bclid11912200001/bctid12068281001">Part 3: The Organizational Challenges of Virtualization</a></p><p><a href="http://link.brightcove.com/services/link/bcpid12040041001/bclid11912202001/bctid12088600001">Part 4: Virtualization and Security Vendors</a></p></blockquote><br /><div>/Hoff</div><br /><div>P.S. The camera adds like 40 pounds, really ;)</div></div>
</content>


    <feedburner:origLink>http://rationalsecurity.typepad.com/blog/2009/02/virtualization-security-disruptive-technologies-a-four-part-video-miniseries.html</feedburner:origLink><feedburner:origLink>http://feedproxy.google.com/~r/typepad/nOnJ/~3/v2uDsQEmLH8/virtualization-security-disruptive-technologies-a-four-part-video-miniseries.html</feedburner:origLink></entry>
    <entry>
        <title>Hire the Hoff - I'm On the Market, Whatcha Need? ;)</title>
        <link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/feedburner/rarz/~3/fqQSRjMMTsM/hire-the-hoff-im-on-the-market-whatcha-need-.html" />
        <link rel="replies" type="text/html" href="http://rationalsecurity.typepad.com/blog/2009/02/hire-the-hoff-im-on-the-market-whatcha-need-.html" thr:count="4" thr:updated="2009-02-24T20:35:42-05:00" />
        <id>tag:typepad.com,2003:post-63232415</id>
        <published>2009-02-23T11:45:36-05:00</published>
        <updated>2009-02-23T12:02:51-05:00</updated>
        <summary>The last two years have been a blast but all things must come to an end. At the conclusion of March, I am moving on to newer pastures. Where that is may be up to you. I am exploring all...</summary>
        <author>
            <name>beaker</name>
        </author>
        <category scheme="http://www.sixapart.com/ns/types#category" term="Career" />
        
        <category scheme="http://sixapart.com/ns/types#tag" term="Chris Hoff" />
        <category scheme="http://sixapart.com/ns/types#tag" term="Christofer Hoff" />
        
<content type="xhtml" xml:lang="en-US" xml:base="http://rationalsecurity.typepad.com/blog/">
<div xmlns="http://www.w3.org/1999/xhtml"><p><a href="http://rationalsecurity.typepad.com/.a/6a00d83451be3669e2011279068ab128a4-pi" style="float: left;"><img alt="Hoffforhire" border="0" class="at-xid-6a00d83451be3669e2011279068ab128a4 " src="http://rationalsecurity.typepad.com/.a/6a00d83451be3669e2011279068ab128a4-800wi" style="margin: 0px 5px 5px 0px;" title="Hoffforhire" /></a>
 The last two years have been a blast but all things must come to an end.</p><div>At the conclusion of March, I am moving on to newer pastures.  Where that is may be up to you.<br /></div><br /><div>I am exploring all options with a focus on traditional security roles including CISO/CSO, but I'd prefer architect/evangelist/CTO roles that focus more on virtualization and Cloud Computing security.</div><br /><div>If you've got an opportunity that you think we'd both be a match for, feel free to reach out.  </div><br /><div>A dose of reality: If you're not serious about envelope pushing, thought/industry leadership, world domination and unabashed enthusiasm sprinkled with rational pragmatism, I'm not your guy...</div><br /><div>My LinkedIn profile is <a href="http://www.linkedin.com/in/choff">here</a>.  My email is <a href="mailto:choff@packetfilter.com">here</a>. </div><br /><div>Thanks,</div><br /><div>/Hoff</div></div>
</content>


    <feedburner:origLink>http://rationalsecurity.typepad.com/blog/2009/02/hire-the-hoff-im-on-the-market-whatcha-need-.html</feedburner:origLink><feedburner:origLink>http://feedproxy.google.com/~r/typepad/nOnJ/~3/5FcGcd5zREw/hire-the-hoff-im-on-the-market-whatcha-need-.html</feedburner:origLink></entry>
    <entry>
        <title>Trust But Verify?  That's An Oxymoron...</title>
        <link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/feedburner/rarz/~3/zESiefJmJlw/trust-but-verify-thats-an-oxymoron.html" />
        <link rel="replies" type="text/html" href="http://rationalsecurity.typepad.com/blog/2009/02/trust-but-verify-thats-an-oxymoron.html" thr:count="3" thr:updated="2009-02-23T18:27:41-05:00" />
        <id>tag:typepad.com,2003:post-63221609</id>
        <published>2009-02-23T07:27:17-05:00</published>
        <updated>2009-02-23T07:31:49-05:00</updated>
        <summary>In response to my post regarding Cloud (SaaS, really) providers' security, Allen Baranov asked me the following excellent question in the comments: Hoff, What would make you trust "the Cloud"? Scrap that... stupid question... What would make you trust SaaS...</summary>
        <author>
            <name>beaker</name>
        </author>
        <category scheme="http://www.sixapart.com/ns/types#category" term="Cloud Computing" />
        <category scheme="http://www.sixapart.com/ns/types#category" term="Cloud Security" />
        <category scheme="http://www.sixapart.com/ns/types#category" term="Risk Assessment" />
        <category scheme="http://www.sixapart.com/ns/types#category" term="Risk Management" />
        
        <category scheme="http://sixapart.com/ns/types#tag" term="Chris Hoff" />
        <category scheme="http://sixapart.com/ns/types#tag" term="Christofer Hoff" />
        <category scheme="http://sixapart.com/ns/types#tag" term="Cloud" />
        <category scheme="http://sixapart.com/ns/types#tag" term="Cloud Computing" />
        <category scheme="http://sixapart.com/ns/types#tag" term="Cloud Security" />
        <category scheme="http://sixapart.com/ns/types#tag" term="Confidentiality" />
        <category scheme="http://sixapart.com/ns/types#tag" term="Information Security" />
        <category scheme="http://sixapart.com/ns/types#tag" term="Privacy" />
        <category scheme="http://sixapart.com/ns/types#tag" term="Rational Security" />
        <category scheme="http://sixapart.com/ns/types#tag" term="Rational Survivability" />
        <category scheme="http://sixapart.com/ns/types#tag" term="SaaS" />
        <category scheme="http://sixapart.com/ns/types#tag" term="Trust" />
        
<content type="html" xml:lang="en-US" xml:base="http://rationalsecurity.typepad.com/blog/">
&lt;div xmlns="http://www.w3.org/1999/xhtml"&gt;&lt;p&gt;&lt;a href="http://rationalsecurity.typepad.com/.a/6a00d83451be3669e201127906162f28a4-popup" onclick="window.open( this.href, &amp;#39;_blank&amp;#39;, &amp;#39;width=640,height=480,scrollbars=no,resizable=no,toolbar=no,directories=no,location=no,menubar=no,status=no,left=0,top=0&amp;#39; ); return false" style="float: right;"&gt;&lt;img alt="GBCIA" class="at-xid-6a00d83451be3669e201127906162f28a4 " src="http://rationalsecurity.typepad.com/.a/6a00d83451be3669e201127906162f28a4-150wi" style="width: 150px; margin: 0px 0px 5px 5px;" /&gt;&lt;/a&gt;
 In response to my &lt;a href="http://rationalsecurity.typepad.com/blog/2009/02/what-people-really-mean-when-they-say-the-cloud-is-more-secure.html"&gt;post regarding Cloud (SaaS, really) providers&amp;#39; security,&lt;/a&gt; Allen Baranov asked me the following excellent question in the comments:&lt;/p&gt;&lt;div&gt;&lt;blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"&gt;&lt;p&gt;&lt;span style="color: #333333; font-family: &amp;#39;trebuchet ms&amp;#39;; line-height: normal; "&gt;&lt;span style="font-style: italic;"&gt;Hoff,&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;/blockquote&gt;&lt;blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"&gt;&lt;p&gt;&lt;span style="color: #333333; font-family: &amp;#39;trebuchet ms&amp;#39;; line-height: normal; "&gt;&lt;span style="font-style: italic;"&gt;What would make you trust &amp;quot;the Cloud&amp;quot;? Scrap that... stupid question...&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;/blockquote&gt;&lt;blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"&gt;&lt;p&gt;&lt;span style="color: #333333; font-family: &amp;#39;trebuchet ms&amp;#39;; line-height: normal; "&gt;&lt;span style="font-style: italic;"&gt;&lt;span style="font-weight: bold;"&gt;What would &lt;span style="text-decoration: underline;"&gt;make&lt;/span&gt; you trust SaaS providers?&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;/blockquote&gt;&lt;/div&gt;&lt;div&gt;&lt;span style="color: #333333; line-height: normal;"&gt;To which I responded:&lt;/span&gt;&lt;/div&gt;&lt;blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"&gt;&lt;p&gt;&lt;span style="color: #333333; font-family: &amp;#39;trebuchet ms&amp;#39;; line-height: normal; "&gt;&lt;span style="font-style: italic;"&gt;&lt;span style="font-weight: bold;"&gt;Generally, my CEO or CFO. :( &amp;#0160;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;/blockquote&gt;&lt;blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"&gt;&lt;p&gt;&lt;span style="color: #333333; font-family: &amp;#39;trebuchet ms&amp;#39;; line-height: normal; "&gt;&lt;span style="font-style: italic;"&gt;I don&amp;#39;t &amp;quot;trust&amp;quot; third party vendors with my data. I never will. I simply exercise the maximal amount of due diligence that I am afforded given prevailing time, money, resources and transparency and assess risk from there.&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;/blockquote&gt;&lt;blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"&gt;&lt;p&gt;&lt;span style="color: #333333; font-family: &amp;#39;trebuchet ms&amp;#39;; line-height: normal; "&gt;&lt;span style="font-style: italic;"&gt;Even if the data is not critical/sensitive, I don&amp;#39;t &amp;quot;trust&amp;quot; that it&amp;#39;s not going to be mishandled. Not in today&amp;#39;s world. &amp;#0160;(Ed: How I deal with that mishandling is the secret sauce...)&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;/blockquote&gt;&lt;div&gt;&lt;span style="color: #333333; line-height: normal;"&gt;&lt;span style="font-family: &amp;#39;trebuchet ms&amp;#39;; "&gt;&lt;p style="margin-top: 10px; margin-bottom: 10px; "&gt;I then got thinking about the line that Ronald Reagan is often credited with wherein he described managing relations with the former Soviet Union:&lt;/p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"&gt;&lt;p&gt;&lt;span style="color: #333333; font-family: &amp;#39;trebuchet ms&amp;#39;; line-height: normal; "&gt;&lt;span style="font-style: italic;"&gt;&lt;span style="font-weight: bold;"&gt;Trust but verify&lt;/span&gt;&lt;/span&gt;&lt;span style="font-weight: bold;"&gt;.&lt;/span&gt;&lt;/span&gt;&lt;span style="font-weight: bold;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/p&gt;&lt;/blockquote&gt;&lt;div&gt;&lt;span style="color: #333333; line-height: normal;"&gt;&lt;span style="font-family: &amp;#39;trebuchet ms&amp;#39;; "&gt;&lt;p style="margin-top: 10px; margin-bottom: 10px; "&gt;Security professionals use that phrase a lot. They shouldn&amp;#39;t. It&amp;#39;s oxymoronic.&lt;/p&gt;&lt;p style="margin-top: 10px; margin-bottom: 10px; "&gt;The very definition of &amp;quot;trust&amp;quot; is:&lt;/p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"&gt;&lt;p&gt;&lt;span style="font-family: Baskerville; font-size: 16px; line-height: normal; "&gt;&lt;span class="hw" d:dhw="1" d:priority="2" style="font-size: 150%; "&gt;&lt;span apple_mouseover_highlight="1"&gt;trust&lt;/span&gt;&lt;/span&gt;&lt;span class="pronGrp"&gt;&lt;span class="pr" d:pr="US" style="font-family: HiraMinPro-W3; " type="US"&gt;&amp;#0160;|trəst|&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Baskerville; font-size: 16px; line-height: normal; "&gt;noun&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Baskerville; font-size: 16px; line-height: normal; "&gt;&lt;span class="sn" style="font-weight: 600; "&gt;1&amp;#0160;&lt;/span&gt;&lt;span class="def" style="font-weight: normal; "&gt;&lt;span apple_mouseover_highlight="1"&gt;firm&lt;/span&gt;&amp;#0160;&lt;span apple_mouseover_highlight="1"&gt;belief&lt;/span&gt;&amp;#0160;&lt;span apple_mouseover_highlight="1"&gt;in&lt;/span&gt;&amp;#0160;the reliability, truth, ability, or strength of someone&amp;#0160;&lt;span apple_mouseover_highlight="1"&gt;or something&lt;/span&gt;&amp;#0160;&lt;/span&gt;&lt;span class="ex" d:priority="2" style="font-style: italic; "&gt;&lt;span class="lbl" style="font-weight: normal; "&gt;:&amp;#0160;&lt;/span&gt;relations have to be built on trust&amp;#0160;&lt;/span&gt;&lt;span class="ex" d:priority="2" style="font-style: italic; "&gt;&lt;span class="lbl" style="font-weight: normal; "&gt;|&amp;#0160;&lt;/span&gt;they have been able to win the trust of the others.&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Baskerville; font-size: 16px; line-height: normal; "&gt;&lt;span class="lbl" style="font-family: LucidaGrande; font-size: 80%; "&gt;•&amp;#0160;&lt;/span&gt;&lt;span class="def"&gt;&lt;span style="font-weight: bold;"&gt;acceptance of the truth of a statement without evidence or investigation&amp;#0160;&lt;/span&gt;&lt;/span&gt;&lt;span class="ex" d:priority="2" style="font-style: italic; "&gt;&lt;span class="lbl"&gt;&lt;span style="font-weight: bold;"&gt;:&amp;#0160;&lt;/span&gt;&lt;/span&gt;&lt;span style="font-weight: bold;"&gt;I used only primary sources,&amp;#0160;&lt;/span&gt;&lt;span class="bold" style="font-style: italic; "&gt;&lt;span style="font-weight: bold;"&gt;taking&amp;#0160;&lt;/span&gt;&lt;/span&gt;&lt;span style="font-weight: bold;"&gt;nothing&amp;#0160;&lt;/span&gt;&lt;span class="bold" style="font-style: italic; "&gt;&lt;span style="font-weight: bold;"&gt;on trust&lt;/span&gt;&lt;/span&gt;&lt;span style="font-weight: bold;"&gt;.&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Baskerville; font-size: 16px; line-height: normal; "&gt;&lt;span class="lbl" style="font-family: LucidaGrande; font-size: 80%; "&gt;•&amp;#0160;&lt;/span&gt;&lt;span class="def" style="font-weight: normal; "&gt;the state of being responsible for someone or something&amp;#0160;&lt;/span&gt;&lt;span class="ex" d:priority="2" style="font-style: italic; "&gt;&lt;span class="lbl" style="font-weight: normal; "&gt;:&amp;#0160;&lt;/span&gt;a man in a position of trust.&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Baskerville; font-size: 16px; line-height: normal; "&gt;&lt;span class="lbl" style="font-family: LucidaGrande; font-size: 80%; "&gt;•&amp;#0160;&lt;/span&gt;&lt;span class="regLabel" d:priority="2" style="font-family: HelveticaNeue-Light; font-size: 80%; "&gt;poetic/literary&amp;#0160;&lt;/span&gt;&lt;span class="def" style="font-weight: normal; "&gt;a person or duty for which one has responsibility&amp;#0160;&lt;/span&gt;&lt;span class="ex" d:priority="2" style="font-style: italic; "&gt;&lt;span class="lbl" style="font-weight: normal; "&gt;:&amp;#0160;&lt;/span&gt;rulership is a trust&amp;#0160;&lt;span apple_mouseover_highlight="1"&gt;from&lt;/span&gt;&amp;#0160;God.&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Baskerville; font-size: 16px; line-height: normal; "&gt;&lt;span class="lbl" style="font-family: LucidaGrande; font-size: 80%; "&gt;•&amp;#0160;&lt;/span&gt;&lt;span class="regLabel" d:priority="2" style="font-family: HelveticaNeue-Light; font-size: 80%; "&gt;poetic/literary&amp;#0160;&lt;/span&gt;&lt;span class="def" style="font-weight: normal; "&gt;a hope&amp;#0160;&lt;span apple_mouseover_highlight="1"&gt;or&lt;/span&gt;&amp;#0160;&lt;span apple_mouseover_highlight="1"&gt;expectation&lt;/span&gt;&amp;#0160;&lt;/span&gt;&lt;span class="ex" d:priority="2" style="font-style: italic; "&gt;&lt;span class="lbl" style="font-weight: normal; "&gt;:&amp;#0160;&lt;/span&gt;&lt;span apple_mouseover_highlight="1"&gt;all the&lt;/span&gt;&amp;#0160;&lt;span apple_mouseover_highlight="1"&gt;great&lt;/span&gt;&amp;#0160;trusts of&amp;#0160;&lt;span apple_mouseover_highlight="1"&gt;womanhood&lt;/span&gt;.&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;/blockquote&gt;&lt;div&gt;&lt;span style="color: #333333; line-height: normal;"&gt;&lt;span style="font-family: &amp;#39;trebuchet ms&amp;#39;; "&gt;&lt;p style="margin-top: 10px; margin-bottom: 10px; "&gt;See the second bullet above &amp;quot;....without evidence or investigation&amp;quot;? &amp;#0160;I don&amp;#39;t &amp;quot;trust&amp;quot; people over which I have no effective control. With third parties handling your data, you have no effective &amp;quot;control.&amp;quot; You have the capability to audit, assess and recover, but control? &amp;#0160;Nope.&lt;/p&gt;&lt;p style="margin-top: 10px; margin-bottom: 10px; "&gt;&lt;span style="font-weight: bold;"&gt;Does that mean I think you should not put your information into the hands of a third party? &amp;#0160;Of course not. &amp;#0160;It&amp;#39;s inevitable. &amp;#0160;You already have. However, admitting defeat and working from there may make Jack a dull boy, but he&amp;#39;s also not unprepared for when the bad stuff happens. &amp;#0160;And it will.&lt;/span&gt;&lt;/p&gt;&lt;p style="margin-top: 10px; margin-bottom: 10px; "&gt;I stand by my answer to Allen.&lt;/p&gt;&lt;p style="margin-top: 10px; margin-bottom: 10px; "&gt;You?&lt;/p&gt;&lt;p style="margin-top: 10px; margin-bottom: 10px; "&gt;/Hoff&lt;/p&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;/div&gt;
</content>


    <feedburner:origLink>http://rationalsecurity.typepad.com/blog/2009/02/trust-but-verify-thats-an-oxymoron.html</feedburner:origLink><feedburner:origLink>http://feedproxy.google.com/~r/typepad/nOnJ/~3/X--DGtnQGls/trust-but-verify-thats-an-oxymoron.html</feedburner:origLink></entry>
    <entry>
        <title>What People REALLY Mean When They Say "THE Cloud" Is More Secure...</title>
        <link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/feedburner/rarz/~3/ea71gNqYfcM/what-people-really-mean-when-they-say-the-cloud-is-more-secure.html" />
        <link rel="replies" type="text/html" href="http://rationalsecurity.typepad.com/blog/2009/02/what-people-really-mean-when-they-say-the-cloud-is-more-secure.html" thr:count="6" thr:updated="2009-02-23T07:10:20-05:00" />
        <id>tag:typepad.com,2003:post-63115885</id>
        <published>2009-02-20T11:53:11-05:00</published>
        <updated>2009-02-20T12:07:23-05:00</updated>
        <summary>Over the last two days, I've seen a plethora (yes, Jefe, a plethora) of trade rag and blog articles espousing that The Cloud is more secure than an enterprise's datacenter and that Cloud security concerns are overblown. I'd pick these...</summary>
        <author>
            <name>beaker</name>
        </author>
        <category scheme="http://www.sixapart.com/ns/types#category" term="Cloud Computing" />
        <category scheme="http://www.sixapart.com/ns/types#category" term="Cloud Security" />
        
        <category scheme="http://sixapart.com/ns/types#tag" term="Chris Hoff" />
        <category scheme="http://sixapart.com/ns/types#tag" term="Christofer Hoff" />
        <category scheme="http://sixapart.com/ns/types#tag" term="Cloud" />
        <category scheme="http://sixapart.com/ns/types#tag" term="Cloud Computing" />
        <category scheme="http://sixapart.com/ns/types#tag" term="Cloud Security" />
        <category scheme="http://sixapart.com/ns/types#tag" term="Rational Security" />
        <category scheme="http://sixapart.com/ns/types#tag" term="Rational Survivability" />
        
<content type="xhtml" xml:lang="en-US" xml:base="http://rationalsecurity.typepad.com/blog/">
<div xmlns="http://www.w3.org/1999/xhtml"><p><a href="http://rationalsecurity.typepad.com/.a/6a00d83451be3669e20111688a126e970c-popup" onclick="window.open( this.href, '_blank', 'width=640,height=480,scrollbars=no,resizable=no,toolbar=no,directories=no,location=no,menubar=no,status=no,left=0,top=0' ); return false" style="float: right;"><img alt="Monkeys" class="at-xid-6a00d83451be3669e20111688a126e970c " src="http://rationalsecurity.typepad.com/.a/6a00d83451be3669e20111688a126e970c-200wi" style="width: 200px; margin: 0px 0px 5px 5px;" /></a>
 Over the last two days, I've seen a plethora (yes, <a href="http://www.imdb.com/title/tt0092086/quotes">Jefe</a>, a plethora) of trade rag and blog articles espousing that <a href="http://blogs.computerworld.com/news_flash_the_cloud_is_probably_better_than_your_data_center">The Cloud is more secure than an enterprise's datacenter</a> and that <a href="http://www.networkworld.com/news/2009/021909-cloud-security-fears-are-overblown.html?page=1">Cloud security concerns are overblown</a>.  I'd pick these things apart, but honestly, I've got work to do.</p><div><div>&lt;sigh&gt;</div><br /><div>Here's the problem with these generalizations, even when some of the issues these people describe are actually reasonably good points:</div><br /><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><p>A<span style="font-weight: bold;">lmost all of these references to "better security through Cloudistry" are drawn against examples of Software as a Service (SaaS) offerings.  SaaS is <span style="text-decoration: underline;">not</span> THE Cloud to the exclusion of everything else.  Keep defining SaaS as THE Cloud and you're being intellectually dishonest (and ignorant.)</span></p></blockquote>But since people continue to attest to SaaS==Cloud, let me point out something relevant.<br /><div><span style="font-weight: bold;">There are two classes of SaaS vendors: those that own the entire stack including the platform and underlying infrastructure and those those that don't.  </span><br /><br /><div>Those that have control/ownership over the entire stack naturally have the opportunity for much tighter control over the "security" of their offerings.  Why?  because they run their business and the datacenters and applications housed in them with the same level of diligence that an enterprise would.</div><br /><div>They have context.  They have visibility.  They have control.  They have ownership of the entire stack.  </div><br /><div><span style="font-weight: bold;">The HUGE difference is that in many cases, they only have to deal with supporting a limited number of applications.  This reflects positively on those who say "</span><strike><span style="font-weight: bold;">Cloud </span></strike><span style="font-weight: bold;">SaaS providers are "more secure," mostly because they have less to secure.</span></div><br /><div>Meanwhile those SaaS providers that simply run their appstack atop someone else's platform and infrastructure are, in turn, at the mercy of their providers.  The information and applications are abstracted from the underlying platforms and infrastructure to the point that there is no unified telemetry or context between the two.  Further, add in the multi-tenancy issue and we're now talking about trust boundaries that get very fuzzy and hard to define: who is responsible for securing what.</div><br /><div><span style="font-weight: bold;">Just. Like. An. Enterprise. :(</span></div><br /><div>Check out the Cloud model below which shows the demarcation between the various layers of the SPI model of which SaaS is but ONE:</div><br /><div><a href="http://rationalsecurity.typepad.com/.a/6a00d83451be3669e2011278fea80e28a4-popup" onclick="window.open( this.href, '_blank', 'width=640,height=480,scrollbars=no,resizable=no,toolbar=no,directories=no,location=no,menubar=no,status=no,left=0,top=0' ); return false" style="display: inline;"><img alt="CloudTaxonomyOntology_v14" class="at-xid-6a00d83451be3669e2011278fea80e28a4 " src="http://rationalsecurity.typepad.com/.a/6a00d83451be3669e2011278fea80e28a4-500wi" /></a>
 <br /></div><div>The further up the offering stack you go, the more control you have over your information and the security thereof. Oh, and just one other thing.  The notion that Cloud offerings diminish attack surfaces is in many cases a good thing for sophisticated attackers as much as it may act as a deterrent.  Why?  Because now they have a more clearly defined set of attack surfaces -- usually at the application layer -- that makes their job easier.</div><br /><div>Next time one of these word monkeys makes a case for how much more secure The Cloud is and references a SaaS vendor like SalesForce.com (a single application) in comparison to an enterprise running (and securing) hundreds of applications, remind them about <a href="http://voices.washingtonpost.com/securityfix/2007/11/salesforcecom_acknowledges_dat.html">this</a> and <a href="http://voices.washingtonpost.com/securityfix/2009/01/monstercom_breach_may_bring_mo.html" style="color: blue; text-decoration: underline; cursor: pointer; ">this</a>, both Cloud providers. I wrote about this last year in an article humorously titled "<a href="http://rationalsecurity.typepad.com/blog/2008/11/cloud-providers-are-better-at-securing-your-data-than-you-are.html">Cloud Providers Are Better At Securing Your Data Than You Are.</a>"</div><br /><div>Like I said on Twitter this morning "I *love* the Cloud. I just don't trust it.  Sort of like why I don't give my wife the keys to my motorcycles."</div><br /><div>We done now?</div><br /><div>/Hoff</div><br /></div></div></div>
</content>


    <feedburner:origLink>http://rationalsecurity.typepad.com/blog/2009/02/what-people-really-mean-when-they-say-the-cloud-is-more-secure.html</feedburner:origLink><feedburner:origLink>http://feedproxy.google.com/~r/typepad/nOnJ/~3/1H93nLTZ_3Q/what-people-really-mean-when-they-say-the-cloud-is-more-secure.html</feedburner:origLink></entry>
    <entry>
        <title>Coghead Closes and It's the Death Knell For Cloud Computing!? Holy Hyperbole, Batman!</title>
        <link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/feedburner/rarz/~3/T3TEaPshKtM/coghead-closes-and-its-the-death-knell-for-cloud-computing-holy-hyperbole-batman.html" />
        <link rel="replies" type="text/html" href="http://rationalsecurity.typepad.com/blog/2009/02/coghead-closes-and-its-the-death-knell-for-cloud-computing-holy-hyperbole-batman.html" thr:count="7" thr:updated="2009-02-25T08:30:24-05:00" />
        <id>tag:typepad.com,2003:post-63096081</id>
        <published>2009-02-19T23:04:27-05:00</published>
        <updated>2009-02-19T23:10:20-05:00</updated>
        <summary>This InformationWeek article took artistic license to lofty new levels in a single sentence as it described the demise of Cloud Computing PaaS vendor Coghead and the subsequent IP/Engineering purchase by SAP: Bad news for cloud computing: Coghead -- a...</summary>
        <author>
            <name>beaker</name>
        </author>
        <category scheme="http://www.sixapart.com/ns/types#category" term="Cloud Computing" />
        
        <category scheme="http://sixapart.com/ns/types#tag" term="Chris Hoff" />
        <category scheme="http://sixapart.com/ns/types#tag" term="Christofer Hoff" />
        <category scheme="http://sixapart.com/ns/types#tag" term="Cloud" />
        <category scheme="http://sixapart.com/ns/types#tag" term="Cloud Computing" />
        <category scheme="http://sixapart.com/ns/types#tag" term="Coghead" />
        <category scheme="http://sixapart.com/ns/types#tag" term="InformationWeek" />
        <category scheme="http://sixapart.com/ns/types#tag" term="PaaS" />
        <category scheme="http://sixapart.com/ns/types#tag" term="Rational Security" />
        <category scheme="http://sixapart.com/ns/types#tag" term="Rational Survivability" />
        <category scheme="http://sixapart.com/ns/types#tag" term="SAP" />
        
<content type="xhtml" xml:lang="en-US" xml:base="http://rationalsecurity.typepad.com/blog/">
<div xmlns="http://www.w3.org/1999/xhtml"><p><a href="http://rationalsecurity.typepad.com/.a/6a00d83451be3669e201116888d0da970c-popup" onclick="window.open( this.href, '_blank', 'width=640,height=480,scrollbars=no,resizable=no,toolbar=no,directories=no,location=no,menubar=no,status=no,left=0,top=0' ); return false" style="float: right;"><img alt="Cogheaddead" border="0" class="at-xid-6a00d83451be3669e201116888d0da970c " src="http://rationalsecurity.typepad.com/.a/6a00d83451be3669e201116888d0da970c-800wi" style="margin: 0px 0px 5px 5px;" title="Cogheaddead" /></a>
 <a href="http://www.informationweek.com/news/services/saas/showArticle.jhtml?articleID=214502010&amp;cid=RSSfeed_twitter">This InformationWeek article</a> took artistic license to lofty new levels in a single sentence as it described the demise of Cloud Computing PaaS vendor Coghead and the subsequent IP/Engineering purchase by SAP:</p><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><p><span style="font-family: geneva; font-size: 12px; line-height: normal; "><span style="font-weight: bold;">Bad news for cloud computing</span>: Coghead -- a venture-backed, online application development <a href="http://www.techweb.com/encyclopedia/defineterm.jhtml?term=platform&amp;x=&amp;y=" style="text-decoration: none; color: #0f4692; ">platform</a> -- is closing, leaving customers with a problem to solve.</span></p></blockquote><p><span style="font-family: geneva; font-size: 12px; line-height: normal;"><div><span style="font-family: 'Trebuchet MS'; font-size: 13px; line-height: 15px; ">It's indeed potentially bad news for Coghead's customers who as early adopters took a risk by choosing to invest in a platform startup in an emerging technology sector.  It's hardly indicative of an established trend that somehow predicts "bad news for Cloud Computing" as a whole.</span><br /></div><div><span style="font-family: 'Trebuchet MS'; font-size: 13px; line-height: 15px;"><br /></span></div><div><span style="font-family: 'Trebuchet MS'; font-size: 13px; line-height: 15px;">It's a friendly reminder that "whens you rolls da dice, you takes your chances." Prudent and pragmatic risk assessment and relevant business decisions still have to be made when you decide to place your bets on a startup.  Just because you move to the Cloud doesn't mean you stop employing pragmatic common sense. I hope these customers have a Plan B.</span></div><div><span style="font-family: 'Trebuchet MS'; font-size: 13px; line-height: 15px;"><br /></span></div><div><span style="font-family: 'Trebuchet MS'; font-size: 13px; line-height: 15px;">This is the problem again with lumping all of the *aaS'es into a bucket called Cloud; are we to assume Amazon's AWS (IaaS) and SalesForce.com (SaaS) are going to shutter next week?  No, of course not. Will there be others who close their doors and firesale?  Most assuredly yes, just like there are in most tech markets.</span></div><div><span style="font-family: 'Trebuchet MS'; font-size: 13px; line-height: 15px;"><br /></span></div><div><span style="font-family: 'Trebuchet MS'; font-size: 13px; line-height: 15px;">Here's what Coghead's CEO (in the same article, mind you) explained as the reason for the closure:</span></div></span></p><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><p><span style="font-family: geneva; font-size: 12px; line-height: normal; ">Though McNamara said business was continuing to grow rapidly, the recession ultimately did Coghead in, and Coghead began looking for buyers a few months ago. "Faced with the most difficult economy in <a href="http://www.techweb.com/encyclopedia/defineterm.jhtml?term=memory&amp;x=&amp;y=" style="text-decoration: none; color: #0f4692; ">memory</a> and a challenging fundraising climate, we determined that the SAP deal was the best way forward for the company," McNamara wrote in a letter to customers that went out late Thursday</span></p></blockquote><p>That's correct kids, even the almighty Cloud, the second coming of computing, is not immune to the pressures of running a business in a tough economy, especially the platform business...</p><div>First it was hype around the birth of Cloud and now it's raining epitaphs.  I call dibs on Amazon's SAN arrays!</div><br /><div>/Hoff</div></div>
</content>


    <feedburner:origLink>http://rationalsecurity.typepad.com/blog/2009/02/coghead-closes-and-its-the-death-knell-for-cloud-computing-holy-hyperbole-batman.html</feedburner:origLink><feedburner:origLink>http://feedproxy.google.com/~r/typepad/nOnJ/~3/vbYSxMqhm6Y/coghead-closes-and-its-the-death-knell-for-cloud-computing-holy-hyperbole-batman.html</feedburner:origLink></entry>
    <entry>
        <title>Berkeley RAD Lab Cloud Computing Paper: Above the Clouds or In the Sand?</title>
        <link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/feedburner/rarz/~3/afKBmh2bNas/berkeley-rad-lab-cloud-computing-paper-above-the-clouds-or-in-the-sand.html" />
        <link rel="replies" type="text/html" href="http://rationalsecurity.typepad.com/blog/2009/02/berkeley-rad-lab-cloud-computing-paper-above-the-clouds-or-in-the-sand.html" thr:count="2" thr:updated="2009-02-20T10:50:19-05:00" />
        <id>tag:typepad.com,2003:post-63059687</id>
        <published>2009-02-19T10:33:46-05:00</published>
        <updated>2009-02-19T16:11:27-05:00</updated>
        <summary>I've waffled on how, or even if, I would write my critique of the Berkeley RAD Lab's paper titled "Above the Clouds: A Berkeley View of Cloud Computing." I think I've had a hard time deciding where the authors have...</summary>
        <author>
            <name>beaker</name>
        </author>
        
        <category scheme="http://sixapart.com/ns/types#tag" term="Above the Clouds" />
        <category scheme="http://sixapart.com/ns/types#tag" term="Chris Hoff" />
        <category scheme="http://sixapart.com/ns/types#tag" term="Christofer Hoff" />
        <category scheme="http://sixapart.com/ns/types#tag" term="Christopher Hoff" />
        <category scheme="http://sixapart.com/ns/types#tag" term="Chuck Hollis" />
        <category scheme="http://sixapart.com/ns/types#tag" term="Cisco" />
        <category scheme="http://sixapart.com/ns/types#tag" term="Cloud" />
        <category scheme="http://sixapart.com/ns/types#tag" term="Cloud Computing" />
        <category scheme="http://sixapart.com/ns/types#tag" term="Cloud Security" />
        <category scheme="http://sixapart.com/ns/types#tag" term="David Linthicum" />
        <category scheme="http://sixapart.com/ns/types#tag" term="EMC" />
        <category scheme="http://sixapart.com/ns/types#tag" term="James Urquhart" />
        <category scheme="http://sixapart.com/ns/types#tag" term="RAD Lab" />
        <category scheme="http://sixapart.com/ns/types#tag" term="Rational Security" />
        <category scheme="http://sixapart.com/ns/types#tag" term="Rational Survivability" />
        <category scheme="http://sixapart.com/ns/types#tag" term="UC Berkeley" />
        
<content type="xhtml" xml:lang="en-US" xml:base="http://rationalsecurity.typepad.com/blog/">
<div xmlns="http://www.w3.org/1999/xhtml"><p><a href="http://rationalsecurity.typepad.com/.a/6a00d83451be3669e2011168871bce970c-popup" onclick="window.open( this.href, '_blank', 'width=640,height=480,scrollbars=no,resizable=no,toolbar=no,directories=no,location=no,menubar=no,status=no,left=0,top=0' ); return false" style="float: right;"><img alt="Cal" class="at-xid-6a00d83451be3669e2011168871bce970c " src="http://rationalsecurity.typepad.com/.a/6a00d83451be3669e2011168871bce970c-150wi" style="width: 150px; margin: 0px 0px 5px 5px;" /></a>
 I've waffled on how, or even if, I would write my critique of the Berkeley RAD Lab's paper titled "<a href="http://www.eecs.berkeley.edu/Pubs/TechRpts/2009/EECS-2009-28.pdf">Above the Clouds: A Berkeley View of Cloud Computing.</a>" </p><p>I think I've had a hard time deciding where the authors have their heads, hence the title.</p><p>Those of you who know me are probably chuckling at the fact that I was a good boy and left off the potential third cranial location option...</p><div><div>Many people have written their respective reviews of the work including <a href="http://news.cnet.com/8301-19413_3-10164659-240.html?tag=mncol;title">James Urquhart</a><a href="http://news.cnet.com/8301-19413_3-10164659-240.html?tag=mncol;title"><span style="color: #000000; text-decoration: none;">, </span></a><a href="http://www.intelligententerprise.com/movabletype/blog/dlinthic.html/blog/archives/2009/02/berkley_talks_c.html">David Linthicum</a> and <a href="http://chucksblog.emc.com/chucks_blog/2009/02/enterprise-cloud-wars.html">Chuck Hollis</a> who all did a nice job summarizing various perspectives.</div><br /><div>I decided to add my $0.02 because it occurred to me that despite several issues I have with the paper, two things really haven't been appropriately discussed:</div><div><ol>
<li>The audience for the paper</li>
<li>Expectations of the reader </li>
</ol>
The goals of the paper were fairly well spelled out and within context of what was written, the authors achieved many of them.</div><br /><div>Given that it was described as a "view" of Cloud Computing and not <span style="text-decoration: underline;">the</span> definitive work on the subject, I think perhaps the baby has been unfairly thrown out with the bath water even when balanced with the "danger" that the general public or press may treat it as gospel.</div><br /><div>I think the reason there has been so much frothy reaction to this paper by the "Cloud community" is that because the paper comes from the Electrical Engineering/Computer Science department of UC Berkeley, a certain level of technical depth and a more holistic (dare I say empirical) model for analysis is expected by many readers and their expectations are therefore set a certain way.  </div><br /><div>Most of the reviews that might be perceived as negative are coming from folks who are reasonably technical, of which I am one.<br /></div><br /><div>To that point and that of item #1 above, I don't feel that "we" are the intended audience for this paper and thus, to point #2 above, our expectations -- despite the goals of the paper -- were not met.</div><br /><div>That being said, I <span style="text-decoration: underline;">do</span> have issues with the authors' definition of cloud computing as unnecessarily obtuse, their refusal to discuss the differences between the de facto SPI model and its variants is annoying and short-sighted, and their dismissal of private clouds as relevant is quite disturbing.  The notion that Cloud Computing must be "external" to an enterprise and use the Internet as a transport is simply delusional. <br /></div><br /><div>Eschewing de facto models of reference because the authors could not agree amongst themselves on the differences between them -- despite consensus in industry outside of academia and even models like the one I've been working on -- comes across as myopic and insulated.  </div><br /><div>Ultimately I think the biggest miss of the paper was the fact that they did not successfully answer "What is Cloud Computing and how is it different from previous paradigm shifts such as Software as a Service (SaaS)?"  In fact, I came away from the paper with the feeling that Cloud Computing is SaaS...<br /></div><br /><div>However, I found the coverage of the business drivers, economic issues and the top 10 obstacles to be very good and that people unfamiliar with Cloud Computing would come away with a better understanding -- not necessarily complete -- of the topic.<br /></div><br /><div><div>It was an interesting read that is complimentary to much of the other work going on right now in the field.  I think we should treat it as such and move on.<br /></div><br /><div>/Hoff</div></div></div></div>
</content>


    <feedburner:origLink>http://rationalsecurity.typepad.com/blog/2009/02/berkeley-rad-lab-cloud-computing-paper-above-the-clouds-or-in-the-sand.html</feedburner:origLink><feedburner:origLink>http://feedproxy.google.com/~r/typepad/nOnJ/~3/-A-EULIeUR8/berkeley-rad-lab-cloud-computing-paper-above-the-clouds-or-in-the-sand.html</feedburner:origLink></entry>
    <entry>
        <title>Incomplete Thought: Separating Virtualization From Cloud?</title>
        <link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/feedburner/rarz/~3/8b0LiiGP7gg/incomplete-thought-separating-virtualization-from-cloud.html" />
        <link rel="replies" type="text/html" href="http://rationalsecurity.typepad.com/blog/2009/02/incomplete-thought-separating-virtualization-from-cloud.html" thr:count="16" thr:updated="2009-02-25T20:07:23-05:00" />
        <id>tag:typepad.com,2003:post-63012565</id>
        <published>2009-02-18T10:09:33-05:00</published>
        <updated>2009-02-18T10:12:59-05:00</updated>
        <summary>I was referenced in a CSO article recently titled "Four Questions On Google App Security." I wasn't interviewed for the story directly, but Bill Brenner simply referenced our prior interviews and my skepticism for virtualization security and cloud Security as...</summary>
        <author>
            <name>beaker</name>
        </author>
        <category scheme="http://www.sixapart.com/ns/types#category" term="Cloud Computing" />
        <category scheme="http://www.sixapart.com/ns/types#category" term="Cloud Security" />
        <category scheme="http://www.sixapart.com/ns/types#category" term="Virtualization" />
        
        <category scheme="http://sixapart.com/ns/types#tag" term="Chris Hoff" />
        <category scheme="http://sixapart.com/ns/types#tag" term="Christofer Hoff" />
        <category scheme="http://sixapart.com/ns/types#tag" term="Cloud" />
        <category scheme="http://sixapart.com/ns/types#tag" term="Cloud Computing" />
        <category scheme="http://sixapart.com/ns/types#tag" term="Cloud Security" />
        <category scheme="http://sixapart.com/ns/types#tag" term="CSO" />
        <category scheme="http://sixapart.com/ns/types#tag" term="Dynamic Infrastructure" />
        <category scheme="http://sixapart.com/ns/types#tag" term="f5" />
        <category scheme="http://sixapart.com/ns/types#tag" term="Google" />
        <category scheme="http://sixapart.com/ns/types#tag" term="Lori MacVittie" />
        <category scheme="http://sixapart.com/ns/types#tag" term="Rational Security" />
        <category scheme="http://sixapart.com/ns/types#tag" term="Rational Survivability" />
        <category scheme="http://sixapart.com/ns/types#tag" term="VirtSec" />
        <category scheme="http://sixapart.com/ns/types#tag" term="Virtualization" />
        <category scheme="http://sixapart.com/ns/types#tag" term="Virtualization Security" />
        
<content type="xhtml" xml:lang="en-US" xml:base="http://rationalsecurity.typepad.com/blog/">
<div xmlns="http://www.w3.org/1999/xhtml"><p>I was referenced in a CSO article recently titled "<a href="http://www.csoonline.com/article/471115/Four_Questions_On_Google_App_Security">Four Questions On Google App Security.</a>" I wasn't interviewed for the story directly, but Bill Brenner simply referenced our prior interviews and my skepticism for virtualization security and cloud Security as a discussion point.</p><div>Google's response was interesting and a little tricky given how they immediately set about driving a wedge between virtualization and Cloud.  I think I understand why, but if the article featured someone like Amazon, I'm not convinced it would go the same way...</div><br /><div>As I understand it, Google doesn't really leverage much in the way of virtualization (from the classical compute/hypervisor perspective) for their "cloud" offerings as compared to Amazon. That may be in large part due to the fact of the differences in models and classification -- Amazon AWS is an IaaS play while GoogleApps is a SaaS offering.</div><br /><div>You can see why I made the abstraction layer in the <a href="http://rationalsecurity.typepad.com/blog/2009/01/cloud-computing-taxonomy-ontology-please-review.html">cloud </a><strike><span style="font-family: 'Trebuchet MS'; ">taxonomy/ontology</span></strike><span style="font-family: 'Trebuchet MS'; "> model</span> "optional."</div><br /><div>This post dovetails nicely with Lori MacVittie's article today titled "<a href="http://devcentral.f5.com/weblogs/macvittie/archive/2009/02/18/dynamic-infrastructure-the-cloud-within-the-cloud.aspx">Dynamic Infrastructure: The Cloud Within the Cloud</a>" wherein she highlights how the obfuscation of infrastructure isn't always a good thing. Given my role, what's in that cloudy bubble *does* matter.</div><br /><div>So here's my incomplete thought -- a question, really:</div><br /><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><p><span style="font-weight: bold;">How many of you assume that virtualization is an integral part of cloud computing? From your perspective do you assume one includes the other?  Should you care?</span></p></blockquote><br /><div>Yes, it's intentionally vague.  Have at it.</div><br /><div>/Hoff</div></div>
</content>


    <feedburner:origLink>http://rationalsecurity.typepad.com/blog/2009/02/incomplete-thought-separating-virtualization-from-cloud.html</feedburner:origLink><feedburner:origLink>http://feedproxy.google.com/~r/typepad/nOnJ/~3/3h3W71DzQ5g/incomplete-thought-separating-virtualization-from-cloud.html</feedburner:origLink></entry>
    <entry>
        <title>First Oracle with "Unbreakable" Now IBM "Guarantees Cloud Security"</title>
        <link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/feedburner/rarz/~3/mnaH-QZpYe8/first-oracle-with-unbreakable-now-ibm-guarantees-cloud-security.html" />
        <link rel="replies" type="text/html" href="http://rationalsecurity.typepad.com/blog/2009/02/first-oracle-with-unbreakable-now-ibm-guarantees-cloud-security.html" thr:count="3" thr:updated="2009-02-18T06:26:54-05:00" />
        <id>tag:typepad.com,2003:post-62959773</id>
        <published>2009-02-17T09:04:25-05:00</published>
        <updated>2009-02-17T09:08:23-05:00</updated>
        <summary>I'm heading out in a few minutes for an all day talk, but I choked on my oatmeal when I read this: In a CBR article titled "We Can Guarantee Cloud Security" Kristof Kloeckner, IBM's Cloud Computing CTO was quoted...</summary>
        <author>
            <name>beaker</name>
        </author>
        <category scheme="http://www.sixapart.com/ns/types#category" term="Cloud Computing" />
        <category scheme="http://www.sixapart.com/ns/types#category" term="Cloud Security" />
        
        <category scheme="http://sixapart.com/ns/types#tag" term="Chris Hoff" />
        <category scheme="http://sixapart.com/ns/types#tag" term="Christofer Hoff" />
        <category scheme="http://sixapart.com/ns/types#tag" term="Cloud Computing" />
        <category scheme="http://sixapart.com/ns/types#tag" term="Cloud Security" />
        <category scheme="http://sixapart.com/ns/types#tag" term="IBM" />
        <category scheme="http://sixapart.com/ns/types#tag" term="Rational Security" />
        <category scheme="http://sixapart.com/ns/types#tag" term="Rational Survivability" />
        
<content type="xhtml" xml:lang="en-US" xml:base="http://rationalsecurity.typepad.com/blog/">
<div xmlns="http://www.w3.org/1999/xhtml"><p>I'm heading out in a few minutes for an all day talk, but I choked on my oatmeal when I read this:</p><div>In a CBR article titled "<a href="http://appdev.cbronline.com/news/we_can_guarantee_cloud_security_ibm_170209">We Can Guarantee Cloud Security</a>" Kristof Kloeckner, IBM's Cloud Computing CTO was quoted at the IBM's Pulse 2009 conference as he tried to "...ease worries over security in the cloud":</div><br /><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><p><span style="color: #5c5c5c; font-family: Arial; line-height: normal; ">Despite all the hype surrounding cloud computing, the issue of security is one debate that will not go away. It is regularly flagged as one of the potential stumbling blocks to widespread cloud adoption.</span></p><p><span style="color: #5c5c5c; font-family: Arial; line-height: normal; ">He said: “We’ve developed some interesting technologies that allow the separation of applications and data on the same infrastructure. <span style="font-weight: bold;">We guarantee the security through Tivoli Security and Identity Management and Authentication software,</span> and we also ensure the separation of workloads through the separation of the virtual machines and also the separation of client data in a shared database.”</span> <span style="color: #5c5c5c; font-family: Arial; line-height: normal; ">Speaking to CBR after the press conference, Kloeckner went into more detail about IBM’s cloud security offering.</span></p></blockquote><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><p><span style="color: #5c5c5c; font-family: Arial; line-height: normal; ">“Security is not essentially any different from securing any kind of open environment; you have to ensure that you know who accesses it and control their rights. We have security software that allows you to manage identities from an organisational model, from whoever is entitled to use a particular service. We can actually ensure that best practices are followed,” Kloeckner said.</span></p></blockquote><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><p><span style="color: #5c5c5c; font-family: Arial; line-height: normal; ">Kloeckner added that most people do not realise just how vulnerable they really are. He said: “Most people, unless forced by regulations, usually treat security as a necessary evil. They say it’s very high on their list, but if you really scratch the service, it’s not obvious to me that best practices are followed.”</span></p></blockquote><div><span style="color: #5c5c5c; font-family: Arial; line-height: normal; "><p style="margin-top: 0px; margin-right: 0px; margin-bottom: 0.5em; margin-left: 0px; padding-top: 0px; padding-right: 0px; padding-bottom: 0px; padding-left: 0px; display: block; " /><p style="margin-top: 0px; margin-right: 0px; margin-bottom: 0.5em; margin-left: 0px; padding-top: 0px; padding-right: 0px; padding-bottom: 0px; padding-left: 0px; display: block; "><span style="color: #000000; font-family: 'Trebuchet MS'; line-height: 15px;">I wonder if this guarantee is backed up with anything else short of a "sorry" if something bad happens?</span></p><p style="margin-top: 0px; margin-right: 0px; margin-bottom: 0.5em; margin-left: 0px; padding-top: 0px; padding-right: 0px; padding-bottom: 0px; padding-left: 0px; display: block; "><span style="color: #000000; font-family: 'Trebuchet MS'; line-height: 15px; ">This will make for some very interesting discussion when I return today.</span></p><p style="margin-top: 0px; margin-right: 0px; margin-bottom: 0.5em; margin-left: 0px; padding-top: 0px; padding-right: 0px; padding-bottom: 0px; padding-left: 0px; display: block; "><span style="color: #000000; font-family: 'Trebuchet MS'; line-height: 15px;">/Hoff</span></p><p style="margin-top: 0px; margin-right: 0px; margin-bottom: 0.5em; margin-left: 0px; padding-top: 0px; padding-right: 0px; padding-bottom: 0px; padding-left: 0px; display: block; "><span style="color: #000000; font-family: 'Trebuchet MS'; line-height: 15px;"><br /></span></p></span></div></div>
</content>


    <feedburner:origLink>http://rationalsecurity.typepad.com/blog/2009/02/first-oracle-with-unbreakable-now-ibm-guarantees-cloud-security.html</feedburner:origLink><feedburner:origLink>http://feedproxy.google.com/~r/typepad/nOnJ/~3/lrOb2bADuCA/first-oracle-with-unbreakable-now-ibm-guarantees-cloud-security.html</feedburner:origLink></entry>
    <entry>
        <title>Old MacDonald Had a (Virtual Server) Farm, I/O, I/O, Oh!</title>
        <link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/feedburner/rarz/~3/7i8rapLypCA/old-macdonald-had-a-server-farm-io-io-oh.html" />
        <link rel="replies" type="text/html" href="http://rationalsecurity.typepad.com/blog/2009/02/old-macdonald-had-a-server-farm-io-io-oh.html" thr:count="4" thr:updated="2009-02-14T15:57:46-05:00" />
        <id>tag:typepad.com,2003:post-62839051</id>
        <published>2009-02-13T22:03:07-05:00</published>
        <updated>2009-02-14T10:52:47-05:00</updated>
        <summary>It's all about the I/O and your ability to shuffle packets...or see them in the first place... In reading Neil macDonald's first post under the Gartner-branded blog titled "Virtualization Security Is Transformational -- If the legacy Security Vendors Would Stop...</summary>
        <author>
            <name>beaker</name>
        </author>
        <category scheme="http://www.sixapart.com/ns/types#category" term="Virtualization" />
        
        <category scheme="http://sixapart.com/ns/types#tag" term="Chris Hoff" />
        <category scheme="http://sixapart.com/ns/types#tag" term="Christofer Hoff" />
        <category scheme="http://sixapart.com/ns/types#tag" term="Gartner" />
        <category scheme="http://sixapart.com/ns/types#tag" term="Neil MacDonald" />
        <category scheme="http://sixapart.com/ns/types#tag" term="Rational Security" />
        <category scheme="http://sixapart.com/ns/types#tag" term="Rational Survivability" />
        <category scheme="http://sixapart.com/ns/types#tag" term="VirtSec" />
        <category scheme="http://sixapart.com/ns/types#tag" term="Virtualization" />
        <category scheme="http://sixapart.com/ns/types#tag" term="Virtualization Security" />
        <category scheme="http://sixapart.com/ns/types#tag" term="VMware" />
        
<content type="xhtml" xml:lang="en-US" xml:base="http://rationalsecurity.typepad.com/blog/">
<div xmlns="http://www.w3.org/1999/xhtml"><p><span><span><div><span style="font-family: Arial;"><span style="font-weight: bold;"><span style="font-style: italic; "><span style="font-family: 'Trebuchet MS'; font-style: normal; font-weight: normal; " /><span style="font-family: 'Trebuchet MS'; font-style: normal; font-weight: normal; "><a href="http://rationalsecurity.typepad.com/.a/6a00d83451be3669e2011168628e5e970c-popup" onclick="window.open( this.href, '_blank', 'width=640,height=480,scrollbars=no,resizable=no,toolbar=no,directories=no,location=no,menubar=no,status=no,left=0,top=0' ); return false" style="float: right;"><img alt="Sheep" class="at-xid-6a00d83451be3669e2011168628e5e970c " src="http://rationalsecurity.typepad.com/.a/6a00d83451be3669e2011168628e5e970c-200wi" style="width: 200px; margin: 0px 0px 5px 5px;" /></a>
 </span>It's all about the I/O and your ability to shuffle packets...or see them in the first place...</span></span></span></div><div><span style="font-family: Arial;"><br /></span></div><div><span style="font-family: Arial;">In reading Neil macDonald's first post under the Gartner-branded blog titled "</span><a href="http://blogs.gartner.com/neil_macdonald/2009/02/13/virtualization-security-is-transformational-if-the-legacy-security-vendors-would-stop-fighting-it/">Virtualization Security Is Transformational -- If the legacy Security Vendors Would Stop Fighting It,</a><span style="font-family: Arial;">" I find myself nodding in violent agreement whilst also shaking my head in bewilderment.  Perhaps I missed the point, but I'm really confused.<br /></span></div><div><span style="font-family: Arial;"><br /></span></div><div><span style="font-family: Arial;">Neil sets the stage by suggesting that "established" security vendors who offer solutions for non-virtualized environments simply "...don't get it" when it comes to realizing the shortcomings of their existing solutions in virtualized contexts and that they are "fighting" the encroachment of virtualization on their appliance sales:</span></div><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><p><span style="color: #333333; line-height: 17px; "><span style="font-style: italic;"><span style="font-family: Arial;">Many are clinging to business models based on their overpriced hardware-based solutions and not offering virtualized versions of their solutions. They are afraid of the inevitable disruption (and potential cannibalization) that virtualization will create. However, you and I have real virtualization security needs today and smaller innovative startups have rushed in to fill the gap. And, yes, there are pricing discontinuities. A firewall appliance that costs $25,000 in a physical form can cost $2500 or less in a virtual form from startups like Altor Networks or Reflex Systems.</span></span></span></p></blockquote><span style="color: #333333; line-height: 17px; "><span style="font-family: Arial;"><span style="font-weight: bold;">I'm very interested in which "established" vendors are supposedly clinging to their overpriced hardware-based solutions and avoiding virtualization besides niche players in niche markets that are hardware-bound.  </span></span></span></span></span></p><div><span><span><span style="color: #333333; line-height: 17px; "><span style="font-family: Arial;"><span style="font-weight: bold;">As far as I can tell the top five vendors by revenue in the security space (that sell hardware, not just software) are all actively engaged in both supporting these environments with the limitations that currently exist based on the virtualization platforms today and are very much investing in development of new solutions to work properly in virtual environments given the unique requirements thereof.</span></span></span></span></span><div><span style="color: #333333; line-height: 17px; "><span style="font-family: Arial;"><br /></span></span></div><div><span style="color: #333333; line-height: 17px; "><span style="font-family: Arial;">Neil is really comparing apples to muffler brackets.  He points out in his blog that physical appliances can offer multi-gigabit performance whereas software-based VA's cannot, and yet we're surprised that pricing differentials in orders of magnitude exist?  You get what you pay for.<br /></span></span><div><span><span><span style="font-family: Arial;"><span style="color: #333333; line-height: 17px; " /></span></span><div><span style="color: #333333; line-height: 17px; "><span style="font-family: Arial;"><br /></span></span></div><div><span style="font-family: Arial;"><span /></span><span style="color: #333333; line-height: 17px; "><span style="font-family: Arial;">As I pointed out in my </span></span><a href="http://rationalsecurity.typepad.com/blog/2008/08/complete-slides.html"><span style="font-family: Arial;">Four Horsemen presentation</span></a><span style="color: #333333; line-height: 17px; "><span style="font-family: Arial;"> (and is alluded to in the remainder of Neil's post below) EVERY SINGLE VENDOR is currently hamstrung by the same level of integration and architectural limitations involved with the current state of virtual appliance performance in the security space, including those he mentions such as Altor and Reflex.  They are all in a holding pattern.  I've written about that numerous times.</span></span></div><div><span style="color: #333333; line-height: 17px; "><span style="font-family: Arial;"><br /></span></span></div><div><span style="color: #333333; line-height: 17px; "><span style="font-family: Arial;">In fact, as I mentioned in my post titled "</span></span><a href="http://rationalsecurity.typepad.com/blog/2008/06/visualization-t.html"><span style="font-family: Arial;">Visualization Through Virtualization</span></a><span style="color: #333333; line-height: 17px; "><span style="font-family: Arial;">", the majority of these new-fangled, virtualization-specific "security" tools are actually (now) more focused on visibility, management and change montoring/control than they are pure network-level security because they cannot compete from a performance and scalability perspective with hardware-based solutions.</span></span></div><div><span style="color: #333333; line-height: 17px; "><span style="font-family: Arial;"><br /></span></span></div><div><span style="color: #333333; line-height: 17px; "><span style="font-family: Arial;">Here's where I do agree with Neil, based upon what I mention above: </span></span><div><span><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><p><span style="color: #333333; line-height: 17px; "><span style="font-style: italic;"><span style="font-family: Arial;">Feature-wise, the security protection services delivered are similar. But, there is a key difference — throughput. What the legacy security vendors forget is that there is still a role for dedicated hardware. There is no way you are going to get full multi-gigabit line speed deep-packet inspection and protocol decode for intrusion prevention from a virtual appliance. A next-generation data center will need </span></span><span style="padding-top: 0px; padding-right: 0px; padding-bottom: 0px; padding-left: 0px; margin-top: 0px; margin-right: 0px; margin-bottom: 0px; margin-left: 0px; font-size: 13px !important; line-height: 18px; "><span style="font-style: italic;"><span style="font-family: Arial;">both</span></span></span><span style="font-style: italic;"><span style="font-family: Arial;"> physical and virtualized security controls — ideally, from a vendor that can provide both. I’ll argue that the move to virtualize security controls will grow the overall use of security controls. </span></span></span></p></blockquote><span style="color: #333333; font-style: italic; line-height: 17px; "><span style="font-style: normal;"><span style="font-family: Arial;">So this actually explains the disparity in both approach and pricing that he alluded to above.  How does this represent vendors "fighting" virtualization?  I see it as hanging on for as long as possible to preserve and milk their investment in the physical appliances Neil says we'll still need while they perform the R&amp;D on their virtualized versions.  They can't deploy the new solutions until the platform to support them exists!</span></span></span><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><p><span style="color: #333333; line-height: 17px; "><span style="font-style: italic;"><span style="font-family: Arial;">The move to virtualize security controls reduces barriers to adoption. Rather than a sprinkle a few physical appliance here and there based on network topology, we can now place controls when and where they are needed, including physical appliances as appropriate. If fact, the legacy vendors have a distinct advantage over virtualization security startups since you prefer a security solution that spans both your physical and virtual environments with consistent management.</span></span></span></p></blockquote><span style="color: #333333; line-height: 17px; "><span style="font-family: Arial;">Exactly.  So again, how is this "fighting" virtualization?  </span></span></span></div><div><span style="color: #333333; line-height: 17px; "><span style="font-family: Arial;"><br /></span></span></div><div><span><span style="color: #333333; line-height: 17px; "><span style="font-family: Arial;">Here's where we ignore reality again:</span></span><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><p><span style="color: #333333; line-height: 17px; "><span style="font-style: italic;"><span style="font-family: Arial;">Over the past six months, I’ve seen signs of life from the legacy physical security vendors. However, some of the legacy physical security vendors have simply taken the code from their physical appliance and moved it into a virtual machine. This is like wrapping a green-screen terminal application with a web front end — it looks better, but the guts haven’t changed. In a data center where workloads move dynamically between physical servers and between data centers, it makes no sense to link security policy to static attributes such as TCP/IP addresses, MAC addresses or servers. </span></span></span></p></blockquote><span style="color: #333333; line-height: 17px; "><span style="font-family: Arial;">First of all, what we're really talking about in the enterprise space is VMware, since given its market dominance, this is where the sweet spot is for security vendors.  This will change over time, but for now, it's VMware.</span></span></span></div><div><span style="color: #333333; line-height: 17px; "><span style="font-family: Arial;"><br /></span></span></div><div><span><span style="color: #333333; line-height: 17px; "><span style="font-family: Arial;">That being the case, the moment VMsafe was announced/hinted at two years ago, 20+ security vendors -- big and small -- have been diligently working within the constructs of what is made available from VMware to re-engineer their products to take advantage of the API's that will be coming in VMware's upcoming release.  This is no small feat.  Distributed virtual switching and the two-tier driver architecture with DVfilters means re-engineering your products and approach.</span></span></span></div><div><span style="color: #333333; line-height: 17px; "><span style="font-family: Arial;"><br /></span></span></div><div><span><span style="color: #333333; line-height: 17px; "><span style="font-family: Arial;"><span style="font-weight: bold;">Until VMware's next platform is released, every security vendor -- big or small -- is hamstrung by having to do exactly what Neil says; creating a software instantiation of their hardware products which is integration-limited for the reasons I've already stated.  What should vendors do?  Firesale their inventories and wait it out?  </span></span></span></span></div><div><span style="color: #333333; line-height: 17px; "><span style="font-family: Arial;"><span style="font-weight: bold;"><br /></span></span></span></div><div><span style="color: #333333; line-height: 17px; "><span style="font-family: Arial;"><span style="font-weight: bold;">I ask again: how is this "fighting" virtualization?</span></span></span></div><div><span style="color: #333333; line-height: 17px; "><span style="font-family: Arial;"><br /></span></span></div><div><span style="color: #333333; line-height: 17px; "><span style="font-family: Arial;">The reason there hasn't been a lot of movement is because the entire industry is in a holding pattern. Pretending otherwise is absolutely ridiculous.  The obvious exception is Cisco which has invested in and developed substantial solutions such as the Nexus 1000v and VN-Link (which is again awaiting the availability of VMware's next release.)</span></span></div><div><span><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><p><span style="color: #333333; line-height: 17px; "><span style="font-style: italic;"><span style="font-family: Arial;">Security policy in a virtualized environment must be tied to logical identities - like identities of VM workloads, identities of application flows and identities of users. When VMs move, policies need to move. This requires more than a mere port of an existing solution, it requires a new mindset.</span></span></span></p></blockquote><span style="color: #333333; line-height: 17px; "><span style="font-family: Arial;">Yep.  And most of them are adapting their products as best they can.  Many companies will follow the natural path of consolidation and wait to buy a startup in this space and integrate it...much like VMware did with BlueLane, for example.  Others will look to underlying enablers such as Cisco's VN-Link/Nexus 1000v and chose to integrate at the virtual networking layer there and/or in coordination with VMsafe.</span></span><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><p><span style="color: #333333; line-height: 17px; "><span style="font-style: italic;"><span style="font-family: Arial;">The legacy vendors need to wake up. If they don’t offer robust virtualization security capabilities (and, yes, potentially cannibalize the sales of some of their hardware), another vendor will. With virtualization projects on the top of the list of IT initiatives for 2009, we can’t continue to limp along without protection. It’s time to vote with our wallets and make support of virtual environments a mandatory part of our security product evaluation and selection.</span></span></span></p></blockquote><span style="color: #333333; line-height: 17px; "><span style="font-family: Arial;">Absolutely!  And every vendor -- big and small -- that I've spoken to is absolutely keen on this concept and are actively engaged in developing solutions for these environments with these unique requirements in mind. Keep in mind that VMsafe is about more than just network visibility via the VMM, it also includes disk, memory and CPU...most network-based appliances have never had this sort of access before (since they are NETWORK appliances) and so OF COURSE products will have to be re-tooled.<br /></span></span><div><span style="font-family: Arial;"><br /></span></div><div><span style="font-family: Arial;">Overall, I'm very confused by Neil's post as it seems quite contradictory and at odds with what I've personally been briefed on by vendors in the space and overlooks the huge left turns being made by vendors over the last 18 months who have been patiently waiting for VMsafe and other introspection capabilities of the underlying platforms.</span></div><div><span style="font-family: Arial;"><br /></span></div><div><span style="font-family: Arial;">I think the windshield needs cleaning on the combine harvester...</span></div><div><span style="font-family: Arial;"><br /></span></div><div><span style="font-family: Arial;">/Hoff</span></div></span></div></div></span><br /></div></div></div></div>
</content>


    <feedburner:origLink>http://rationalsecurity.typepad.com/blog/2009/02/old-macdonald-had-a-server-farm-io-io-oh.html</feedburner:origLink><feedburner:origLink>http://feedproxy.google.com/~r/typepad/nOnJ/~3/8EkqLCSyWcw/old-macdonald-had-a-server-farm-io-io-oh.html</feedburner:origLink></entry>
    <entry>
        <title>Cisco Is NOT Getting Into the Server Business...</title>
        <link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/feedburner/rarz/~3/pmYIvYDVksU/cisco-is-not-getting-into-the-server-business.html" />
        <link rel="replies" type="text/html" href="http://rationalsecurity.typepad.com/blog/2009/02/cisco-is-not-getting-into-the-server-business.html" thr:count="4" thr:updated="2009-02-24T06:48:23-05:00" />
        <id>tag:typepad.com,2003:post-62794697</id>
        <published>2009-02-13T11:01:06-05:00</published>
        <updated>2009-02-13T11:13:11-05:00</updated>
        <summary>Yes, yes. We've talked about this before here. Cisco is introducing a blade chassis that includes compute capabilities (heretofore referred to as a 'blade server.') It also includes networking, storage and virtualization all wrapped up in a tidy bundle. So...</summary>
        <author>
            <name>beaker</name>
        </author>
        <category scheme="http://www.sixapart.com/ns/types#category" term="Cisco" />
        <category scheme="http://www.sixapart.com/ns/types#category" term="Cloud Computing" />
        <category scheme="http://www.sixapart.com/ns/types#category" term="Cloud Security" />
        
        <category scheme="http://sixapart.com/ns/types#tag" term="Chris Hoff" />
        <category scheme="http://sixapart.com/ns/types#tag" term="Christofer Hoff" />
        <category scheme="http://sixapart.com/ns/types#tag" term="Cisco" />
        <category scheme="http://sixapart.com/ns/types#tag" term="Network Security" />
        <category scheme="http://sixapart.com/ns/types#tag" term="Nexus" />
        <category scheme="http://sixapart.com/ns/types#tag" term="Nexus 1000v" />
        <category scheme="http://sixapart.com/ns/types#tag" term="Rational Security" />
        <category scheme="http://sixapart.com/ns/types#tag" term="Rational Survivability" />
        <category scheme="http://sixapart.com/ns/types#tag" term="Unified Computing" />
        <category scheme="http://sixapart.com/ns/types#tag" term="VirtSec" />
        <category scheme="http://sixapart.com/ns/types#tag" term="Virtualization" />
        <category scheme="http://sixapart.com/ns/types#tag" term="Virtualization Security" />
        <category scheme="http://sixapart.com/ns/types#tag" term="VN-Link" />
        
<content type="xhtml" xml:lang="en-US" xml:base="http://rationalsecurity.typepad.com/blog/">
<div xmlns="http://www.w3.org/1999/xhtml"><p><a href="http://rationalsecurity.typepad.com/.a/6a00d83451be3669e2011278d6787328a4-popup" onclick="window.open( this.href, '_blank', 'width=640,height=480,scrollbars=no,resizable=no,toolbar=no,directories=no,location=no,menubar=no,status=no,left=0,top=0' ); return false" style="float: left;"><img alt="Walklikeaduck" class="at-xid-6a00d83451be3669e2011278d6787328a4 " src="http://rationalsecurity.typepad.com/.a/6a00d83451be3669e2011278d6787328a4-200wi" style="width: 200px; margin: 0px 5px 5px 0px;" /></a>
 Yes, yes. We've talked about this before <a href="http://rationalsecurity.typepad.com/blog/2008/12/servers-and-switches-and-vmms-oh-my-ciscos-california-server-switch-.html">here</a>. Cisco is introducing a blade chassis that includes compute capabilities (heretofore referred to as a 'blade server.')  It also includes networking, storage and virtualization all wrapped up in a tidy bundle.</p><div>So while that looks like a blade server (quack!,) walks like a blade server (quack! quack!) that doesn't mean it's going to be positioned, talked about or sold like a blade server (quack! quack! quack!)</div><br /><div>What's my point?  What Cisco is building is just another building block of virtualized INFRASTRUCTURE. Necessary infrastructure to ensure control and relevance as their customers' networks morph.</div><br /><div>My point is that what Cisco is building is the natural by-product of converged technologies with an approach that deserves attention.  It *is* unified computing.  It's a solution that includes integrated capabilities that otherwise customers would be responsible for piecing together themselves...and that's one of the biggest problems we have with disruptive innovation today: integration.</div><br /><div>While the analysts worry about margin erosion and cannibalizing the ecosystem (which is inevitable as a result of both innovation and consolidation,) this is a great move for Cisco, especially when you recognize that if they didn't do this, the internalization of network and storage layers within the virtualization platforms  would otherwise cause them to lose relevance beyond dumb plumbing in virtualized and cloud environments.</div><br /><div>Also, let us not forget that one of the beauties of having this "end-to-end" solution from a security perspective is the ability to leverage policy across not only the network, but compute and storage realms also.  You can whine (and I have) about the quality of the security functionality offered by Cisco, but the coverage you're going to get with centralized policy that has affinity across the datacenter (and beyond,) iis  going to be hard to beat.</div><br /><div>(There, I said it...OMG, I'm becoming a fanboy!)</div><br /><div>And as far as competency as a "server" vendor, c'mon. Firstly, you can't swing a dead cat without hitting a commoditzed PC architecture that Joe's Crab Shack could market as a solution and besides which, that's what ODM's are for.  I'm sure we'll see just as much "buy and ally" with the build as part of this process. </div><br /><div>What's the difference between a blade chassis with intel line processors and integrated networking and a switch these days?  Not much.</div><br /><div>So, what Cisco may lose in margin in the "server" sale, they will by far make up with the value people will pay for with converged compute, network, storage, virtualization, management, VN-Link, the Nexus 1000v, security and the integrated one-stop-shopping you'll get.  And if folks want to keep buying their HP's and IBM's, they have that choice, too.</div><br /><p>QUACK!</p><div><br /><div>/Hoff</div></div></div>
</content>


    <feedburner:origLink>http://rationalsecurity.typepad.com/blog/2009/02/cisco-is-not-getting-into-the-server-business.html</feedburner:origLink><feedburner:origLink>http://feedproxy.google.com/~r/typepad/nOnJ/~3/495SphDlUyY/cisco-is-not-getting-into-the-server-business.html</feedburner:origLink></entry>
    <entry>
        <title>Incomplete Thought: What Should Come First...Cloud Portability or Interoperability</title>
        <link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/feedburner/rarz/~3/XSrrBzPNwT0/incomplete-thought-what-should-come-firstcloud-portability-or-interoperability.html" />
        <link rel="replies" type="text/html" href="http://rationalsecurity.typepad.com/blog/2009/02/incomplete-thought-what-should-come-firstcloud-portability-or-interoperability.html" thr:count="5" thr:updated="2009-02-16T05:57:55-05:00" />
        <id>tag:typepad.com,2003:post-62788733</id>
        <published>2009-02-13T08:37:17-05:00</published>
        <updated>2009-02-13T08:37:17-05:00</updated>
        <summary>It seems that my incomplete thoughts are more popular with folks than the one's I take the time to think all the way through and conclude, so here's the next one... Here it is: There is a lot of effort...</summary>
        <author>
            <name>beaker</name>
        </author>
        <category scheme="http://www.sixapart.com/ns/types#category" term="Cloud Computing" />
        <category scheme="http://www.sixapart.com/ns/types#category" term="Cloud Security" />
        
        <category scheme="http://sixapart.com/ns/types#tag" term="Chris Hoff" />
        <category scheme="http://sixapart.com/ns/types#tag" term="Christofer Hoff" />
        <category scheme="http://sixapart.com/ns/types#tag" term="Christopher Hoff" />
        <category scheme="http://sixapart.com/ns/types#tag" term="Cloud" />
        <category scheme="http://sixapart.com/ns/types#tag" term="Cloud Computing" />
        <category scheme="http://sixapart.com/ns/types#tag" term="Cloud Interoperability" />
        <category scheme="http://sixapart.com/ns/types#tag" term="Cloud Portability" />
        <category scheme="http://sixapart.com/ns/types#tag" term="Cloud Security" />
        <category scheme="http://sixapart.com/ns/types#tag" term="Rational Security" />
        <category scheme="http://sixapart.com/ns/types#tag" term="Rational Survivability" />
        
<content type="xhtml" xml:lang="en-US" xml:base="http://rationalsecurity.typepad.com/blog/">
<div xmlns="http://www.w3.org/1999/xhtml"><p><a href="http://rationalsecurity.typepad.com/.a/6a00d83451be3669e20111685ffe0a970c-popup" onclick="window.open( this.href, '_blank', 'width=640,height=480,scrollbars=no,resizable=no,toolbar=no,directories=no,location=no,menubar=no,status=no,left=0,top=0' ); return false" style="float: right;"><img alt="Chickenegg" class="at-xid-6a00d83451be3669e20111685ffe0a970c " src="http://rationalsecurity.typepad.com/.a/6a00d83451be3669e20111685ffe0a970c-150wi" style="width: 150px; margin: 0px 0px 5px 5px;" /></a>
 It seems that my incomplete thoughts are more popular with folks than the one's I take the time to think all the way through and conclude, so here's the next one...</p><br /><div>Here it is:</div><div><span style="font-weight: bold;"><span style="font-style: italic;"><br /></span></span></div><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><p><span style="font-weight: bold;"><span style="font-style: italic;">There is a lot of effort being spent now on attempts to craft standards and definitions in order to provide interfaces which allow discrete Cloud elements and providers to interoperate. Should we not <span style="text-decoration: underline;">first</span> focus our efforts on ensuring portability between Clouds of our atomic instances (however you wish to define them) and the metastructure* that enables them?</span></span></p></blockquote><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><br /></blockquote><div>/Hoff</div><br /><div>*Within this context I mean 'metastructure' to define not only the infrastructure but all the semantic configuration information and dynamic telemetry needed to support such.</div></div>
</content>


    <feedburner:origLink>http://rationalsecurity.typepad.com/blog/2009/02/incomplete-thought-what-should-come-firstcloud-portability-or-interoperability.html</feedburner:origLink><feedburner:origLink>http://feedproxy.google.com/~r/typepad/nOnJ/~3/KssBC2yd2_s/incomplete-thought-what-should-come-firstcloud-portability-or-interoperability.html</feedburner:origLink></entry>
    <entry>
        <title>Dear Mr. Oberlin: Here's Your Sign...</title>
        <link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/feedburner/rarz/~3/gWLN_nVvTiY/dear-mr-oberlin-heres-your-sign.html" />
        <link rel="replies" type="text/html" href="http://rationalsecurity.typepad.com/blog/2009/02/dear-mr-oberlin-heres-your-sign.html" thr:count="4" thr:updated="2009-02-12T17:48:15-05:00" />
        <id>tag:typepad.com,2003:post-62718507</id>
        <published>2009-02-11T18:56:57-05:00</published>
        <updated>2009-02-13T16:43:14-05:00</updated>
        <summary>No Good Deed Goes Unpunished... I've had some fantastic conversations with folks over the last couple of weeks as we collaborated from the perspective of how a network and security professional might map/model/classify various elements of Cloud Computing. I just...</summary>
        <author>
            <name>beaker</name>
        </author>
        <category scheme="http://www.sixapart.com/ns/types#category" term="Cloud Computing" />
        <category scheme="http://www.sixapart.com/ns/types#category" term="Cloud Security" />
        
        <category scheme="http://sixapart.com/ns/types#tag" term="Cassatt" />
        <category scheme="http://sixapart.com/ns/types#tag" term="Chris Hoff" />
        <category scheme="http://sixapart.com/ns/types#tag" term="Christofer Hoff" />
        <category scheme="http://sixapart.com/ns/types#tag" term="Cloud Computing" />
        <category scheme="http://sixapart.com/ns/types#tag" term="Cloud Ontology" />
        <category scheme="http://sixapart.com/ns/types#tag" term="Cloud Security" />
        <category scheme="http://sixapart.com/ns/types#tag" term="Cloud Taxonomy" />
        <category scheme="http://sixapart.com/ns/types#tag" term="Rational Security" />
        <category scheme="http://sixapart.com/ns/types#tag" term="Rational Survivability" />
        <category scheme="http://sixapart.com/ns/types#tag" term="Steve Oberlin" />
        <category scheme="http://sixapart.com/ns/types#tag" term="William Vanbenepe" />
        
<content type="xhtml" xml:lang="en-US" xml:base="http://rationalsecurity.typepad.com/blog/">
<div xmlns="http://www.w3.org/1999/xhtml"><div><div><span style="font-family: Arial; font-size: 12px; line-height: normal; -webkit-border-horizontal-spacing: 2px; -webkit-border-vertical-spacing: 2px; "><div><a href="http://rationalsecurity.typepad.com/.a/6a00d83451be3669e20111685bf6ae970c-popup" onclick="window.open( this.href, '_blank', 'width=640,height=480,scrollbars=no,resizable=no,toolbar=no,directories=no,location=no,menubar=no,status=no,left=0,top=0' ); return false" style="float: right;"><img alt="Thanksfornothing" class="at-xid-6a00d83451be3669e20111685bf6ae970c " src="http://rationalsecurity.typepad.com/.a/6a00d83451be3669e20111685bf6ae970c-200wi" style="width: 200px; margin: 0px 0px 5px 5px;" /></a>
 <span style="font-weight: bold;"><span style="font-style: italic; ">No Good Deed Goes Unpunished...</span></span></div><br /><div>I've had some fantastic conversations with folks over the last couple of weeks as we collaborated from the perspective of how a network and security professional might <a href="http://rationalsecurity.typepad.com/blog/2009/01/cloud-computing-taxonomy-ontology-please-review.html">map/model/classify</a> various elements of Cloud Computing.</div><br /><div>I just spent several hours with folks at ShmooCon (a security conference) winding through the model with my peers getting excellent feedback.  </div><br /><div>Prior to that, I've had many people say that the collaboration has yielded a much simpler view on what the Cloud means to them and how to align solutions sets they already have and find gaps with those they don't.</div><br /><div>My goal was to share my thinking in a way which helps folks with a similar bent get a grasp on what this means to them.  I'm happy with the results.</div><br /><div><span style="font-weight: bold;"><span style="font-style: italic;">And then....one day at Cloud Camp...</span></span></div><br /><div>However, it seems I chose an unfortunate way of describing what I was doing in calling it a taxonomy/ontology, despite what I still feel is a clear definition of these words as they apply to the work.</div><br /><div>I say unfortunate because I came across a post by Steve Oberlin, Cassat's Chief Scientist on his "Cloudology" blog titled "<a href="http://steveoberlin.com/cloudology/?p=12">Cloud Burst</a>" that resonates with me as the most acerbic, condescending and pompous contributions to nothingness I have read in a long time.</div><br /><div>Steve took 9 paragraphs and 7,814 characters to basically say that he doesn't like people using the words taxonomy or ontology to describe efforts to discuss and model Cloud Computing and that we're all idiots and have provided nothing of use.</div><br /><div>The most egregiously offensive comment was one of his last points:</div></span></div></div><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><p><span style="font-size: 14px; line-height: 18px; "><span style="font-style: italic; font-size: 12px; font-family: 'Trebuchet MS'; ">I do think some blame (a mild chastisement) is owed to anyone participating in the cloud taxonomy conversation that is not exercising appropriately-high levels of skepticism and insisting on well-defined and valid standards in their frameworks.  Taxonomies are thought-shaping tools and bad tools make for bad thinking.   One commenter on one of the many blogs echoing/amplifying the taxonomy conversation remarked that some of the diagrams were mere “marketecture” and others warned against special interests warping the framework to suit their own ends.  We should all be such critical thinkers.</span></span></p></blockquote><div><span style="font-size: 14px; font-style: italic; line-height: 18px; "><span style="font-size: 12px; font-style: normal; line-height: normal; -webkit-border-horizontal-spacing: 2px; -webkit-border-vertical-spacing: 2px; "><span style="font-family: Arial;">What exactly in any of my efforts (since I'm not speaking for anyone else) suggests that in collaborating and opening up the discussion for unfettered review and critique, constitutes anything other than high-levels of skepticism?  The reason I built the model in the first place was because I didn't feel the others accurately conveyed what was relevant and important from my perspective.  I was, gasp!, skeptical. </span></span></span></div><div><span style="font-size: 12px; line-height: normal; -webkit-border-horizontal-spacing: 2px; -webkit-border-vertical-spacing: 2px; "><span style="font-family: Arial;"><br /></span></span></div><div><span style="font-size: 12px; line-height: normal; -webkit-border-horizontal-spacing: 2px; -webkit-border-vertical-spacing: 2px; "><span style="font-family: Arial;">We definitely don't want to have discussions that might "shape thought."  That would be dangerous.  Shall we start burning books too?<br /></span></span></div><div><span style="font-size: 12px; line-height: normal; -webkit-border-horizontal-spacing: 2px; -webkit-border-vertical-spacing: 2px; "><span style="font-family: Arial;"><br /></span></span></div><div><span style="font-family: Arial; font-size: 12px; line-height: normal; -webkit-border-horizontal-spacing: 2px; -webkit-border-vertical-spacing: 2px;"><span style="font-style: italic; font-weight: bold; ">From the Department of I've Had My Digits Trampled..</span><br /></span></div><div><span style="font-family: Arial; font-size: 12px; font-style: italic; font-weight: bold; line-height: normal; -webkit-border-horizontal-spacing: 2px; -webkit-border-vertical-spacing: 2px;"><br /></span></div><div><span style="font-size: 14px; font-style: italic; line-height: 18px; "><span style="font-size: 12px; font-style: normal; line-height: normal; -webkit-border-horizontal-spacing: 2px; -webkit-border-vertical-spacing: 2px; "><span style="font-family: Arial;">So what I extracted from Oberlin's whine is that we are all to be chided because somehow only he possesses the yardstick against which critical thought can be measured?  I loved this bit as he reviewed my contribution:</span></span></span></div><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><p><span style="font-size: 14px; line-height: 18px; "><span style="font-style: italic; font-size: 12px; font-family: 'Trebuchet MS'; ">I might find more constructive criticism to offer, but the dearth of description and discussion of what it really means (beyond the blog’s comments, which were apparently truncated by TypePad) make the diagram something of a Rorschach test.  Anyone discussing it may be revealing more about themselves than what the concepts suggested by the diagram might actually mean</span><span style="font-style: italic; font-size: 12px; font-family: Arial; ">.</span></span></p></blockquote><div><span style="font-family: Arial;">Interestingly, over 60 other people have stooped low enough to add their criticism and input without me "directing" their interpretation so as not to be constraining, but again, somehow this is a bad thing.</span><span style="font-family: Arial;"><span style="font-size: 12px; line-height: normal; -webkit-border-horizontal-spacing: 2px; -webkit-border-vertical-spacing: 2px; " /></span></div><div><span style="font-size: 12px; line-height: normal; -webkit-border-horizontal-spacing: 2px; -webkit-border-vertical-spacing: 2px; "><span style="font-family: Arial;"><br /></span></span></div><div><span style="font-size: 12px; line-height: normal; -webkit-border-horizontal-spacing: 2px; -webkit-border-vertical-spacing: 2px; "><span style="font-family: Arial;">So after sentencing to death all those poor electrons that go into rendering his rant about how the rest of us are pissing into the wind, what did Oberlin do to actually help clarify Cloud Computing?  What wisdom did he impart to set us all straight?  How did he contribute to the community effort -- no matter how misdirected we may be -- to make sense of all this madness?</span></span><span style="font-family: Arial;"><br /></span></div><div><span style="font-size: 12px; line-height: normal; -webkit-border-horizontal-spacing: 2px; -webkit-border-vertical-spacing: 2px; "><span style="font-family: Arial;"><br /></span></span></div><div><span style="font-size: 12px; line-height: normal; -webkit-border-horizontal-spacing: 2px; -webkit-border-vertical-spacing: 2px; "><span style="font-family: Arial;">Let me be much more concise than the 7,814 characters Oberlin needed and sum it up in 8:</span></span></div><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><p><span style="font-size: 12px; line-height: normal; -webkit-border-horizontal-spacing: 2px; -webkit-border-vertical-spacing: 2px; "><span style="font-weight: bold;"><span style="font-family: Arial;">NOTHING.</span></span></span></p></blockquote><div><span style="font-size: 12px; line-height: normal; -webkit-border-horizontal-spacing: 2px; -webkit-border-vertical-spacing: 2px; "><span style="font-family: Arial;">So it is with an appropriate level of reciprocity that I thank him for it accordingly.</span></span></div><div><span style="font-size: 12px; line-height: normal; -webkit-border-horizontal-spacing: 2px; -webkit-border-vertical-spacing: 2px; "><span style="font-family: Arial;"><br /></span></span></div><div><span style="font-size: 12px; line-height: normal; -webkit-border-horizontal-spacing: 2px; -webkit-border-vertical-spacing: 2px; "><span style="font-family: Arial;"> /Hoff</span></span></div><div><span style="font-size: 12px; line-height: normal; -webkit-border-horizontal-spacing: 2px; -webkit-border-vertical-spacing: 2px; "><span style="font-family: Arial;"><br /></span></span></div><div><span style="font-size: 12px; line-height: normal; -webkit-border-horizontal-spacing: 2px; -webkit-border-vertical-spacing: 2px; "><strike><strike>P.S. Not to be outdone, </strike></strike></span><a href="http://stage.vambenepe.com/archives/530"><strike>William Vanbenepe</strike></a><span style="font-size: 12px; line-height: normal; -webkit-border-horizontal-spacing: 2px; -webkit-border-vertical-spacing: 2px; "><strike> has decided to bestow upon Oberlin a level of credibility not due to his credentials or his conclusions, but because (and I quote) "<strike>.</strike></strike></span><span style="font-size: 12px; line-height: normal; -webkit-border-horizontal-spacing: 2px; -webkit-border-vertical-spacing: 2px; "><span style="line-height: normal; -webkit-border-horizontal-spacing: 2px; -webkit-border-vertical-spacing: 2px; font-size: 12px; "><span style="font-family: 'Trebuchet MS'; ">..</span><strike>[he]</strike></span><span style="font-size: 16px; -webkit-border-horizontal-spacing: 0px; -webkit-border-vertical-spacing: 0px; "><span style="-webkit-border-horizontal-spacing: 0px; -webkit-border-vertical-spacing: 0px; font-size: 12px; "><span style="font-family: 'Trebuchet MS'; "> </span><strike>just love[s] sites that don't feel the need to use decorative pictures. His doesn't have a single image file which means that even if he didn't have superb credentials (which he </strike></span><a href="http://steveoberlin.com/cloudology/?page_id=2" style="color: #0000cd; font-weight: normal; "><span style="color: #0000cd; font-weight: normal; font-size: 12px; "><strike>does</strike></span></a><span style="-webkit-border-horizontal-spacing: 0px; -webkit-border-vertical-spacing: 0px; font-size: 12px; "><span style="font-family: 'Trebuchet MS'; ">)</span><strike> he'd get my respect by default</strike></span><span style="font-size: 12px; "><span style="-webkit-border-horizontal-spacing: 2px; -webkit-border-vertical-spacing: 2px;"><span style="font-family: 'Trebuchet MS'; ">."</span></span></span></span></span></div><div><span style="font-size: 12px; line-height: normal; -webkit-border-horizontal-spacing: 2px; -webkit-border-vertical-spacing: 2px; font-family: 'Trebuchet MS'; "><br /></span></div><div><strike>Yup, we bottom feeders who have to resort to images really are only in it for the decoration. Nice, jackass</strike><span style="font-size: 12px; line-height: normal; -webkit-border-horizontal-spacing: 2px; -webkit-border-vertical-spacing: 2px; font-family: 'Trebuchet MS'; ">.</span></div><div><span style="font-size: 12px; line-height: normal; -webkit-border-horizontal-spacing: 2px; -webkit-border-vertical-spacing: 2px;"><br /></span></div><div><span style="font-size: 12px; line-height: normal; -webkit-border-horizontal-spacing: 2px; -webkit-border-vertical-spacing: 2px;">Update: The reason for the strikethrough above -- and my public apology here -- is that William contacted me and clarified he was not referring to me and my pretty drawings (my words,) although within context it appeared like he was.  I apologize, William and instead of simply deleting it, I am admitting my error, apologizing and hanging it out to dry for all to see.  William is not a jackass. As is readily apparent, I am however. ;)</span></div><div><span style="font-family: Arial; font-size: 12px; line-height: normal; -webkit-border-horizontal-spacing: 2px; -webkit-border-vertical-spacing: 2px;"><br /></span></div></div>
</content>


    <feedburner:origLink>http://rationalsecurity.typepad.com/blog/2009/02/dear-mr-oberlin-heres-your-sign.html</feedburner:origLink><feedburner:origLink>http://feedproxy.google.com/~r/typepad/nOnJ/~3/dJ6miGYxITs/dear-mr-oberlin-heres-your-sign.html</feedburner:origLink></entry>
    <entry>
        <title>Incomplete Thought: Support of IPv6 in Cloud Providers...</title>
        <link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/feedburner/rarz/~3/nuY4t2RDTGA/incomplete-thought-support-of-ipv6-in-cloud-providers.html" />
        <link rel="replies" type="text/html" href="http://rationalsecurity.typepad.com/blog/2009/02/incomplete-thought-support-of-ipv6-in-cloud-providers.html" thr:count="7" thr:updated="2009-02-16T09:49:09-05:00" />
        <id>tag:typepad.com,2003:post-62623969</id>
        <published>2009-02-09T23:47:23-05:00</published>
        <updated>2009-02-09T23:47:23-05:00</updated>
        <summary>This is the first of my "incomplete thought" entries; thoughts too small for a really meaty blog post, but too big for Twitter. OK wiseguy. I know *most* of my thoughts are incomplete, but don't quash my artistic license, mkay?...</summary>
        <author>
            <name>beaker</name>
        </author>
        <category scheme="http://www.sixapart.com/ns/types#category" term="Cloud Computing" />
        <category scheme="http://www.sixapart.com/ns/types#category" term="Cloud Security" />
        
        <category scheme="http://sixapart.com/ns/types#tag" term="Chris Hoff" />
        <category scheme="http://sixapart.com/ns/types#tag" term="Christofer Hoff" />
        <category scheme="http://sixapart.com/ns/types#tag" term="Cloud" />
        <category scheme="http://sixapart.com/ns/types#tag" term="Cloud Computing" />
        <category scheme="http://sixapart.com/ns/types#tag" term="Cloud Networking" />
        <category scheme="http://sixapart.com/ns/types#tag" term="Cloud Security" />
        <category scheme="http://sixapart.com/ns/types#tag" term="IPv6" />
        <category scheme="http://sixapart.com/ns/types#tag" term="Rational Security" />
        <category scheme="http://sixapart.com/ns/types#tag" term="Rational Survivability" />
        
<content type="xhtml" xml:lang="en-US" xml:base="http://rationalsecurity.typepad.com/blog/">
<div xmlns="http://www.w3.org/1999/xhtml"><p>This is the first of my "incomplete thought" entries; thoughts too small for a really meaty blog post, but too big for Twitter.  OK wiseguy.  I know *most* of my thoughts are incomplete, but don't quash my artistic license, mkay?</p><br /><div>Here it is:</div><br /><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><p><span style="font-weight: bold;">How many of the cloud providers (IaaS, PaaS) support IPv6 natively or support tunneling without breaking things like NAT and firewalls?  As part of all this Infrastruture 2.0 chewy goodness, from a networking (and security) perspective, it's pretty important.</span></p></blockquote><br /><div>/Hoff</div></div>
</content>


    <feedburner:origLink>http://rationalsecurity.typepad.com/blog/2009/02/incomplete-thought-support-of-ipv6-in-cloud-providers.html</feedburner:origLink><feedburner:origLink>http://feedproxy.google.com/~r/typepad/nOnJ/~3/APXqxog80cs/incomplete-thought-support-of-ipv6-in-cloud-providers.html</feedburner:origLink></entry>
    <entry>
        <title>How I Know The Cloud Ain't Real...</title>
        <link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/feedburner/rarz/~3/p03z2tQPNlI/how-i-know-the-cloud-aint-real.html" />
        <link rel="replies" type="text/html" href="http://rationalsecurity.typepad.com/blog/2009/02/how-i-know-the-cloud-aint-real.html" thr:count="1" thr:updated="2009-02-05T09:37:02-05:00" />
        <id>tag:typepad.com,2003:post-62391117</id>
        <published>2009-02-04T18:50:43-05:00</published>
        <updated>2009-02-04T18:50:43-05:00</updated>
        <summary>You want to know how I know that The Cloud is all hot air and will never catch on? ...because I can't order it on Amazon.com and get free shipping with Prime. FAIL! FAIL, I say. /Hoff</summary>
        <author>
            <name>beaker</name>
        </author>
        <category scheme="http://www.sixapart.com/ns/types#category" term="Amazon.com" />
        <category scheme="http://www.sixapart.com/ns/types#category" term="Cloud Computing" />
        <category scheme="http://www.sixapart.com/ns/types#category" term="Cloud Security" />
        <category scheme="http://www.sixapart.com/ns/types#category" term="Jackassery" />
        
        <category scheme="http://sixapart.com/ns/types#tag" term="Amazon" />
        <category scheme="http://sixapart.com/ns/types#tag" term="Amazon Web Services" />
        <category scheme="http://sixapart.com/ns/types#tag" term="Amazon.com" />
        <category scheme="http://sixapart.com/ns/types#tag" term="AWS" />
        <category scheme="http://sixapart.com/ns/types#tag" term="Chris Hoff" />
        <category scheme="http://sixapart.com/ns/types#tag" term="Christofer Hoff" />
        <category scheme="http://sixapart.com/ns/types#tag" term="Cloud" />
        <category scheme="http://sixapart.com/ns/types#tag" term="Cloud Computing" />
        <category scheme="http://sixapart.com/ns/types#tag" term="Cloud Security" />
        <category scheme="http://sixapart.com/ns/types#tag" term="FAIL" />
        <category scheme="http://sixapart.com/ns/types#tag" term="Rational Security" />
        <category scheme="http://sixapart.com/ns/types#tag" term="Rational Survivability" />
        
<content type="xhtml" xml:lang="en-US" xml:base="http://rationalsecurity.typepad.com/blog/">
<div xmlns="http://www.w3.org/1999/xhtml"><p>You want to know how I know that The Cloud is all hot air and will never catch on?</p><br /><div><a href="http://rationalsecurity.typepad.com/.a/6a00d83451be3669e20105370dae30970b-popup" onclick="window.open( this.href, '_blank', 'width=640,height=480,scrollbars=no,resizable=no,toolbar=no,directories=no,location=no,menubar=no,status=no,left=0,top=0' ); return false" style="display: inline;"><img alt="AWS-fail" class="at-xid-6a00d83451be3669e20105370dae30970b " src="http://rationalsecurity.typepad.com/.a/6a00d83451be3669e20105370dae30970b-320wi" /></a>
 <br /></div><br /><div>...because I can't order it on Amazon.com and get free shipping with Prime.</div><br /><div>FAIL!  FAIL, I say.</div><br /><div>/Hoff</div></div>
</content>


    <feedburner:origLink>http://rationalsecurity.typepad.com/blog/2009/02/how-i-know-the-cloud-aint-real.html</feedburner:origLink><feedburner:origLink>http://feedproxy.google.com/~r/typepad/nOnJ/~3/Fl-ca7Pb3uM/how-i-know-the-cloud-aint-real.html</feedburner:origLink></entry>
    <entry>
        <title>You Keep Calling Cloud Computing "Confusing, Over-Hyped &amp; a Buzzword" &amp; It Will Be...</title>
        <link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/feedburner/rarz/~3/1p-4qncRZ9E/you-keep-calling-cloud-computing-confusing-overhyped-a-buzzword-it-will-be.html" />
        <link rel="replies" type="text/html" href="http://rationalsecurity.typepad.com/blog/2009/02/you-keep-calling-cloud-computing-confusing-overhyped-a-buzzword-it-will-be.html" thr:count="6" thr:updated="2009-02-11T08:22:05-05:00" />
        <id>tag:typepad.com,2003:post-62305292</id>
        <published>2009-02-03T07:23:40-05:00</published>
        <updated>2009-02-03T07:23:40-05:00</updated>
        <summary>A word of unsolicited advice to those of us trying to help "sort out" Cloud Computing -- myself included: The more times we lead off a description of Cloud Computing as "Confusing," "Over-hyped" and "a Buzzword" then people are going...</summary>
        <author>
            <name>beaker</name>
        </author>
        <category scheme="http://www.sixapart.com/ns/types#category" term="Cloud Computing" />
        <category scheme="http://www.sixapart.com/ns/types#category" term="Cloud Security" />
        
        <category scheme="http://sixapart.com/ns/types#tag" term="Chris Hoff" />
        <category scheme="http://sixapart.com/ns/types#tag" term="Christofer Hoff" />
        <category scheme="http://sixapart.com/ns/types#tag" term="Christopher Hoff" />
        <category scheme="http://sixapart.com/ns/types#tag" term="Cloud" />
        <category scheme="http://sixapart.com/ns/types#tag" term="Cloud Computing" />
        <category scheme="http://sixapart.com/ns/types#tag" term="Cloud Security" />
        <category scheme="http://sixapart.com/ns/types#tag" term="Rational Security" />
        <category scheme="http://sixapart.com/ns/types#tag" term="Rational Survivability" />
        
<content type="xhtml" xml:lang="en-US" xml:base="http://rationalsecurity.typepad.com/blog/">
<div xmlns="http://www.w3.org/1999/xhtml"><p><a href="http://rationalsecurity.typepad.com/.a/6a00d83451be3669e201116842dbb0970c-popup" onclick="window.open( this.href, '_blank', 'width=640,height=480,scrollbars=no,resizable=no,toolbar=no,directories=no,location=no,menubar=no,status=no,left=0,top=0' ); return false" style="float: right;"><img alt="Apathy" class="at-xid-6a00d83451be3669e201116842dbb0970c " src="http://rationalsecurity.typepad.com/.a/6a00d83451be3669e201116842dbb0970c-150wi" style="margin: 0px 0px 5px 5px; width: 150px;" /></a>
 A word of unsolicited advice to those of us trying to help "sort out" Cloud Computing -- myself included:</p><div style="margin-left: 40px;"><em>The more times we lead off a description of Cloud Computing as "Confusing," "Over-hyped" and "a Buzzword" then people are going to start to believe us.  The press is going to start to believe us.  Our customers are going to start to believe us.  Pretty soon we won't be able to escape the gravity of our own message.</em><br /></div><p><br />Granted, we mean well in our cautious and guarded admonishment, but it's starting to wear as thin as those who promote Cloud Computing as the second coming (when we all know full well that is Fiber Channel over Token Ring.)</p><p>We don't all have to chant the same mantra and we don't have to preach rainbows and unicorns, but it's important to be accurate and balanced.</p><p>I, too, am waiting for the day Cloud Computing will wash my car, bring me a beer and make me a ham sandwich. Until that day, instead of standing around trying to look smart by telling everybody that Cloud Computing is nothing more than hot air, how about making a difference by not playing a game of bad news telephone and add something constructive.</p><p>There's value in Cloud Computing so how about we move past the "confusing, over-hyped and buzzword" stage and get to work making it straight-forward, realistic and meaningful instead.</p><p>/Hoff</p><br /></div>
</content>


    <feedburner:origLink>http://rationalsecurity.typepad.com/blog/2009/02/you-keep-calling-cloud-computing-confusing-overhyped-a-buzzword-it-will-be.html</feedburner:origLink><feedburner:origLink>http://feedproxy.google.com/~r/typepad/nOnJ/~3/-l94Vw_jICI/you-keep-calling-cloud-computing-confusing-overhyped-a-buzzword-it-will-be.html</feedburner:origLink></entry>
    <entry>
        <title>Privacy Execs: Orange Jumpsuits In Your Future?  Google's Privacy Counsel Criminally Charged</title>
        <link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/feedburner/rarz/~3/zHHNBIOsY2s/privacy-execs-orange-jumpsuits-in-your-future-googles-privacy-counsel-criminally-charged.html" />
        <link rel="replies" type="text/html" href="http://rationalsecurity.typepad.com/blog/2009/02/privacy-execs-orange-jumpsuits-in-your-future-googles-privacy-counsel-criminally-charged.html" thr:count="0" />
        <id>tag:typepad.com,2003:post-62297960</id>
        <published>2009-02-03T00:27:47-05:00</published>
        <updated>2009-02-03T00:27:47-05:00</updated>
        <summary>I find this case extremely fascinating on many levels. From eWeek: Italian officials charge Google Global Privacy Counsel Peter Fleischer* with criminal charges of defamation and failure to exercise control over personal data two years after Google posted a video...</summary>
        <author>
            <name>beaker</name>
        </author>
        <category scheme="http://www.sixapart.com/ns/types#category" term="Current Affairs" />
        <category scheme="http://www.sixapart.com/ns/types#category" term="Google" />
        <category scheme="http://www.sixapart.com/ns/types#category" term="Net Neutrality" />
        <category scheme="http://www.sixapart.com/ns/types#category" term="Privacy" />
        
        <category scheme="http://sixapart.com/ns/types#tag" term="Breaches" />
        <category scheme="http://sixapart.com/ns/types#tag" term="Chris Hoff" />
        <category scheme="http://sixapart.com/ns/types#tag" term="Christofer Hoff" />
        <category scheme="http://sixapart.com/ns/types#tag" term="Christopher Hoff" />
        <category scheme="http://sixapart.com/ns/types#tag" term="Compliance" />
        <category scheme="http://sixapart.com/ns/types#tag" term="Google" />
        <category scheme="http://sixapart.com/ns/types#tag" term="Lawsuits" />
        <category scheme="http://sixapart.com/ns/types#tag" term="Peter Fleischer" />
        <category scheme="http://sixapart.com/ns/types#tag" term="Privacy" />
        
<content type="xhtml" xml:lang="en-US" xml:base="http://rationalsecurity.typepad.com/blog/">
<div xmlns="http://www.w3.org/1999/xhtml"><p><a href="http://rationalsecurity.typepad.com/.a/6a00d83451be3669e201116842733a970c-popup" onclick="window.open( this.href, '_blank', 'width=640,height=480,scrollbars=no,resizable=no,toolbar=no,directories=no,location=no,menubar=no,status=no,left=0,top=0' ); return false" style="float: right;"><img alt="Handcuffs" class="at-xid-6a00d83451be3669e201116842733a970c " src="http://rationalsecurity.typepad.com/.a/6a00d83451be3669e201116842733a970c-120wi" style="margin: 0px 0px 5px 5px;" /></a>
 I find this case extremely fascinating on many levels.  From <a href="http://www.eweek.com/c/a/Security/Google-Privacy-Exec-Facing-Criminal-Charges/?kc=rss">eWeek</a>:<br /><span class="Article_Date"><span class="Article_Date"><span class="txt"><strong><br /></strong></span></span></span></p><div style="margin-left: 40px;"><em><span class="Article_Date"><span class="Article_Date"><span class="txt"><strong>Italian
officials charge Google Global Privacy Counsel Peter Fleischer* with
criminal charges of defamation and failure to exercise control over
personal data two years after Google posted a video depicting fellow
students harassing a student with Down syndrome. <br /><br />Unlike Italian
Internet service providers, who are not responsible for posted content,
content providers like Google can be held liable for delivered
materials. <br /><br />According to the International Association of Privacy
Professionals, the charges are thought to be the first criminal
sanction ever pursued against a privacy professional for his company's
actions.</strong></span></span></span></em><br /></div> <p><br />You can see the original story from the International Association of Privacy Professionals (IAPP) <a href="https://www.privacyassociation.org/index.php?option=com_content&amp;task=view&amp;id=1745&amp;Itemid=228">here</a>.</p><p>The implications of this are quite profound as you can imagine.  CEO's and CFO's can be held accountable for crimes committed under their watch, so it's not too far of a stretch to see how privacy officers like Fleischer will have their feet held to the fire when subject to international law that takes a different perspective on the responsibilities associated with privacy than we might.  </p><p>How many indictments have we had in the U.S. for the release of information in corporate breaches?  The U.K.?</p><p>I'm not making a judgment call on this particular case because I certainly don't have all of the details, but it sets a very interseting precedent. </p><p>Imagine if you were a Chief Privacy Officer or perhaps a Chief Information Officer subject to this sort of scrutiny outside of the due care and stewardship requirements of the job in general.  If something bad happens, generally the worst thing that might occur is you lose your job.</p><p>Imagine if you were personally liable for the posting of content from millions of users globally and could be sentenced to share a shower and a cell with an angry Italian man who can't get a decent cappuccino.  I can't imagine what that would be like.</p><p>This may be the first time a privacy professional has been charged on behalf of the company he/she is employed by, but I will bet this won't be the last time it happens, either.</p><p>Besides the impact this can have on employees of providers of service, Google suggests it calls into focus larger issues of Net Neutrality:</p><div style="margin-left: 40px;"><em><span class="Article_Date"><span class="Article_Date"><span class="txt">Google issued a statement
late Feb. 2 stressing the company's sympathy for the victim and his family, but
insisted, "We feel that bringing this case to court is totally
wrong. It's akin to prosecuting mail service employees for hate speech letters
sent in the post.  <br /><br />What's more, seeking to hold neutral platforms liable
for content posted on them is a direct attack on a free, open Internet. We
will continue to vigorously defend our employees in this prosecution."</span></span></span></em><br /><span class="Article_Date"><span class="Article_Date"><span class="txt" /></span></span></div><p><span class="Article_Date"><span class="Article_Date"><span class="txt" /></span></span><br />An interesting argument for sure and one I can see being debated vigorously.  It's clear Google operates globally, so they must understand this sort of thing could happen.  What about Facebook (sorry, Chris) or MySpace?  What happens when Amazon is used to host data that is mishandled by someone.  What then?</p><p>Imagine what fun it's going to be when we're all cloudified and the mash-up frenzy makes the cross-pollenization of information today look orderly; who's responsible then?</p><p>What do you think?  Should privacy officers be liable for events like this?  Should CSO's/CISO's and Compliance Managers be liable when a breach occurs exposing protected information?  Think about that answer very carefully.</p><p>/Hoff</p><p>*You can find Peter Fleischer's blog <a href="http://www.peterfleischer.blogspot.com/">here</a>. </p></div>
</content>


    <feedburner:origLink>http://rationalsecurity.typepad.com/blog/2009/02/privacy-execs-orange-jumpsuits-in-your-future-googles-privacy-counsel-criminally-charged.html</feedburner:origLink><feedburner:origLink>http://feedproxy.google.com/~r/typepad/nOnJ/~3/NOIPGjzbfcQ/privacy-execs-orange-jumpsuits-in-your-future-googles-privacy-counsel-criminally-charged.html</feedburner:origLink></entry>
    <entry>
        <title>Don't Hassle the Hoff: Recent Press &amp; Podcast Coverage &amp; Upcoming Speaking Engagements</title>
        <link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/feedburner/rarz/~3/uSl_TUQA7gY/dont-hassle-the-hoff-recent-press-podcast-coverage-upcoming-speaking-engagements.html" />
        <link rel="replies" type="text/html" href="http://rationalsecurity.typepad.com/blog/2009/02/dont-hassle-the-hoff-recent-press-podcast-coverage-upcoming-speaking-engagements.html" thr:count="0" />
        <id>tag:typepad.com,2003:post-62266082</id>
        <published>2009-02-02T12:32:18-05:00</published>
        <updated>2009-02-02T12:32:18-05:00</updated>
        <summary>Here is some of the recent coverage from the last couple of months on topics relevant to content on my blog, presentations and speaking engagements. No particular order or priority. Press/Technology &amp; Security eZines: Byte &amp; Switch: Securing data wherever...</summary>
        <author>
            <name>beaker</name>
        </author>
        <category scheme="http://www.sixapart.com/ns/types#category" term="Podcasts" />
        <category scheme="http://www.sixapart.com/ns/types#category" term="Presentations" />
        <category scheme="http://www.sixapart.com/ns/types#category" term="Press" />
        <category scheme="http://www.sixapart.com/ns/types#category" term="Security Conferences" />
        <category scheme="http://www.sixapart.com/ns/types#category" term="Speaking Engagements" />
        
        <category scheme="http://sixapart.com/ns/types#tag" term="Chris Hoff" />
        <category scheme="http://sixapart.com/ns/types#tag" term="Christofer Hoff" />
        <category scheme="http://sixapart.com/ns/types#tag" term="Christopher Hoff" />
        <category scheme="http://sixapart.com/ns/types#tag" term="Rational Security" />
        <category scheme="http://sixapart.com/ns/types#tag" term="Rational Survivability" />
        
<content type="xhtml" xml:lang="en-US" xml:base="http://rationalsecurity.typepad.com/blog/">
<div xmlns="http://www.w3.org/1999/xhtml"><p><a href="http://rationalsecurity.typepad.com/.shared/image.html?/photos/uncategorized/2008/06/05/microphone.jpg" onclick="window.open(this.href, '_blank', 'width=313,height=313,scrollbars=no,resizable=no,toolbar=no,directories=no,location=no,menubar=no,status=no,left=0,top=0'); return false" style="text-decoration: underline; color: #406fc1; "><img alt="Microphone" border="0" class="selected " height="200" src="http://rationalsecurity.typepad.com/blog/images/2008/06/05/microphone.jpg" style="margin-top: 0px; margin-right: 0px; margin-bottom: 5px; margin-left: 5px; float: right; border-top-width: 0px; border-right-width: 0px; border-bottom-width: 0px; border-left-width: 0px; border-style: initial; border-color: initial; " title="Microphone" width="200" /></a></p><p><span style="color: #333333; font-family: 'trebuchet ms'; line-height: normal; " /></p><p style="margin-top: 10px; margin-bottom: 10px; ">Here is some of the recent coverage from the last couple of months on topics relevant to content on my blog, presentations and speaking engagements.  No particular order or priority.</p><p style="margin-top: 10px; margin-bottom: 10px; "><span style="font-weight: bold;">Press/Technology &amp; Security eZines:</span></p><p style="margin-top: 10px; margin-bottom: 10px; " /><ul>
<li><a href="http://www.byteandswitch.com/document.asp?doc_id=171311&amp;WT.svl=news1_1">Byte &amp; Switch</a>: Securing data wherever it travels</li>
<li><a href="http://feeds.csoonline.com/click.phdo?i=d47ca691d22559e4901e29c82aa6893b">CSO Online</a>: Hoff - Commode Computing</li>
<li><a href="http://www.computerworld.com/action/article.do?command=viewArticleBasic&amp;articleId=9123730&amp;source=rss_topic17">Computerworld</a> &amp; <a href="http://www.csoonline.com/article/471115/Four_Questions_On_Google_App_Security">CSO Online</a>:  Four questions on Google App Security </li>
<li><a href="http://www.darkreading.com/blog/archives/2008/12/crossing_the_st.html">Dark Reading</a>: Crossing the streams virtually </li>
<li><a href="http://PCI needs to address virtualization, experts say">SearchSecurity</a>: PCI needs to address virtualization, experts say</li>
<li><a href="http://www.csoonline.com/article/466819/The_Myth_of_Cloud_Computing">CSO Online</a>: The myth of Cloud Computing </li>
<li><a href="http://www.csoonline.com/article/461881">CSO Online</a>: Chris Hoff - On Virtualization and Cloud Computing </li>
<li><a href="http://feeds.computerworld.com/click.phdo?i=7ee5da2d64c308fc3aec104b03b7e51f">Computerworld</a>: How can you secure a buzzword? </li>
<li><a href="http://www.csoonline.com/article/461364/Security_Predictions_What_Happens_Next_">CSO</a>: Security Predictions - What happens next? </li>
<li><a href="http://www.itworldcanada.com/a/News/c3d9d977-4490-4b67-be95-ddf03e6a7dcd.html">ITWorld Canada</a>: Security admins offer their risk management pitch</li>
</ul>
<p /><p style="margin-top: 10px; margin-bottom: 10px; "><span style="font-weight: bold;">Website/Blog Coverage/Meaningful Links:</span></p><p style="margin-top: 10px; margin-bottom: 10px; " /><ul>
<li><a href="http://server.dzone.com/articles/cloud-ontology-boldly-go-where">Server Zone</a>: Cloud Ontology - to boldly go where ITIL, Grid and SOA have gone before</li>
<li><a href="http://www.virtualization.info/2008/12/top-virtualization-blogs-of-2008.html">Virtualization.info</a>: Top virtualization blogs of 2008 </li>
<li><a href="http://vmware-land.com/Top_10_Lists.html#top10_blogs" style="color: blue; text-decoration: underline; cursor: pointer; ">VMware-land</a>: Top 10 Virtualization blogs </li>
<li><span><a href="http://www.ebizq.net/blogs/connectedweb/2009/01/naming_the_parts_of_the_cloud.php">ebizQ</a>: Naming the part of the cloud</span></li>
<li><span><a href="http://www.johnmwillis.com/other/and-the-2009-cloudie-award-goes-to/">IT Management &amp; Cloud Blog</a>: And the 2009 Cloudie Award goes to... </span> </li>
<li><a href="http://news.cnet.com/8301-19413_3-10152106-240.html">C|Net Wisdom Of the Clouds: </a>Two ontologies shed light on Cloud Computing </li>
<li><a href="http://seekingalpha.com/article/116903-peak-it-the-network-industry-s-core-challenge">SeekingAlph</a>a: Peak IT - The network industry's core challenge</li>
<li><a href="http://blog.securitymonks.com/2009/01/25/recent-cloud-postings/">System Advancements at the Monaster</a>y: Recent Cloud Postings</li>
<li><a href="http://meedabyte.wordpress.com/2009/01/26/be-open-to-winds-of-change/">Meedabyte</a>: Be open to winds of change </li>
<li><a href="http://blogs.zdnet.com/security/?p=2423">ZDNet</a>: Will EDoS be the next DDoS?</li>
<li><a href="http://www.datacenterknowledge.com/archives/2009/01/26/cloudy-day-cloudswitch-aws-torrents-edos/">Data Center Knowledge:</a> Cloudy Day: CloudSwitch, AWS Torrents, eDoS</li>
<li><a href="http://www.softsecurity.com/news/highlights/will-edos-be-the-next-ddos.html">SoftSecurity.com:</a> Will EDoS be the next DDoS?</li>
<li><a href="http://smetube.com/TheGridPlace/story.php?title=In-Cloud-Computing-Good-Network-Gives-You-Control-1">The GridPlace.com</a>: In Cloud Computing, a good network gives you control</li>
<li><a href="http://Penetration Testing Not Dead, Probably Just Pining for the Fjord">RiskAnalys.is:</a> Penetration testing not dead, probably just pining for the fjord</li>
<li><a href="http://cloudcomputing.sys-con.com/node/805811">SYS-CON</a>: How difficult is securing Cloud platforms? Services in a Cloud Computing Environment </li>
<li><a href="http://blogs.cisco.com/datacenter/comments/services_in_a_cloud_computing_environment/#When:07:20:10Z">Data Center Networks (Cisco</a>): Services in a Cloud Computing Environment</li>
<li><a href="http://datacenterlinks.blogspot.com/2009/01/january-cloud-report.html">Data Center Links</a>: January Cloud Report</li>
<li><a href="https://forums.symantec.com/t5/blogs/blogprintpage/blog-id/emerging/article-id/116;jsessionid=FDB892CC8AF3B84EF121724382812738">Symantec Forums</a>: How we win at securing customers in a virtual world</li>
<li><a href="http://vmblog.com/archive/2008/12/16/catbird-the-future-of-virtualization.aspx">VMBlog</a>: The Future of virtualization</li>
<li><a href="http://www.prismmicrosys.com/Logtalk/?p=34">Prism</a>: Security - A casualty in the Sovereighnity vs Efficiency tradeoff</li>
<li><a href="http://How The Cloud Destroys Everything I Love (About Web App Security)">Securosis</a>: How the Cloud destroys everythng I love (about Web App Security)</li>
<li><a href="http://Cloud Computing Risks - EDOS">CloudAve</a>: Cloud Computing Risks - EDoS</li>
<li><a href="http://www.elasticvapor.com/2009/01/cloud-attack-economic-denial-of.html">Elastic Vapor</a>: Cloud attack: Economic denial of sustainability (EDoS)</li>
<li><a href="http://www.tripwire.com/blog/?p=216">Tripwire</a>: Regulations need to get unreal</li>
<li><a href="http://blogoftrust.com/be-an-if-map-innovator/233">Blog Of Trus</a>t: Be an IF-MAP Innovator</li>
<li><a href="http://devcentral.f5.com/weblogs/macvittie/archive/2008/12/02/the-context-aware-cloud.aspx">DevCentral</a>: The Context-Aware Cloud </li>
<li><a href="http://www.law.com/jsp/legaltechnology/pubArticleLT.jsp?id=1202426018763&amp;pos=ataglance">Law.com: </a>Old habits persist in virtual security </li>
<li><a href="http://www.brianmadden.com/blogs/brianmadden/archive/2008/11/17/What-does-Microsoft-Azure-have-to-do-with-us_3F00_-Hint_3A00_-not-much-today_2E00_.aspx">Brian Madden</a>: What does Microsoft Azure have to do with us?</li>
<li><a href="http://securosis.com/2008/11/14/everything-old-is-new-again-in-the-fog-of-the-cloud/">Securosis</a>: Everything old is new again in the fog of the cloud</li>
<li><a href="http://securosis.com/2008/11/12/cloud-security-macro-layers/">Securosis</a>: Cloud Security macro layers</li>
<li><a href="http://telematique.typepad.com/twf/2008/11/clouds-the-crim.html">Telematique</a>: Clouds, the criminal element &amp; V12N to the rescue</li>
<li><a href="http://www.mckeay.net/2008/11/02/pci-compliance-in-the-cloud-get-it-in-writing/">Network Security Blog</a>: PCI Compliance - get it in writing!</li>
<li><a href="http://feeds.citrix.com/~r/officialcitrixblog/group/server-virtualization/~3/436682606/Hoff+is+Still+Confused">Citrix Community Blog</a>: Hoff is still confused </li>
<li><a href="http://blogs.zdnet.com/security/?p=2040">ZDNet</a>: Security will suffer in the financial crisis</li>
</ul>
<p /><p style="margin-top: 10px; margin-bottom: 10px; "><span style="font-style: italic;">I should note that many of my cloud computing writing is being republished over at the SYSCON Cloud Computing Journal with a self-branded mini-site: </span><a href="http://christoferhoff.sys-con.com/" style="color: blue; text-decoration: underline; cursor: pointer; "><span style="font-style: italic;">ChristoferHoff.Sys-Con.com</span></a></p><p style="margin-top: 10px; margin-bottom: 10px; " /><p style="margin-top: 10px; margin-bottom: 10px; "><span style="font-weight: bold;">Podcasts/Webcasts/Video:</span></p><p style="margin-top: 10px; margin-bottom: 10px; " /><ul>
<li><a href="http://Network Security Podcast, Episode 131">Network Security Podcast Episode 131</a>: Co-hosted with Rich Mogull</li>
<li><a href="http://briefingsdirect.blogspot.com/2008/09/virtualization-use-requires-improved.html">Briefings Direct</a>: Improved insights and analysis from systems logs reduce complexity risks from virtualization<span style="color: #cc6600; font-family: Georgia; font-size: 18px; line-height: 25px; " /></li>
<li><a href="http://virtualization.com/video-audio-vodcast-vlog/2008/11/11/video-interview-simon-crosby-cto-of-xensource-citrix-vmworld-2008-part1/">Virtualization.com</a>: Video interview with Simon Crosby, Citrix CTO (not in it, mentioned) </li>
<li><a href="http://blogs.cisco.com/datacenter/comments/data_center_3.0_anniversary_note_and_new_products_video/">Cisco Data Center Blog</a>: Data Center 3.0 anniversary note &amp; new products video</li>
</ul>
<p /><p /><p style="margin-top: 10px; margin-bottom: 10px; "><span style="font-weight: bold;">I am confirmed to  speak at the following upcoming events:</span></p><ul style="margin-top: 10px; margin-bottom: 10px; "><li>Source Boston<span> </span> - Boston, MA - March 11-13</li>
<li>TechTarget Threat Management Decisions Summit - New York, NY - March 26</li>
<li>Americas Growth Capital InfoSec Conference (keynote) - San Francisco, CA, April 20</li>
<li>RSA 2009 (multiple sessions) - San Francisco, CA, April 21-24</li>
<li>Virtualization Congress - Las Vegas, NV, May 4-7</li>
<li>(<span style="font-style: italic;">there are others being sorted at the moment</span>) </li>
</ul>
<p style="margin-top: 10px; margin-bottom: 10px; ">I should/will be attending the following events:</p><p style="margin-top: 10px; margin-bottom: 10px; " /><ul>
<li>Shmoocon</li>
<li>Cloud Computing Expo<span> </span>  </li>
</ul>
<p /><p style="margin-top: 10px; margin-bottom: 10px; " /><p style="margin-top: 10px; margin-bottom: 10px; " /><p style="margin-top: 10px; margin-bottom: 10px; ">/Hoff</p><p /></div>
</content>


    <feedburner:origLink>http://rationalsecurity.typepad.com/blog/2009/02/dont-hassle-the-hoff-recent-press-podcast-coverage-upcoming-speaking-engagements.html</feedburner:origLink><feedburner:origLink>http://feedproxy.google.com/~r/typepad/nOnJ/~3/XmEI44OfDkQ/dont-hassle-the-hoff-recent-press-podcast-coverage-upcoming-speaking-engagements.html</feedburner:origLink></entry>
    <entry>
        <title>Rational Security: This Site May Harm Your Computer (Damned Right It Will!)</title>
        <link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/feedburner/rarz/~3/wHEzdjC0BdE/rational-security-this-site-may-harm-your-computer-damned-right-it-will.html" />
        <link rel="replies" type="text/html" href="http://rationalsecurity.typepad.com/blog/2009/01/rational-security-this-site-may-harm-your-computer-damned-right-it-will.html" thr:count="5" thr:updated="2009-02-02T06:38:23-05:00" />
        <id>tag:typepad.com,2003:post-62190520</id>
        <published>2009-01-31T10:14:39-05:00</published>
        <updated>2009-01-31T10:14:39-05:00</updated>
        <summary>HA! Finally someone (Google) has recognized that my blog is harmful and not fit for either human or computational consumption: Sweet! /Hoff</summary>
        <author>
            <name>beaker</name>
        </author>
        <category scheme="http://www.sixapart.com/ns/types#category" term="Jackassery" />
        
        <category scheme="http://sixapart.com/ns/types#tag" term="Chris Hoff" />
        <category scheme="http://sixapart.com/ns/types#tag" term="Christofer Hoff" />
        <category scheme="http://sixapart.com/ns/types#tag" term="Google" />
        <category scheme="http://sixapart.com/ns/types#tag" term="Harmful Site" />
        <category scheme="http://sixapart.com/ns/types#tag" term="Rational Security" />
        <category scheme="http://sixapart.com/ns/types#tag" term="Rational Survivability" />
        
<content type="xhtml" xml:lang="en-US" xml:base="http://rationalsecurity.typepad.com/blog/">
<div xmlns="http://www.w3.org/1999/xhtml"><div>HA!  Finally someone (Google) has recognized that my blog is harmful and not fit for either human or computational consumption:</div><p><a href="http://rationalsecurity.typepad.com/.a/6a00d83451be3669e2011168374bb6970c-popup" onclick="window.open( this.href, '_blank', 'width=640,height=480,scrollbars=no,resizable=no,toolbar=no,directories=no,location=no,menubar=no,status=no,left=0,top=0' ); return false" style="display: inline;"><img alt="RatSec-GoogleHarm" border="0" class="at-xid-6a00d83451be3669e2011168374bb6970c " src="http://rationalsecurity.typepad.com/.a/6a00d83451be3669e2011168374bb6970c-800wi" title="RatSec-GoogleHarm" /></a> </p><div>Sweet!</div><br /><div>/Hoff</div></div>
</content>


    <feedburner:origLink>http://rationalsecurity.typepad.com/blog/2009/01/rational-security-this-site-may-harm-your-computer-damned-right-it-will.html</feedburner:origLink><feedburner:origLink>http://feedproxy.google.com/~r/typepad/nOnJ/~3/1rrhK_VdBx4/rational-security-this-site-may-harm-your-computer-damned-right-it-will.html</feedburner:origLink></entry>
    <entry>
        <title>Private Clouds: Your Definition Sucks</title>
        <link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/feedburner/rarz/~3/4W3ez96dXOQ/private-clouds-your-definition-sucks.html" />
        <link rel="replies" type="text/html" href="http://rationalsecurity.typepad.com/blog/2009/01/private-clouds-your-definition-sucks.html" thr:count="24" thr:updated="2009-02-11T09:38:38-05:00" />
        <id>tag:typepad.com,2003:post-62179644</id>
        <published>2009-01-30T23:00:09-05:00</published>
        <updated>2009-01-31T10:36:23-05:00</updated>
        <summary>I think we have a failure to communicate...or at least I do. Tonight I was listening to David Linthicum's podcast titled "The Harsh Realities Of Private Clouds" in which he referenced and lauded Dimitry Sotnikov's blog of the same titled...</summary>
        <author>
            <name>beaker</name>
        </author>
        <category scheme="http://www.sixapart.com/ns/types#category" term="Cloud Computing" />
        <category scheme="http://www.sixapart.com/ns/types#category" term="Cloud Security" />
        
        <category scheme="http://sixapart.com/ns/types#tag" term="Chris Hoff" />
        <category scheme="http://sixapart.com/ns/types#tag" term="Christofer Hoff" />
        <category scheme="http://sixapart.com/ns/types#tag" term="Christopher Hoff" />
        <category scheme="http://sixapart.com/ns/types#tag" term="Cloud Computing" />
        <category scheme="http://sixapart.com/ns/types#tag" term="Cloud Security" />
        <category scheme="http://sixapart.com/ns/types#tag" term="CloudCenter" />
        <category scheme="http://sixapart.com/ns/types#tag" term="David Linthicum" />
        <category scheme="http://sixapart.com/ns/types#tag" term="Dimitry Sotnikov" />
        <category scheme="http://sixapart.com/ns/types#tag" term="GoGrid" />
        <category scheme="http://sixapart.com/ns/types#tag" term="Internal Clouds" />
        <category scheme="http://sixapart.com/ns/types#tag" term="James Urquhart" />
        <category scheme="http://sixapart.com/ns/types#tag" term="Private Clouds" />
        <category scheme="http://sixapart.com/ns/types#tag" term="Rational Security" />
        <category scheme="http://sixapart.com/ns/types#tag" term="Rational Survivability" />
        <category scheme="http://sixapart.com/ns/types#tag" term="Virtualization" />
        
<content type="xhtml" xml:lang="en-US" xml:base="http://rationalsecurity.typepad.com/blog/">
<div xmlns="http://www.w3.org/1999/xhtml"><p><a href="http://rationalsecurity.typepad.com/.a/6a00d83451be3669e201116836a49f970c-popup" onclick="window.open( this.href, '_blank', 'width=640,height=480,scrollbars=no,resizable=no,toolbar=no,directories=no,location=no,menubar=no,status=no,left=0,top=0' ); return false" style="float: right;"><img alt="Archie_bunker" class="at-xid-6a00d83451be3669e201116836a49f970c " src="http://rationalsecurity.typepad.com/.a/6a00d83451be3669e201116836a49f970c-150wi" style="width: 150px; margin: 0px 0px 5px 5px;" /></a>
 I think we have a failure to communicate...or at least I do.</p><div><div>Tonight I was listening to David Linthicum's podcast titled "<a href="http://cdn2.libsyn.com/cloudcomputingpodcast/2009-01-30-21-22-25.mp3?nvb=20090131023112&amp;nva=20090201024112&amp;t=054d6985d9660aa86c782">The Harsh Realities Of Private Clouds"</a> in which he referenced and lauded Dimitry Sotnikov's blog of the same titled "<a href="http://cloudenterprise.info/2009/01/16/no-real-private-clouds-yet/">No Real Private Clouds Yet?</a>"</div><br /><div>I continue to scratch my head not because of David's statements that he's yet to find any "killer applications" for Private Clouds but rather the continued unappetizing use of the definition (quoting Dimitry) of a Private Cloud:</div><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><p><span style="color: #666666; font-size: 12px; line-height: 17px; "><span style="font-size: 12px; line-height: 17px; color: #8b8b8b; font-family: Verdana; ">In a nutshell, private clouds are Amazon-like cost-effective and scalable infrastructures</span><span style="font-weight: bold; color: #8b8b8b; font-family: Verdana; "> but run by companies themselves within their firewalls.</span></span></p></blockquote><div><span style="color: #666666; font-family: Verdana; font-size: 12px; line-height: 17px;"><span style="color: #000000; font-family: 'Trebuchet MS'; font-size: 13px; line-height: 15px; ">This seems to be inline with Gartner's view of Private Clouds also:</span></span></div><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><p><span style="font-size: 12px; line-height: 16px; "><span style="font-size: 12px; line-height: 16px; color: #737373; font-family: Verdana; ">The future of corporate IT is in private clouds, flexible computing networks modeled after public providers such as </span><a href="http://www.networkworld.com/subnets/google/" style="color: #fe4e00; text-decoration: none; cursor: pointer; "><span style="text-decoration: none; cursor: pointer; color: #737373; font-family: Verdana; ">Google</span></a><span style="font-size: 12px; line-height: 16px; color: #737373; font-family: Verdana; "> and </span><a href="http://www.networkworld.com/news/2008/091808-amazon-testing-content-delivery-web.html" style="color: #fe4e00; text-decoration: none; cursor: pointer; "><span style="text-decoration: none; cursor: pointer; color: #737373; font-family: Verdana; ">Amazon</span></a><span style="font-size: 12px; line-height: 16px; color: #737373; font-family: Verdana; "> <span style="font-weight: bold;">yet built and managed internally</span> for each business's users</span></span></p></blockquote><div><span style="color: #666666; font-family: Verdana; font-size: 12px; line-height: 17px;"><span style="color: #000000; font-family: 'Trebuchet MS'; font-size: 13px; line-height: 15px; ">My issue is again that of the referenced location and perimeter.  It's like we've gone back to the 80's with our screened subnet architectural Maginot lines again!  "This is inside, that is outside." </span></span></div><br /><div><span style="color: #666666; font-family: Verdana; font-size: 12px; line-height: 17px;"><span style="color: #000000; font-family: 'Trebuchet MS'; font-size: 13px; line-height: 15px; ">That makes absolutely zero sense given the ubiquity, mobility and transitivity of information and platforms today.  I understand the impetus to return back to the mainframe in the sky, but c'mon...</span></span></div><br /><div><span style="color: #666666; font-family: Verdana; font-size: 12px; line-height: 17px;"><span style="color: #000000; font-family: 'Trebuchet MS'; font-size: 13px; line-height: 15px; "><span style="font-weight: bold;">For me, I'd take a much more logical and measured approach to this definition. I think there's a step missing in the definitions above and how Private Clouds really ought to be described and transitioned to.</span></span></span></div><br /><div>I think that the definitions above are too narrow end exculpatory in definition when you consider that you are omitting solutions like <a href="http://blog.gogrid.com/2009/01/14/building-a-house-in-the-cloud-cloudcenters-vs-infrastructure-web-services/">GoGrid's CloudCenter </a>concepts -- extending your datacenter via VPN onto a cloud IaaS provider whose infrastructure is not yours, but offers you the parity in platform and support to your native datacenter.</div><br /><div><span style="color: #666666; font-family: Verdana; font-size: 12px; line-height: 17px;"><span style="color: #000000; font-family: 'Trebuchet MS'; font-size: 13px; line-height: 15px; ">In this scenario, the differentiator between the "public" and "private" is then simply a descriptor defining from whom and where the information and applications running on that cloud may be accessed:</span><br /></span></div><div><span style="font-weight: bold;"><br /></span></div><div><span style="font-weight: bold;">From the "Internet" = Public Cloud.  From the "Intranet" (via a VPN connection between the internal datacenter and the "outsourced" infrastructure) = Private Cloud</span>. </div><br /><div>Check out James Urquhart's thoughts along these lines in his post titled "<a href="http://news.cnet.com/8301-19413_3-10145450-240.html">The Argument For Private Clouds."</a></div><br /><div>As I wrote in my post titled "<a href="http://rationalsecurity.typepad.com/blog/2009/01/mixing-metaphors-private-clouds-arent-limited-to-internal-location.html">Mixing Metaphors: Private Clouds Aren't Defined By Their Location</a>":</div><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><p><span style="color: #333333; font-family: 'trebuchet ms'; line-height: normal; ">Private clouds are about extending the enterprise to leverage infrastructure that makes use of cloud computing capabilities and is not (only) about internally locating the resources used to provide service.  It's also not an all-or-nothing proposition.</span></p></blockquote><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><p><span style="color: #333333; line-height: normal;"><span style="font-family: 'trebuchet ms'; ">It occurs to me that private clouds make a ton of sense as an enabler to enterprises who want to take advantage of cloud computing for any of the oft-cited reasons, but are loathe to (or unable to) surrender their infrastructure and applications without sufficient control.</span></span></p></blockquote><blockquote class="webkit-indent-blockquote" style="margin: 0 0 0 40px; border: none; padding: 0px;"><p><span style="color: #333333; line-height: normal;"><span style="font-family: 'trebuchet ms'; "><div><span>Private clouds mean that an enterprise can decide how and how much of the infrastructure can/should be maintained as a non-cloud operational concern versus how much can benefit from the cloud</span>.</div><br /><div><span>Private clouds make a ton of sense; they provide the economic benefits of outsourced scaleable infrastructure that does not require capital outlay, the needed control over that infrastructure combined with the ability to replicate existing topologies and platforms and ultimately the portability of applications and workflow.</span></div><br /><div>These capabilities may eliminate the re-write and/or re-engineering of applications like is often required when moving to typical IaaS (infrastructure as a Service) player such as Amazon.</div><br /><div><span>From a security perspective -- which is very much my focus -- private clouds provide me with a way of articulating and expressing the value of cloud computing while still enabling me to manage risk to an acceptable level as chartered by my mandate.</span></div></span></span></p></blockquote><div><span style="font-family: arial; font-size: 16px; line-height: normal; " /></div><br /><div>So why wouldn't a solution like <a href="http://www.gogrid.com/">GoGrid's CloudCenter</a> offering paired with <a href="http://www.cohesiveft.com/vpncubed/">CohesiveFT's VPN Cubed</a> and no direct "public" Internet originated access to my resources count as Private Cloud Computing?  </div><br /><div>I get all the benefits of elasticity, utility billing, storage, etc., don't have to purchase the hardware, and I decide based upon risk what I am willing to yield to that infrastructure.</div><br /><div><a href="http://rationalsecurity.typepad.com/.a/6a00d83451be3669e2010536fc4d8f970b-popup" onclick="window.open( this.href, '_blank', 'width=640,height=480,scrollbars=no,resizable=no,toolbar=no,directories=no,location=no,menubar=no,status=no,left=0,top=0' ); return false" style="float: left;"><img alt="CohesiveFT-ClustersExtended" class="at-xid-6a00d83451be3669e2010536fc4d8f970b " src="http://rationalsecurity.typepad.com/.a/6a00d83451be3669e2010536fc4d8f970b-150wi" style="width: 150px; margin: 0px 5px 5px 0px;" /></a></div><div>David brought up the notion of proprietary vendor lock-in, but yet we see GoGrid has also open sourced their CloudCenter API OpenSpec...</div><br /><div>Clearly I'm mad because I simply don't see why folks are painting Private Clouds into a corner only to say that we're years away from recognizing their utility when in fact we have the technology, business need and capability to deliver them today.</div><br /><div>/Hoff</div></div></div>
</content>


    <feedburner:origLink>http://rationalsecurity.typepad.com/blog/2009/01/private-clouds-your-definition-sucks.html</feedburner:origLink><feedburner:origLink>http://feedproxy.google.com/~r/typepad/nOnJ/~3/4MTnGRdV-yQ/private-clouds-your-definition-sucks.html</feedburner:origLink></entry>
    <entry>
        <title>Cloud Computing Taxonomy &amp; Ontology :: Please Review</title>
        <link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/feedburner/rarz/~3/qIBF79HGtSM/cloud-computing-taxonomy-ontology-please-review.html" />
        <link rel="replies" type="text/html" href="http://rationalsecurity.typepad.com/blog/2009/01/cloud-computing-taxonomy-ontology-please-review.html" thr:count="35" thr:updated="2009-03-12T10:47:09-04:00" />
        <id>tag:typepad.com,2003:post-62048330</id>
        <published>2009-01-28T13:18:25-05:00</published>
        <updated>2009-02-10T10:20:45-05:00</updated>
        <summary>Updated: 2/10/09 10:07 EST - v1.4 There have been some excellent discussions of late regarding how to classify and explain the relationships between the many Cloud Computing models floating about. I was inspired by John Willis' blog post this morning...</summary>
        <author>
            <name>beaker</name>
        </author>
        <category scheme="http://www.sixapart.com/ns/types#category" term="Cloud Computing" />
        <category scheme="http://www.sixapart.com/ns/types#category" term="Cloud Security" />
        
        <category scheme="http://sixapart.com/ns/types#tag" term="Chris Hoff" />
        <category scheme="http://sixapart.com/ns/types#tag" term="Christofer Hoff" />
        <category scheme="http://sixapart.com/ns/types#tag" term="Cloud Computing" />
        <category scheme="http://sixapart.com/ns/types#tag" term="Cloud Ontology" />
        <category scheme="http://sixapart.com/ns/types#tag" term="Cloud Security" />
        <category scheme="http://sixapart.com/ns/types#tag" term="Cloud Taxonomy" />
        <category scheme="http://sixapart.com/ns/types#tag" term="IaaS" />
        <category scheme="http://sixapart.com/ns/types#tag" term="PaaS" />
        <category scheme="http://sixapart.com/ns/types#tag" term="SaaS" />
        
<content type="xhtml" xml:lang="en-US" xml:base="http://rationalsecurity.typepad.com/blog/">
<div xmlns="http://www.w3.org/1999/xhtml"><p><span style="font-weight: bold;">Updated: 2/10/09 10:07 EST - v1.4</span></p><p>There have been some excellent discussions of late regarding how to classify and explain the relationships between the many Cloud Computing models floating about.</p><div>I was inspired by John Willis' blog post this morning titled "<a href="http://www.johnmwillis.com/cloud-computing/unified-ontology-of-cloud-computing/">Unified Ontology of Cloud Computing</a>" in which he scraped together many ideas on the subject.</div><br /><div>I'm building a number of presentations for discussing Cloud Security and I've also been working on how to show both the the taxonomy and ontology of various Cloud components and models.  I think it's really a blind mash-up of many of the things John points to, but the others I've seen don't serve my needs completely.  My goal is to gain consensus on the model and the explore each layer and its security requirements and impacts on the model as a whole.</div><br /><div>Here's my <strike>first</strike> <strike>second</strike> <span style="font-weight: bold;">third</span> draft based on the awesome feedback I've received so far.</div><br /><div>I'm not going to explain the layers/levels or groupings because I want people's reactions and feedback to what they get from the diagram without color from me first.  There will likely be things that aren't clear enough or even inaccuracies and missing elements.</div><br /><div>If you could kindly give me your feedback on your first (unabashed) impressions, I'd really appreciate it.</div><br /><div>Thanks!</div><div><span style="font-weight: bold; color: #ff0000; font-family: 'Trebuchet MS'; "><br /></span></div><div><strike>NOTE: TypePad's comment subsystem is having problems.  I'm going to close the comments until it's resolved as the excellent (16 or so) comments are not showing up and I don't want people adding comments using the old system... Please send me comments via email (choff @ packetfilter.com or via Twitter @beaker) in the meantime.  Thanks SO much.</strike></div><br /><p><span style="font-weight: bold; color: #ff0000; font-family: 'Trebuchet MS'; ">The comments are working again.  I've had 30-40 comments via email/twitter, so if something you wanted to communicate isn't addressed, fire away below in the comments!</span></p><div><div>Version 1.4 Diagram:</div><div><a href="http://rationalsecurity.typepad.com/.a/6a00d83451be3669e201116858019e970c-popup" onclick="window.open( this.href, '_blank', 'width=640,height=480,scrollbars=no,resizable=no,toolbar=no,directories=no,location=no,menubar=no,status=no,left=0,top=0' ); return false" style="display: inline;"><img alt="CloudTaxonomyOntology_v14" class="at-xid-6a00d83451be3669e201116858019e970c selected " src="http://rationalsecurity.typepad.com/.a/6a00d83451be3669e201116858019e970c-500wi" /></a>
 <br /></div><br /><span style="font-style: italic;">In v1.4 I added the API layer above 'Applications' in the SaaS grouping. I split out "data, metadata and content" as three separate elements and added structured/unstructured to the right.  I also separated the presentation layer into "modality and platform."  Added some examples of layers to the very right.</span></div><div><span style="font-style: italic;"><br /></span></div><div><span style="font-style: italic;">To do: Break out the uber-bubbles on the left, add more examples in the middle column.</span></div><div> <div>The v1.3 diagram is <a href="http://rationalsecurity.typepad.com/.a/6a00d83451be3669e2011168580018970c-popup" onclick="window.open( this.href, '_blank', 'width=640,height=480,scrollbars=no,resizable=no,toolbar=no,directories=no,location=no,menubar=no,status=no,left=0,top=0' ); return false" style="display: inline;">here.</a></div><div>The v1.2 diagram is <a href="http://rationalsecurity.typepad.com/.a/6a00d83451be3669e2010537021cc1970c-popup" onclick="window.open( this.href, '_blank', 'width=640,height=480,scrollbars=no,resizable=no,toolbar=no,directories=no,location=no,menubar=no,status=no,left=0,top=0' ); return false" style="display: inline;">here.</a></div><div>The v1.1 diagram is <a href="http://rationalsecurity.typepad.com/.a/6a00d83451be3669e2010536f840a5970b-popup" onclick="window.open( this.href, '_blank', 'width=640,height=480,scrollbars=no,resizable=no,toolbar=no,directories=no,location=no,menubar=no,status=no,left=0,top=0' ); return false" style="display: inline;">here.</a></div><div>The original v1.0 diagram is <a href="http://rationalsecurity.typepad.com/.a/6a00d83451be3669e2010536f5dab5970b-popup" onclick="window.open( this.href, '_blank', 'width=640,height=480,scrollbars=no,resizable=no,toolbar=no,directories=no,location=no,menubar=no,status=no,left=0,top=0' ); return false" style="display: inline;">here.</a>  </div></div></div>
</content>


    <feedburner:origLink>http://rationalsecurity.typepad.com/blog/2009/01/cloud-computing-taxonomy-ontology-please-review.html</feedburner:origLink><feedburner:origLink>http://feedproxy.google.com/~r/typepad/nOnJ/~3/53fP59YDIhE/cloud-computing-taxonomy-ontology-please-review.html</feedburner:origLink></entry>
    <entry>
        <title>Cloud Security Link Love: Monk Style...</title>
        <link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/feedburner/rarz/~3/YZ1mm90Ay48/cloud-security-link-love-monk-style.html" />
        <link rel="replies" type="text/html" href="http://rationalsecurity.typepad.com/blog/2009/01/cloud-security-link-love-monk-style.html" thr:count="1" thr:updated="2009-01-28T18:02:17-05:00" />
        <id>tag:typepad.com,2003:post-61897238</id>
        <published>2009-01-25T20:05:40-05:00</published>
        <updated>2009-01-25T20:05:40-05:00</updated>
        <summary>John Gerber from the Syetem Advancements at the Monastery blog compiled an awesome round-up of Cloud related news/postings. The blog entry covers many areas of the cloud including security, which I greatly appreciate. Check it out here. Well worth the...</summary>
        <author>
            <name>beaker</name>
        </author>
        <category scheme="http://www.sixapart.com/ns/types#category" term="Cloud Computing" />
        <category scheme="http://www.sixapart.com/ns/types#category" term="Cloud Security" />
        
        <category scheme="http://sixapart.com/ns/types#tag" term="Chris Hoff" />
        <category scheme="http://sixapart.com/ns/types#tag" term="Christofer Hoff" />
        <category scheme="http://sixapart.com/ns/types#tag" term="Cloud Computing" />
        <category scheme="http://sixapart.com/ns/types#tag" term="Cloud Computing Security" />
        <category scheme="http://sixapart.com/ns/types#tag" term="Cloud Security" />
        <category scheme="http://sixapart.com/ns/types#tag" term="John Gerber" />
        <category scheme="http://sixapart.com/ns/types#tag" term="Rational Security" />
        <category scheme="http://sixapart.com/ns/types#tag" term="Rational Survivability" />
        <category scheme="http://sixapart.com/ns/types#tag" term="System Improvements at the Monastery" />
        
<content type="xhtml" xml:lang="en-US" xml:base="http://rationalsecurity.typepad.com/blog/">
<div xmlns="http://www.w3.org/1999/xhtml"><p><a href="http://rationalsecurity.typepad.com/.a/6a00d83451be3669e2010536ecc4fd970b-popup" onclick="window.open( this.href, '_blank', 'width=640,height=480,scrollbars=no,resizable=no,toolbar=no,directories=no,location=no,menubar=no,status=no,left=0,top=0' ); return false" style="float: left;"><img alt="Saint_Anthony_Abbot" class="at-xid-6a00d83451be3669e2010536ecc4fd970b " src="http://rationalsecurity.typepad.com/.a/6a00d83451be3669e2010536ecc4fd970b-120wi" style="margin: 0px 5px 5px 0px;" /></a>
 John Gerber from the <a href="http://blog.securitymonks.com/">Syetem Advancements at the Monastery</a> blog compiled an awesome round-up of Cloud related news/postings. </p><p>The blog entry covers many areas of the cloud including security, which I greatly appreciate.</p><p>Check it out <a href="http://blog.securitymonks.com/2009/01/25/recent-cloud-postings/">here</a>.  Well worth the read and the perspective.</p><p>/Hoff</p></div>
</content>


    <feedburner:origLink>http://rationalsecurity.typepad.com/blog/2009/01/cloud-security-link-love-monk-style.html</feedburner:origLink><feedburner:origLink>http://feedproxy.google.com/~r/typepad/nOnJ/~3/kDMnEBknK-I/cloud-security-link-love-monk-style.html</feedburner:origLink></entry>
    <entry>
        <title>PCI Security Standards Council to Form Virtualization SIG...</title>
        <link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/feedburner/rarz/~3/ezfBu6riFSc/pci-security-standards-council-to-form-virtualization-sig.html" />
        <link rel="replies" type="text/html" href="http://rationalsecurity.typepad.com/blog/2009/01/pci-security-standards-council-to-form-virtualization-sig.html" thr:count="1" thr:updated="2009-01-24T18:47:18-05:00" />
        <id>tag:typepad.com,2003:post-61859464</id>
        <published>2009-01-24T17:14:47-05:00</published>
        <updated>2009-01-24T17:14:47-05:00</updated>
        <summary>I'm happy to say that there appears to be some good news on the PCI DSS front with the promise of a SIG being formed this year for virtualization. This is a good thing. You'll remember my calls for better...</summary>
        <author>
            <name>beaker</name>
        </author>
        <category scheme="http://www.sixapart.com/ns/types#category" term="Compliance" />
        <category scheme="http://www.sixapart.com/ns/types#category" term="PCI" />
        <category scheme="http://www.sixapart.com/ns/types#category" term="Virtualization" />
        <category scheme="http://www.sixapart.com/ns/types#category" term="VMWare" />
        
        <category scheme="http://sixapart.com/ns/types#tag" term="Chris Hoff" />
        <category scheme="http://sixapart.com/ns/types#tag" term="Christofer Hoff" />
        <category scheme="http://sixapart.com/ns/types#tag" term="Cloud Computing" />
        <category scheme="http://sixapart.com/ns/types#tag" term="Cloud Security" />
        <category scheme="http://sixapart.com/ns/types#tag" term="Michael Hoesing" />
        <category scheme="http://sixapart.com/ns/types#tag" term="PCI" />
        <category scheme="http://sixapart.com/ns/types#tag" term="PCI Compliance" />
        <category scheme="http://sixapart.com/ns/types#tag" term="PCI DSS" />
        <category scheme="http://sixapart.com/ns/types#tag" term="PCI Security Standards Council" />
        <category scheme="http://sixapart.com/ns/types#tag" term="Rational Security" />
        <category scheme="http://sixapart.com/ns/types#tag" term="Rational Survivability" />
        <category scheme="http://sixapart.com/ns/types#tag" term="Troy Leach" />
        <category scheme="http://sixapart.com/ns/types#tag" term="VirtSec" />
        <category scheme="http://sixapart.com/ns/types#tag" term="Virtualization" />
        <category scheme="http://sixapart.com/ns/types#tag" term="Virtualization Security" />
        
<content type="xhtml" xml:lang="en-US" xml:base="http://rationalsecurity.typepad.com/blog/">
<div xmlns="http://www.w3.org/1999/xhtml"><p>I'm happy to say that there appears to be some good news on the PCI DSS front with the promise of a SIG being formed this year for virtualization.  This is a good thing.  </p><p>You'll remember my calls for better guidance for both <a href="http://rationalsecurity.typepad.com/blog/2008/11/when-the-carrot-doesnt-work-try-a-stick-vmware-joins-pci-ssc.html">virtualization</a> and ultimately <a href="http://rationalsecurity.typepad.com/blog/2008/10/please-help-me-i-need-a-qsa-to-assess-pcidss-compliance-in-the-cloud.html">cloud</a> computing from the council given the proliferation of these technologies and the impact they will have on both security and compliance.</p><p>In that light, news comes from Troy Leach, technical director of the PCI Security Standards Council via a kind note to me from Michael Hoesing:</p><div style="margin-left: 40px;"><em>A PCI SSC Special Interest Group (SIG) for virtualization is most likely coming this year but we don't have any firm dates or objectives as of yet.  We will be soliciting feedback from our Participating Organizations which is comprised of more than 500 companies (which include Vmware, Microsoft, Dell, etc) as well as industry subject matter experts such as the 1,800+ security assessors that currently perform assessments as either a Qualified Security Assessor or Approved Scanning Vendor (ASV).<br /><br />The PCI SSC Participating Organization program allows industry stakeholders an opportunity to provide feedback on all standards and supporting procedures.  Information to join as a Participating Organization can be found here on our <a href="https://www.pcisecuritystandards.org/">website</a>. <br /></em></div><p><br />This is a good first step.  if you've got input, make sure to contribute!</p><p>/Hoff</p></div>
</content>


    <feedburner:origLink>http://rationalsecurity.typepad.com/blog/2009/01/pci-security-standards-council-to-form-virtualization-sig.html</feedburner:origLink><feedburner:origLink>http://feedproxy.google.com/~r/typepad/nOnJ/~3/u2eEl5OQPHM/pci-security-standards-council-to-form-virtualization-sig.html</feedburner:origLink></entry>
 
</feed><!-- ph=1 --><!-- nhm:dynamic-ssi -->
