<?xml version="1.0" encoding="UTF-8"?><rss version="0.92">
<channel>
	<title>Rational Survivability</title>
	<link>http://www.rationalsurvivability.com/blog</link>
	<description>Hoff&#039;s Ramblings about Information Survivability, Information Centricity, Risk Management and Disruptive Innovation. Oh, I have a fondness for virtualization and cloud computing security, too...</description>
	<lastBuildDate>Thu, 02 Sep 2010 05:55:33 +0000</lastBuildDate>
	<docs>http://backend.userland.com/rss092</docs>
	<language>en</language>
	<!-- generator="WordPress/3.0.1" -->

	<item>
		<title>VMware&#8217;s (New) vShield: The (Almost) Bottom Line</title>
		<description><![CDATA[After my initial post yesterday (How To Wield the New vShield (Edge, App &#38; Endpoint) remarking on the general sessions I sat through on vShield, I thought I&#8217;d add some additional color given my hands-on experience in the labs today. I will reserve more extensive technical analysis of vShield Edge and App (I didn&#8217;t get [...]]]></description>
		<link>http://www.rationalsurvivability.com/blog/?p=2646</link>
			</item>
	<item>
		<title>How To Wield the New vShield (Edge, App &amp; Endpoint)</title>
		<description><![CDATA[Image via CrunchBase Today at VMworld I spent my day in and out of sessions focused on the security of virtualized and cloud environments. Many of these security sessions hinged on the release of VMware&#8216;s new and improved suite of vShield product offerings which can be simply summarized by a deceptively simple set of descriptions: [...]]]></description>
		<link>http://www.rationalsurvivability.com/blog/?p=2639</link>
			</item>
	<item>
		<title>Why Is NASA Re-Inventing IT vs. Putting Men On the Moon? Simple.</title>
		<description><![CDATA[Image via Wikipedia I was struck with a sense of disappointment as I read Bob Wardspan&#8217;s (Smoothspan) blog today &#8220;NASA Fiddles While Rome Is Burning.&#8221;  So as Bob was rubbed the wrong way by Alex Howard&#8217;s post (below,) so too was I by Bob&#8217;s perspective.  All&#8217;s fair in love and space, I suppose. In what [...]]]></description>
		<link>http://www.rationalsurvivability.com/blog/?p=2627</link>
			</item>
	<item>
		<title>Dear Verizon Business: I Have Some Questions About Your PCI-Compliant Cloud&#8230;</title>
		<description><![CDATA[You&#8217;ll forgive my impertinence, but the last time I saw a similar claim of a PCI compliant Cloud offering, it turned out rather anti-climatically for RackSpace/Mosso, so I just want to make sure I understand what is really being said.  I may be mixing things up in asking my questions, so hopefully someone can shed [...]]]></description>
		<link>http://www.rationalsurvivability.com/blog/?p=2619</link>
			</item>
	<item>
		<title>Hoff&#8217;s 5 Rules Of Cloud Security&#8230;</title>
		<description><![CDATA[Mike Dahn pinged me via Twitter with an interesting and challenging question: I took this as a challenge in 5 minutes or less to articulate this in succinct, bulleted form.  I timed it. 4 minutes &#38; 48 seconds. Loaded with snark and Hoffacino-fueled dogma. Here goes: Get an Amazon Web Services [or Rackspace or Terremark [...]]]></description>
		<link>http://www.rationalsurvivability.com/blog/?p=2607</link>
			</item>
	<item>
		<title>VMworld – v0dgeball Deathmatch Details: vSquirrels vs. Sakacc&#8217;s Army&#8230;</title>
		<description><![CDATA[UPDATE: Thanks to Chad&#8217;s hard work, transportation to/from the venue is provided: v0dgeball bus (players and groupies) Marriott on Mission ~5:30PM Thurs, departs at 6:00 PM sharp &#38; return ~10:00 PM. [Reposted and edited for snark from Sakacc's blog.] To celebrate the close of VMworld 2010, there will be a best 5 of 9 match [...]]]></description>
		<link>http://www.rationalsurvivability.com/blog/?p=2596</link>
			</item>
	<item>
		<title>Video Of My Cloudifornication Presentation [Microsoft BlueHat v9]</title>
		<description><![CDATA[In advance of publishing a more consolidated compilation of various recordings of my presentations, I thought I&#8217;d post this one. This is from Microsoft&#8217;s BlueHat v9 and is from my &#8220;Cloudifornication: Indiscriminate Information Intercourse Involving Internet Infrastructure&#8221; presentation. The direct link is here in case you have scripting disabled. The follow-on to this is my [...]]]></description>
		<link>http://www.rationalsurvivability.com/blog/?p=2560</link>
			</item>
	<item>
		<title>Airing Private Cloud&#8217;s Dirty Laundry&#8230;</title>
		<description><![CDATA[Image via Wikipedia It&#8217;s 10:13pm on a Friday night and as the highlight of my day begrudgingly reveals itself, I discover in preparation for the inevitable appearance of tomorrow, that I am once again out of clean underwear. There are many potential remedies for this situation. Option number one suggests I could borrow a pair [...]]]></description>
		<link>http://www.rationalsurvivability.com/blog/?p=2384</link>
			</item>
	<item>
		<title>If You Could Have One Resource For Cloud Security&#8230;</title>
		<description><![CDATA[I got an interesting tweet sent to me today that asked a great question: I thought about this and it occurred to me that while I would have liked to have answered that the Cloud Security Alliance Guidance was my first choice, I think the most appropriate answer is actually the following: &#8220;Cloud Security and [...]]]></description>
		<link>http://www.rationalsurvivability.com/blog/?p=2378</link>
			</item>
	<item>
		<title>See You At Black Hat 2010 &amp; Defcon 18?</title>
		<description><![CDATA[This year looks to be another swell get-together in Vegas.  I had to miss last year (first time in&#8230;forever) so I&#8217;m looking forward to 112 degrees, recirculated air, and stumble-drunk hax0rs jackpotting ATMs and commandeering elevators. I&#8217;ll be getting in on the 27th. I have a keynote at the Cloud Security Alliance Summit on the [...]]]></description>
		<link>http://www.rationalsurvivability.com/blog/?p=2349</link>
			</item>
	<item>
		<title>Reflections on SANS &#8217;99 New Orleans: Where It All Started</title>
		<description><![CDATA[A few weeks ago I saw some RT&#8217;s/@&#8217;s on Twitter referencing John Flowers and that name brought back some memories. Today I sent a tweet to John asking him if I remembered correctly that he was at SANS in New Orleans in 1999 when he was still at Hiverworld. He responded back confirming he was, [...]]]></description>
		<link>http://www.rationalsurvivability.com/blog/?p=2293</link>
			</item>
	<item>
		<title>On Amrit Williams&#8217; (BigFix) Beyond The Perimeter Podcast</title>
		<description><![CDATA[My good friend Amrit Williams (@amrittsering) from BigFix (congrats on the IBM acquisition!) has an awesome Podcast titled &#8220;Beyond the Perimeter.&#8221; He was nice enough to invite me to record episode 93 titled &#8220;Is Trust the Real Barrier To Cloud Computing?&#8221; (ultimately points you to an iTunes subscription.) We spoke for almost an hour on [...]]]></description>
		<link>http://www.rationalsurvivability.com/blog/?p=2262</link>
			</item>
	<item>
		<title>Incomplete Thought: Why We Need Open Source Security Solutions More Than Ever&#8230;</title>
		<description><![CDATA[Image via Wikipedia I don&#8217;t have time to write a big blog post and quite frankly, I don&#8217;t need to. Not on this topic. I do, however, feel that it&#8217;s important to bring back into consciousness how very important open source security solutions are to us &#8212; at least those of us who actually expect [...]]]></description>
		<link>http://www.rationalsurvivability.com/blog/?p=2173</link>
			</item>
	<item>
		<title>CLOUDINOMICON: Idempotent Infrastructure, Survivable Systems &amp; Bringing Sexy Back to Information Centricity</title>
		<description><![CDATA[I&#8217;m hurrying to polish up the next in my series of virtualization and cloud computing security presentations which I&#8217;m going to give at this year&#8217;s Black Hat conference in Las Vegas on July 29th.  I&#8217;m speaking from 10-11am on day two up next to folks like Jeremiah Grossman, Moxie Marlinspike, Ivan Ristic, Haroon Meer&#8230;quite the [...]]]></description>
		<link>http://www.rationalsurvivability.com/blog/?p=2121</link>
			</item>
	<item>
		<title>The Security Hamster Sine Wave Of Pain: Public Cloud &amp; The Return To Host-Based Protection&#8230;</title>
		<description><![CDATA[Image via Wikipedia This is a revisitation of a blog I wrote last year: Incomplete Thought: Cloud Security IS Host-Based…At The Moment I use my &#8216;Security Hamster Sine Wave of Pain&#8221; to illustrate the cyclical nature of security investment and deployment models over time and how disruptive innovation and technology impacts the flip-flop across the [...]]]></description>
		<link>http://www.rationalsurvivability.com/blog/?p=2064</link>
			</item>
	<item>
		<title>The Classical DMZ Design Pattern: How To Kill Security In the Cloud</title>
		<description><![CDATA[Every day I get asked to discuss how Cloud Computing impacts security architecture and what enterprise security teams should do when considering &#8220;Cloud.&#8221; These discussions generally lend themselves to a bifurcated set of perspectives depending upon whether we&#8217;re discussing Public or Private Cloud Computing. This is unfortunate. From a security perspective, focusing the discussion primarily [...]]]></description>
		<link>http://www.rationalsurvivability.com/blog/?p=2023</link>
			</item>
	<item>
		<title>Friday Cloud Poetry: &#8220;On the Bullshit That is False Cloud&#8221;</title>
		<description><![CDATA[I was inspired to write this given the latest round of marketing being tended to by Amazon Web Services in their renewed campaign to convince Enterprises CIO&#8217;s that their server-hugging IT teams are luddites and interested in nothing more than boat anchoring the success of their companies to some desperate need to buy legacy kit. The &#8220;public-all-or-nothing&#8221; [...]]]></description>
		<link>http://www.rationalsurvivability.com/blog/?p=1912</link>
			</item>
	<item>
		<title>All For One, One For All? On Standardizing Virtual Appliance Operating Systems</title>
		<description><![CDATA[Image via Wikipedia Hot on the tail of the announcement that VMware and Novell are entering into a deeper &#8220;strategic partnership&#8221; in order to deliver and support SUSE Linux Enterprise Server (SLES) for VMware vSphere environments, was an interesting blog post from Stu (@vinternals) titled &#8220;Enter the Appliance.&#8221; Now, before we get to Stu&#8217;s post, [...]]]></description>
		<link>http://www.rationalsurvivability.com/blog/?p=1904</link>
			</item>
	<item>
		<title>Incomplete Thought: The DevOps Disconnect</title>
		<description><![CDATA[DevOps &#8212; what it means and how it applies &#8212; is a fascinating topic that inspires all sorts of interesting reactions from people, polarized by their interpretation of what this term really means. At CloudCamp Denver, adjacent to Gluecon, Aaron Pederson of OpsCode gave a lightning talk titled: &#8221;Operations as Code.&#8221;  I&#8217;ve seen this presentation on-line before, [...]]]></description>
		<link>http://www.rationalsurvivability.com/blog/?p=1890</link>
			</item>
	<item>
		<title>Amazon Web Services Hires a CISO &#8211; Did You Know?</title>
		<description><![CDATA[Image via CrunchBase Just to point out a fact many/most of you may not be aware of, but Amazon Web Services hired (transferred (?) since he was an AWS insider) Stephen Schmidt as their CISO earlier this year.  He has a team that goes along with him, also. That&#8217;s a very, very good thing. I, [...]]]></description>
		<link>http://www.rationalsurvivability.com/blog/?p=1886</link>
			</item>
	<item>
		<title>Novell Marketing Genius: Interpretive Reading Of One Of My Cloud Security Blog Posts&#8230;</title>
		<description><![CDATA[Speechless. The embedded version (Flash) appears below. Direct link here. “Cloud: Security Doesn’t Matter (Or, In Cloud, Nobody Can Hear You Scream)” by Chris Hoff from Novell, Inc. on Vimeo. Hysterical. /Hoff]]></description>
		<link>http://www.rationalsurvivability.com/blog/?p=1883</link>
			</item>
	<item>
		<title>The Hypervisor Platform Shuffle: Pushing The Networking &amp; Security Envelope</title>
		<description><![CDATA[Last night we saw coverage by Carl Brooks Jo Maitland (sorry, Jo) of an announcement from RackSpace that they were transitioning their IaaS Cloud offerings based on the FOSS Xen platform and moving to the commercially-supported Citrix XenServer instead: Jaws dropped during the keynote sessions [at Citrix Synergy] when Lew Moorman, chief strategy officer and president [...]]]></description>
		<link>http://www.rationalsurvivability.com/blog/?p=1877</link>
			</item>
	<item>
		<title>Virtualization &amp; Cloud Don&#8217;t Offer An *Information* Security Renaissance&#8230;</title>
		<description><![CDATA[I was reading the @emccorp Twitter stream this morning from EMC World and noticed some interesting quotes from RSA&#8217;s Art Coviello as he spoke about Cloud Computing and security: Fundamentally, I don&#8217;t disagree that virtualization (and Cloud) can act as fantastic forcing functions that help us focus on securing the things that matter most if [...]]]></description>
		<link>http://www.rationalsurvivability.com/blog/?p=1865</link>
			</item>
	<item>
		<title>Security: In the Cloud, For the Cloud &amp; By the Cloud&#8230;</title>
		<description><![CDATA[When my I interact with folks and they bring up the notion of &#8220;Cloud Security,&#8221; I often find it quite useful to stop and ask them what they mean.  I thought perhaps it might be useful to describe why. In the same way that I differentiated &#8220;Virtualizing Security, Securing Virtualization and Security via Virtualization&#8221; in [...]]]></description>
		<link>http://www.rationalsurvivability.com/blog/?p=1860</link>
			</item>
	<item>
		<title>Dear SaaS Vendors: If Cloud Is The Way Forward &amp; Companies Shouldn&#8217;t Spend $ On Privately-Operated Infrastructure, When Are You Moving Yours To Amazon Web Services?</title>
		<description><![CDATA[We&#8217;re told repetitively by Software as a Service (SaaS)* vendors that infrastructure is irrelevant, that CapEx spending is for fools and that Cloud Computing has fundamentally changed the way we will, forever, consume computing resources. Why is it then that many of the largest SaaS providers on the planet (including firms like Salesforce.com, Twitter, Facebook, etc.) [...]]]></description>
		<link>http://www.rationalsurvivability.com/blog/?p=1845</link>
			</item>
	<item>
		<title>You Can&#8217;t Secure The Cloud&#8230;</title>
		<description><![CDATA[That&#8217;s right. You can&#8217;t secure &#8220;The Cloud&#8221; and the real shocker is that you don&#8217;t need to. You can and should, however, secure your assets and the elements within your control that are delivered by cloud services and cloud service providers, assuming of course there are interfaces to do so made available by the delivery/deployment [...]]]></description>
		<link>http://www.rationalsurvivability.com/blog/?p=1836</link>
			</item>
	<item>
		<title>Introducing The HacKid Conference &#8211;  Hacking, Networking, Security, Self-Defense, Gaming &amp; Technology for Kids &amp; Their Parents</title>
		<description><![CDATA[This is mostly a cross-post from the official HacKid.org website, but I wanted to drive as many eyeballs to it as possible. The gist of the idea for HacKid (sounds like “hacked,” get it?) came about when I took my three daughters aged 6, 9 and 14 along with me to the Source Security conference [...]]]></description>
		<link>http://www.rationalsurvivability.com/blog/?p=1838</link>
			</item>
	<item>
		<title>The Four Horsemen Of the Virtualization (and Cloud) Security Apocalypse&#8230;</title>
		<description><![CDATA[I just stumbled upon this YouTube video (link here, embedded below) interview I did right after my talk at Blackhat 2008 titled &#8220;The 4 Horsemen of the Virtualization Security Apocalypse (PDF)&#8221; [There's a better narrative to the PDF that explains the 4 Horsemen here.] I found it interesting because while it was rather &#8220;new&#8221; and interesting [...]]]></description>
		<link>http://www.rationalsurvivability.com/blog/?p=1831</link>
			</item>
	<item>
		<title>Incomplete Thought: &#8220;The Cloud in the Enterprise: Big Switch or Little Niche?&#8221;</title>
		<description><![CDATA[Joe Weinman wrote an interesting post in advance of his panel at Structure &#8217;10 titled &#8220;The Cloud in the Enterprise: Big Switch or Little Niche?&#8221; wherein he explored the future of Cloud adoption. In this blog, while framing the discussion with Nick Carr&#8216;s (in)famous &#8220;Big Switch&#8221; utility analog, he asks the question: So will enterprise [...]]]></description>
		<link>http://www.rationalsurvivability.com/blog/?p=1818</link>
			</item>
	<item>
		<title>Patching the (Hypervisor) Platform: How Do You Manage Risk?</title>
		<description><![CDATA[Hi. Me again. In 2008 I wrote a blog titled &#8220;Patching the Cloud&#8221; which I followed up with material examples in 2009 in another titled &#8220;Redux: Patching the Cloud.&#8221; These blogs focused mainly on virtualization-powered IaaS/PaaS offerings and whilst they targeted &#8220;Cloud Computing,&#8221; they applied equally to the heavily virtualized enterprise.  To this point I [...]]]></description>
		<link>http://www.rationalsurvivability.com/blog/?p=1812</link>
			</item>
	<item>
		<title>More On High Assurance (via TPM) Cloud Environments</title>
		<description><![CDATA[Image via Wikipedia Back in September 2009 after presenting at the Intel Virtualization (and Cloud) Security Summit and urging Intel to lead by example by pushing the adoption and use of TPM in virtualization and cloud environments, I blogged a simple question (here) as to the following: Does anyone know of any Public Cloud Provider [...]]]></description>
		<link>http://www.rationalsurvivability.com/blog/?p=1809</link>
			</item>
	<item>
		<title>Good Interview/Resource Regarding CloudAudit from SearchCloudComputing&#8230;</title>
		<description><![CDATA[The guys from SearchCloudComputing gave me a ring and we chatted about CloudAudit. The interview that follows is a distillation of that discussion and goes a long way toward answering many of the common questions surrounding CloudAudit/A6.  You can find the original here. What are the biggest challenges when auditing cloud-based services, particularly for the [...]]]></description>
		<link>http://www.rationalsurvivability.com/blog/?p=1806</link>
			</item>
	<item>
		<title>[Webinar] Cloud Based Security Services: Saving Cloud Computing Users From Evil-Doers</title>
		<description><![CDATA[I wanted to give you a heads-up on a webinar that Andy Ellis (Akamai,) Jeremiah Grossman (Whitehat) and I did at the tail-end of the RSA Security Conference.  The webinar will be held on 3/31/10 at 12:00 pm EST. You can register here. Web based threats are becoming increasingly malicious and sophisticated every day The [...]]]></description>
		<link>http://www.rationalsurvivability.com/blog/?p=1802</link>
			</item>
	<item>
		<title>Video: Cloud Computing in Government&#8230;</title>
		<description><![CDATA[I got the pleasure of moderating a great &#8220;Cloud Computing in Government&#8221; panel a few weeks ago at a conference in D.C.  The panelists included Mark Krzysko (Department of Defense,) Tim Schmidt (CIO, U.S. Dept. of Transportation,) and Mike Nelson (Professor, Georgetown University.) The videographer jumped me on the way out to capture the essence [...]]]></description>
		<link>http://www.rationalsurvivability.com/blog/?p=1799</link>
			</item>
	<item>
		<title>Incomplete Thought: The Other Side Of Cloud &#8211; Where The (Wild) Infrastructure Things Are&#8230;</title>
		<description><![CDATA[This is bound to be an unpopular viewpoint.  I&#8217;ve struggled with how to write it because I want to inspire discussion not a religious battle.  It has been hard to keep it an incomplete thought. I&#8217;m not sure I have succeeded I&#8217;d like you to understand that I come at this from the perspective of [...]]]></description>
		<link>http://www.rationalsurvivability.com/blog/?p=1793</link>
			</item>
	<item>
		<title>Chattin&#8217; With the Boss: &#8220;Securing the Network&#8221; (Waiting For the Jet Pack)</title>
		<description><![CDATA[At the RSA security conference last week I spent some time with Tom Gillis on a live uStream video titled &#8220;Securing the Network.&#8221; Tom happens to be (as he points out during a rather funny interlude) my boss&#8217; boss &#8212; he&#8217;s the VP and GM of Cisco&#8216;s STBU (Security Technology Business Unit.) It&#8217;s an interesting [...]]]></description>
		<link>http://www.rationalsurvivability.com/blog/?p=1784</link>
			</item>
	<item>
		<title>2010 RSA Security Bloggers Award &#8211; Thanks A Bunch&#8230;</title>
		<description><![CDATA[I don&#8217;t pay much attention to lists or awards, other than to usually make fun of them (especially when I&#8217;m put on one.) However, this time I&#8217;ll make an exception. I was nominated this year for the RSA Security Bloggers Awards in the category of &#8220;Most Entertaining blog&#8221; and was voted &#8220;most likely to do [...]]]></description>
		<link>http://www.rationalsurvivability.com/blog/?p=1781</link>
			</item>
	<item>
		<title>RSA Interview (c/o Tripwire) On the State Of Information Security In Virtualized/Cloud Environments.</title>
		<description><![CDATA[David Sparks (c/o Tripwire) interviewed me on the state of Information Security in virtualized/cloud environments.  It&#8217;s another reminder about Information Centricity. Direct Link here. Emedded below: Related articles by Zemanta Six Year Old Rationalizes the Cloud (rationalsurvivability.com) Cloud Computing Security: (Orchestral) Maneuvers In the Dark? (rationalsurvivability.com) From the X-Files &#8211; The Cloud in Context: Evolution [...]]]></description>
		<link>http://www.rationalsurvivability.com/blog/?p=1779</link>
			</item>
	<item>
		<title>Slides from My Cloud Security Alliance Keynote: The Cloud Magic 8 Ball (Future Of Cloud)</title>
		<description><![CDATA[Here are the slides from my Cloud Security Alliance (CSA) keynote from the Cloud Security Summit at the 2010 RSA Security Conference. The punchline is as follows: All this iteration and debate on the future of the &#8220;back-end&#8221; of Cloud Computing &#8212; the provider side of the equation &#8212; is ultimately less interesting than how [...]]]></description>
		<link>http://www.rationalsurvivability.com/blog/?p=1777</link>
			</item>
	<item>
		<title>Virtual Networking/Nexus 1000v Virtual Switch Blogger Roundtable/WebEx Logistics &#8211; March 2nd.</title>
		<description><![CDATA[About a year before I started working at the Jolly Green Giant (Cisco) I had a rather loud and addictive hobby that was focused on proving that Cisco would offer a &#8220;third party&#8221; virtual switch for VMware environments.  This sort of unhealthy fascination also dovetailed with another related to &#8220;Project California&#8221; which later became the [...]]]></description>
		<link>http://www.rationalsurvivability.com/blog/?p=1774</link>
			</item>
	<item>
		<title>Six Year Old Rationalizes the Cloud</title>
		<description><![CDATA[My youngest, Olivia, was interested in a video promo I was filming today for the RSA Security Conference on Cloud Computing.  She mentioned that she wanted to film a spot on Cloud, too.  Who am I to argue? Direct link here.  Embedded below. &#8230;she gets rather upset about people&#8217;s poor password practices around 6:25 or [...]]]></description>
		<link>http://www.rationalsurvivability.com/blog/?p=1771</link>
			</item>
	<item>
		<title>Don’t Hassle the Hoff: Recent Press &amp; Podcast Coverage &amp; Upcoming Speaking Engagements</title>
		<description><![CDATA[Here is some of the recent coverage from the last couple of months or so on topics relevant to content on my blog, presentations and speaking engagements.  No particular order or priority and I haven&#8217;t kept a good record, unfortunately. Important Stuff I&#8217;m Working On: Cloud Security Alliance CloudAudit/A6 Common Assurance Metrics Press/Technology &#38; Security [...]]]></description>
		<link>http://www.rationalsurvivability.com/blog/?p=1755</link>
			</item>
	<item>
		<title>Comments on the PwC/TSB Debate: The cloud/thin computing will fundamentally change the nature of cyber security…</title>
		<description><![CDATA[I saw a very interesting post on LinkedIn with the title PwC/TSB Debate: The cloud/thin computing will fundamentally change the nature of cyber security… PricewaterhouseCoopers are working with the Technology Strategy Board (part of BIS) on a high profile research project which aims to identify future technology and cyber security trends. These statements are forward [...]]]></description>
		<link>http://www.rationalsurvivability.com/blog/?p=1747</link>
			</item>
	<item>
		<title>The Automated Audit, Assertion, Assessment, and Assurance API (A6) Becomes: CloudAudit</title>
		<description><![CDATA[I&#8217;m happy to announce that the Automated Audit, Assertion, Assessment, and Assurance API (A6) working group is organizing under the brand of &#8220;CloudAudit.&#8221;  We&#8217;re doing so to enable reaching a broader audience, ensure it is easier to find us in searches and generally better reflect the mission of the group.  A6 remains our byline. We&#8217;ve [...]]]></description>
		<link>http://www.rationalsurvivability.com/blog/?p=1739</link>
			</item>
	<item>
		<title>Pimping the Security Non-Cons: Troopers 2010</title>
		<description><![CDATA[My friends at ERNW in Germany are putting on another fantastic security conference this year. I was lucky enough to attend Troopers &#8217;08 in Munich and this year it&#8217;s in Heidelberg.  Check out the details here. TROOPERS10 &#8211; This time it&#8217;s a home match. This year we&#8217;re bringing back the action right to the place [...]]]></description>
		<link>http://www.rationalsurvivability.com/blog/?p=1735</link>
			</item>
	<item>
		<title>Microsoft Azure Going &#8220;Down Stack,&#8221; Adding IaaS Capabilities. AWS/VMware WAR!</title>
		<description><![CDATA[It&#8217;s very interesting to see that now that infrastructure-as-a-service (IaaS) players like Amazon Web Services are clawing their way &#8220;up the stack&#8221; and adding more platform-as-a-service (PaaS) capabilities, that Microsoft is going &#8220;down stack&#8221; and providing IaaS capabilities by way of adding RDP and VM capabilities to Azure. From Carl Brooks&#8217; (@eekygeeky) article today: Microsoft [...]]]></description>
		<link>http://www.rationalsurvivability.com/blog/?p=1727</link>
			</item>
	<item>
		<title>Where Are the Network Virtual Appliances? Hobbled By the Virtual Network, That&#8217;s Where&#8230;</title>
		<description><![CDATA[Allan Leinwand from GigaOm wrote a great article asking &#8220;Where are the network virtual appliances?&#8221; This was followed up by another excellent post by Rich Miller. Allan sets up the discussion describing how we&#8217;ve typically plumbed disparate physical appliances into our network infrastructure to provide discrete network and security capabilities such as load balancers, VPNs, [...]]]></description>
		<link>http://www.rationalsurvivability.com/blog/?p=1717</link>
			</item>
	<item>
		<title>Hacking Exposed: Virtualization &amp; Cloud Computing&#8230;Feedback Please</title>
		<description><![CDATA[Craig Balding, Rich Mogull and I are working on a book due out later this year. It&#8217;s the latest in the McGraw-Hill &#8220;Hacking Exposed&#8221; series.  We&#8217;re focusing on virtualization and cloud computing security. We have a very interesting set of topics to discuss but we&#8217;d like to crowd/cloud-source ideas from all of you. The table [...]]]></description>
		<link>http://www.rationalsurvivability.com/blog/?p=1713</link>
			</item>
	<item>
		<title>MashSSL &#8211; An Excellent Idea You&#8217;ve Probably Never Heard Of&#8230;</title>
		<description><![CDATA[MashSSL allows web applications to mutually authenticate and establish a secure channel without having to trust the user or the browser. MashSSL is a Layer 7 security protocol running within HTTP in a RESTful fashion. It uses an innovation called "friend in the middle" to turn the proven SSL protocol into a multi-party protocol that inherits SSL's security, efficiency and mature trust infrastructure]]></description>
		<link>http://www.rationalsurvivability.com/blog/?p=1704</link>
			</item>
	<item>
		<title>Cloud: Security Doesn&#8217;t Matter (Or, In Cloud, Nobody Can Hear You Scream)</title>
		<description><![CDATA[In the Information Security community, many of us have long come to the conclusion that we are caught in what I call my &#8220;Security Hamster Sine Wave Of Pain.&#8221;  Those of us who have been doing this awhile recognize that InfoSec is a zero-sum game; it&#8217;s about staving off the inevitable and trying to ensure [...]]]></description>
		<link>http://www.rationalsurvivability.com/blog/?p=1694</link>
			</item>
	<item>
		<title>Incomplete Thought: Batteries &#8211; The Private Cloud Equivalent Of Electrical Utility&#8230;</title>
		<description><![CDATA[If the power utility "grid" represents Public Cloud, then perhaps batteries are a reasonable equivalent for Private Cloud.]]></description>
		<link>http://www.rationalsurvivability.com/blog/?p=1687</link>
			</item>
	<item>
		<title>&#8220;Vint &amp; Me&#8221; &#8211; Kickin&#8217; Butt &amp; Takin&#8217; Names (Unfortunately Mine&#8230;)</title>
		<description><![CDATA[I think perhaps my choice of words were met with an unfortunate style of punctuation I was not expecting&#8230; The Internet &#8212; once again kicking security&#8217;s ass, Karate Kid style, no less&#8230; It seems I&#8217;m going to have to sharpen my mad skills, as the previous two meetings have led to similar results: and&#8230;]]></description>
		<link>http://www.rationalsurvivability.com/blog/?p=1678</link>
			</item>
	<item>
		<title>Cloud: Over Subscription vs. Over Capacity &#8211; Two Different Things</title>
		<description><![CDATA[There&#8217;s been a very interesting set of discussions lately regarding performance anomalies across Cloud infrastructure providers.  The most recent involves Amazon Web Services and RackSpace Cloud. Let&#8217;s focus on the former because it&#8217;s the one that has a good deal of analysis and data attached to it. Reuven Cohen&#8217;s post (Oversubscribing the Cloud) summarizing many [...]]]></description>
		<link>http://www.rationalsurvivability.com/blog/?p=1672</link>
			</item>
	<item>
		<title>Cloud Light Presents: Real Men Of Genius &#8211; Mr. Dump All Your Crap In the Cloud Guy.</title>
		<description><![CDATA[It&#8217;s full of awesomesauce. Here. Cloud Light Presents&#8230;Real Men of Genius {Real Men of Genius&#8230;} Today we salute you, Mr. Dump-All-Your-Crap-In-the-Cloud Guy {Mr. Dump-All-Your-Crap-In-the-Cloud Guy} Some seek danger in cliff diving&#8230;others? Competitive eating&#8230;flamethrowing or ferret wrestling. But You? You put data in other people&#8217;s hands in the Cloud {You&#8217;re asking for it} Armed with a [...]]]></description>
		<link>http://www.rationalsurvivability.com/blog/?p=1665</link>
			</item>
	<item>
		<title>Recording &amp; Playback of WebEx A6 Working Group Kick-Off Call from 1/8/2010 Available</title>
		<description><![CDATA[If you&#8217;re interested in the great discussion and presentations we had during the kickoff call for the A6 (Automated Audit, Assertion, Assessment, and Assurance API) Working Group, there are two options to listen/view the WebEx recording: Topic: A6 API Working Group &#8211; Kickoff Call-20100108 1704 Create time: 1/8/10 10:07 am File size: 33.23MB Duration: 1 [...]]]></description>
		<link>http://www.rationalsurvivability.com/blog/?p=1662</link>
			</item>
	<item>
		<title>To Achieve True Cloud (X/Z)en, One Must Leverage Introspection</title>
		<description><![CDATA[Back in October 2008, I wrote a post detailing efforts around the Xen community to create a standard security introspection API (Xen.Org Launches Community Project To Bring VM Introspection to Xen The Xen Introspection Project is a community effort within Xen.org to leverage the existing research presented above with other work not yet public to [...]]]></description>
		<link>http://www.rationalsurvivability.com/blog/?p=1657</link>
			</item>
	<item>
		<title>The Great Cloud Security Challenge: I Triple-Dog-Dare You&#8230;</title>
		<description><![CDATA[There&#8217;s an awful lot of hyperbole being flung back and forth about the general state of security and Cloud-based services. I&#8217;ve spent enough time highlighting both the practical and hypothetical (many of which actually have been realized) security issues created and exacerbated by Cloud up and down the stack, from IaaS to SaaS. It seems, [...]]]></description>
		<link>http://www.rationalsurvivability.com/blog/?p=1648</link>
			</item>
	<item>
		<title>How Many Open Letters To Howard Schmidt Do We Need? Just One.</title>
		<description><![CDATA[My friend Adam at the The New School Information Security Blog wrote An Open Letter to the New Cyber-Security Czar: Congratulations on the new job! Even as a cynic, I’m surprised at just how fast the knives have come out, declaring that you’ll get nothing done. I suppose that low expectations are easy to exceed. [...]]]></description>
		<link>http://www.rationalsurvivability.com/blog/?p=1642</link>
			</item>
	<item>
		<title>2010 &#8211; It&#8217;s Time for Security Resolutions Not Predictions&#8230;</title>
		<description><![CDATA[November and December usually signal the onslaught of security predictions for the coming year. They&#8217;re usually focused on the negative. I&#8217;ve done these a couple of times and while I find the mental exercise interesting, it really doesn&#8217;t result in anything, well, actionable. So, this year I&#8217;m going to state what I am *going* to [...]]]></description>
		<link>http://www.rationalsurvivability.com/blog/?p=1639</link>
			</item>
	<item>
		<title>Cloud Security Alliance v2.1 Security Guidance for Critical Areas of Focus in Cloud Computing Available</title>
		<description><![CDATA[Version 2.1 of the Cloud Security Alliance &#8220;Security Guidance for Critical Areas of Focus in Cloud Computing&#8221; is available for download here. It&#8217;s important to note that in this version of the guidance there are some notable changes in structure and content focus: The guidance provided herein is the second version of the Cloud Security [...]]]></description>
		<link>http://www.rationalsurvivability.com/blog/?p=1630</link>
			</item>
	<item>
		<title>Speaking at the 2009 Federal Identity Management &amp; Cybersecurity Conference</title>
		<description><![CDATA[The (first annual) 2009 Federal Identity Management &#38; Cyber Security Conference is being held in Washington on December 15-16th.  I&#8217;m speaking on day two on a panel moderated by Earl Crane of DHS on &#8220;Innovation and security in Cloud Computing.&#8221; The Information Security and Identity Management Committee (ISIMC) of the Federal CIO Council is taking [...]]]></description>
		<link>http://www.rationalsurvivability.com/blog/?p=1620</link>
			</item>
	<item>
		<title>Cloud Computing Public Service Announcement &#8211; Please Read</title>
		<description><![CDATA[If your security practices suck in the physical realm, you&#8217;ll be delighted by the surprising lack of change when you move to Cloud. Thank You. /Hoff]]></description>
		<link>http://www.rationalsurvivability.com/blog/?p=1618</link>
			</item>
	<item>
		<title>Dear Public Cloud Providers: Please Make Your Networking Capabilities Suck Less. Kthxbye</title>
		<description><![CDATA[There are lots of great discussions these days about how infrastructure and networking need to become more dynamic and intelligent in order to more fully enable the mobility and automation promised by both virtualization and cloud computing.  There are many examples of how that&#8217;s taking place in the enterprise. Incumbent networking vendors and emerging cloud/network [...]]]></description>
		<link>http://www.rationalsurvivability.com/blog/?p=1603</link>
			</item>
	<item>
		<title>Great InformationWeek/Dark Reading/Black Hat Cloud &amp; Virtualization Security Virtual Panel on 12/9</title>
		<description><![CDATA[I wanted to let you know about about a cool virtual panel I&#8217;m moderating as part of the InformationWeek/Dark Reading/Black Hat virtual event titled &#8220;IT Security: The Next Decade&#8221; on December 9th. There are numerous awesome speakers throughout the day, but the panel I&#8217;m moderating is especially interesting to me because I was able to [...]]]></description>
		<link>http://www.rationalsurvivability.com/blog/?p=1596</link>
			</item>
	<item>
		<title>From the X-Files &#8211; The Cloud in Context: Evolution from Gadgetry to Popular Culture</title>
		<description><![CDATA[Below is an article I wrote many months ago prior to all the Nicholas Carr &#8220;electricity ain&#8217;t Cloud&#8221; discussions.  The piece was one from a collection that was distributed to &#8220;&#8230;the Intelligence Community, the DoD, and Congress&#8221; with the purpose of giving a high-level overview of Cloud security issues. &#8211; The Cloud in Context: Evolution [...]]]></description>
		<link>http://www.rationalsurvivability.com/blog/?p=1519</link>
			</item>
	<item>
		<title>Apologizing In Advance: I&#8217;ll Be On PaulDotCom 11/27&#8230;</title>
		<description><![CDATA[This won&#8217;t end well. Day after Thanksgiving: Hoff Friday By Mike Perez on November 24, 2009 12:00 PM &#124; Permalink- Paul, Carlos, Mick, Larry, John, &#38; Darren. What better way to emerge from your (Wild) Turkey stupor than to join the PDC crew and guest Christofer Hoff live at 20:30 EST on Friday November 27th [...]]]></description>
		<link>http://www.rationalsurvivability.com/blog/?p=1573</link>
			</item>
	<item>
		<title>The Cloud &amp; eHarmony&#8217;s 29 Dimensions Of Compatability&#8230;</title>
		<description><![CDATA[I speak to many customers &#8212; large companies in numerous verticals and service providers &#8211;  who are for the reasons we are all very well aware of, engaging in projects large and small focused on Cloud adoption. On the enterprise side, the dialog almost inevitably goes like this: We&#8217;re working on taking applications and data [...]]]></description>
		<link>http://www.rationalsurvivability.com/blog/?p=1569</link>
			</item>
	<item>
		<title>ENISA launches Cloud Computing Security Risk Assessment Document</title>
		<description><![CDATA[ENISA (the European Network and Information Security Agency) today launched their 124 page report on Cloud Computing Security Risk Assessment. At first glance it&#8217;s an excellent read and will be a fantastic accompaniment to the the CSA&#8217;s guidance.  I plan to dig into it more over the weekend.  I really appreciate the risk assessment approach [...]]]></description>
		<link>http://www.rationalsurvivability.com/blog/?p=1559</link>
			</item>
	<item>
		<title>Cloud Security: Dilbert Style</title>
		<description><![CDATA[From: http://dilbert.com/strips/comic/2009-11-19/]]></description>
		<link>http://www.rationalsurvivability.com/blog/?p=1554</link>
			</item>
	<item>
		<title>Just A Reflective Bookmark: Microsoft&#8217;s Azure&#8230;The Dark Horse Emergeth&#8230;</title>
		<description><![CDATA[I&#8217;ve said it before, I&#8217;ll say it again: Don&#8217;t underestimate Microsoft and the potential disruption Azure will deliver.* You might not get Microsoft&#8217;s strategy for Azure. Heck, much of Microsoft may not get Microsoft&#8217;s strategy for Azure, but one thing is for sure: Azure will be THE platform for products, solutions and services across all [...]]]></description>
		<link>http://www.rationalsurvivability.com/blog/?p=1537</link>
			</item>
	<item>
		<title>The A6 (Audit, Assertion, Assessment, and Assurance API) Working Group is Live. Please join &amp; read the intro.</title>
		<description><![CDATA[For those of you following along at home, the A6 (Audit, Assertion, Assessment, and Assurance API) Working Group is Live. I&#8217;ve setup the Google group so please join &#38; read the introduction here. Hope to see you there. /Hoff]]></description>
		<link>http://www.rationalsurvivability.com/blog/?p=1533</link>
			</item>
	<item>
		<title>Silent Lucidity: IaaS &#8212; Already A Dinosaur? The Evolution of PaaSasaurus Rex&#8230;</title>
		<description><![CDATA[Sitting in an impressive room at the Google campus in Mountain View last month, I asked the collective group of brainpower a slightly rhetorical question: How much longer do you feel pure-play Infrastructure-As-A-Service will be a relevant service model within the spectrum of cloud services? I couched the question with previous &#8220;incomplete thoughts*&#8221; relating to [...]]]></description>
		<link>http://www.rationalsurvivability.com/blog/?p=1523</link>
			</item>
	<item>
		<title>Dear Santa: All I Want For Christmas On My Amazon Wishlist Is a Straight Answer&#8230;</title>
		<description><![CDATA[A couple of weeks ago amidst another interesting Amazon Web Services announcement featuring the newly-arrived Relational Database Service, Werner Vogels (Amazon CTO) jokingly retweeted a remark that someone made suggesting he was like &#8220;&#8230;Santa for nerds.&#8221; So, now that I have Werner following me on Twitter and a confirmed mailing address (clearly the North Pole) I [...]]]></description>
		<link>http://www.rationalsurvivability.com/blog/?p=1513</link>
			</item>
	<item>
		<title>Cloud/Cloud Computing Definitions &#8211; Why they Do(n&#8217;t) Matter&#8230;</title>
		<description><![CDATA[A couple of weeks ago I wrote a piece titled Cloud: The Other White Meat…On Service Failures &#38; Hysterics in which I summarized why Cloud/Cloud Computing (or what I now refer to as Cloudputing has become such a definitional Super-Fund clean up site: To me, cloud is the “other white meat” to the Internet’s array [...]]]></description>
		<link>http://www.rationalsurvivability.com/blog/?p=1507</link>
			</item>
	<item>
		<title>Don’t Hassle the Hoff: Recent Press &amp; Podcast Coverage &amp; Upcoming Speaking Engagements</title>
		<description><![CDATA[Here is some of the recent coverage from the last month or so on topics relevant to content on my blog, presentations and speaking engagements.  No particular order or priority and I haven&#8217;t kept a good record, unfortunately. Press/Technology &#38; Security eZines/Website/Blog Coverage/Meaningful Links: Threatpost &#8211; Coverage of my SecTor 2009 Cloud Security Keynote Can [...]]]></description>
		<link>http://www.rationalsurvivability.com/blog/?p=1497</link>
			</item>
	<item>
		<title>Can We Secure Cloud Computing?  Can We Afford Not To?</title>
		<description><![CDATA[[The following is a re-post from the Microsoft (Technet) blog I did as a lead up to my Cloudifornication presentation at Bluehat v9 I'll be posting after I deliver the revised edition tomorrow.] There have been many disruptive innovations in the history of modern computing, each of them in some way impacting how we create, [...]]]></description>
		<link>http://www.rationalsurvivability.com/blog/?p=1491</link>
			</item>
	<item>
		<title>Incomplete Thought: The Cloud Software vs. Hardware Value Battle &amp; Why AWS Is Really A Grid&#8230;</title>
		<description><![CDATA[Some suggest in discussing the role and long-term sustainable value of infrastructure versus software in cloud that software will marginalize bespoke infrastructure and the latter will simply commoditize. I find that an interesting assertion, given that it tends to ignore the realities that both hardware and software ultimately suffer from a case of Moore&#8217;s Law [...]]]></description>
		<link>http://www.rationalsurvivability.com/blog/?p=1476</link>
			</item>
	<item>
		<title>&#8220;Open&#8221; means more than just an API&#8230;Google&#8217;s Data Liberation Project Ponies Up</title>
		<description><![CDATA[This is chewy goodness. Short and sweet from the Googleborg via a Webmonkey article titled &#8220;Pack Up Your Data and Leave Whenever You Want, It’s the New Rule of the Cloud:&#8221; Users should be able to control the data they store in any of Google&#8217;s products. Our team&#8217;s goal is to make it easier for them [...]]]></description>
		<link>http://www.rationalsurvivability.com/blog/?p=1466</link>
			</item>
	<item>
		<title>Amazon Web Services: It&#8217;s Not The Size Of the Ship, But Rather The Motion Of the&#8230;</title>
		<description><![CDATA[Carl Brooks (@eekygeeky) gets some fantastic, thought-provoking interviews.  His recent article wherein he interviewed Peter DeSantis, VP of EC2, Amazon Web Services, was titled: &#8220;Amazon would like to remind you where the hype started&#8221; is another great example. However, this article left a bad taste in my mouth and ultimately invites more questions than it [...]]]></description>
		<link>http://www.rationalsurvivability.com/blog/?p=1456</link>
			</item>
	<item>
		<title>Transparency: I Do Not Think That Means What You Think That Means&#8230;</title>
		<description><![CDATA[Ha ha! You fool! You fell victim to one of the classic blunders &#8211; The most famous of which is &#8220;never get involved in a cloud war in Asia&#8221; &#8211; but only slightly less well-known is this: &#8220;Never go against Werner when availability is on the line!&#8221; As an outsider, it&#8217;s easy to play armchair [...]]]></description>
		<link>http://www.rationalsurvivability.com/blog/?p=1440</link>
			</item>
	<item>
		<title>Cloud: The Other White Meat&#8230;On Service Failures &amp; Hysterics</title>
		<description><![CDATA[Cloud: the other white meat&#8230; To me, cloud is the &#8220;other white meat&#8221; to the Internet&#8217;s array of widely-available chicken parts.  Both are tasty and if I order parmigiana made with either, they may even look or taste the same.  If someone orders it in a restaurant, all they say they care about is how [...]]]></description>
		<link>http://www.rationalsurvivability.com/blog/?p=1429</link>
			</item>
	<item>
		<title>AMI Secure? (Or: Shared AMIs/Virtual Appliances &#8211; Bot or Not?)</title>
		<description><![CDATA[To some of you, this is going to sound like obvious and remedial advice that you would consider common sense.  This post is not for you. Some of you &#8212; and you know who you are &#8212; are going to walk away from this post with a scratching sound coming from inside your skull. The [...]]]></description>
		<link>http://www.rationalsurvivability.com/blog/?p=1419</link>
			</item>
	<item>
		<title>Cloud Providers and Security &#8220;Edge&#8221; Services &#8211; Where&#8217;s The Beef?</title>
		<description><![CDATA[Previously I wrote a post titled &#8220;Oh Great Security Spirit In the Cloud: Have You Seen My WAF, IPS, IDS, Firewall…&#8221; in which I described the challenges for enterprises moving applications and services to the Cloud while trying to ensure parity in compensating controls, some of which are either not available or suffer from the [...]]]></description>
		<link>http://www.rationalsurvivability.com/blog/?p=1407</link>
			</item>
	<item>
		<title>Really Interesting Crap In My Browser Tabs: Poor Man&#8217;s Del.icio.us</title>
		<description><![CDATA[I usually keep 40-50 tabs open in my browser for review when I find things worthy of review. What usually happens is the damn thing memory leaks, implodes and I lose a bunch of good stuff.  Here&#8217;s my uber-optimized and virtualized solution to this problem.  Post &#8216;em here: StorageMojo &#8211; The Cloud Quadrant Simon Crosby, [...]]]></description>
		<link>http://www.rationalsurvivability.com/blog/?p=1402</link>
			</item>
	<item>
		<title>The Emotion of VMotion&#8230;</title>
		<description><![CDATA[A lot has been said about the wonders of workload VM portability. Within the construct of virtualization, and especially VMware, an awful lot of time is spent on VM Mobility but as numerous polls and direct customer engagements have shown, the majority (50% and higher) do not use VMotion.  I talked about this in a [...]]]></description>
		<link>http://www.rationalsurvivability.com/blog/?p=1391</link>
			</item>
	<item>
		<title>Incomplete Thought: Virtual Machines Are the Problem, Not the Solution&#8230;</title>
		<description><![CDATA[I&#8217;m an infrastructure guy. A couple of days ago I had a lightbulb go on.  If you&#8217;re an Apps person, you&#8217;ve likely already had your share of illumination.  I&#8217;ve just never thought about things from this perspective.  Please don&#8217;t think any less of me You can bet I&#8217;m talking above my pay grade here, but [...]]]></description>
		<link>http://www.rationalsurvivability.com/blog/?p=1371</link>
			</item>
	<item>
		<title>Google &amp; AWS: Just Goes To Prove You Can Have Your Cloud and, um, Eat It Too&#8230;</title>
		<description><![CDATA[&#8230;and by &#8220;eat it&#8221; I mean that how you think I mean that.  I feel for these guys, they have big targets on their backs, but that&#8217;s what happens when you&#8217;re a market leader. To wit, there are two polarized views expressed every time Google or Amazon have an outage or service interruption given that [...]]]></description>
		<link>http://www.rationalsurvivability.com/blog/?p=1359</link>
			</item>
	<item>
		<title>Redux: Patching the Cloud</title>
		<description><![CDATA[Back in 2008 I wrote a piece titled &#8220;Patching the Cloud&#8221; in which I highlighted the issues associated with the black box ubiquity of Cloud and what that means to patching/upgrading processes: Your application is sitting atop an operating system and underlying infrastructure that is managed by the cloud operator.  This “datacenter OS” may not [...]]]></description>
		<link>http://www.rationalsurvivability.com/blog/?p=1354</link>
			</item>
	<item>
		<title>Incomplete Thought: Forget VM Sprawl, Worry More About SaaSprawl&#8230;</title>
		<description><![CDATA[A lot of fuss has been made about run-away VM sprawl in enterprises who are heavily virtualized due to the ease with which a VM can constructed and operationalized. I&#8217;m not convinced about the reality versus the potential of VM Sprawl, meaning that I have no evidence from anyone facing this issue to date.  I [...]]]></description>
		<link>http://www.rationalsurvivability.com/blog/?p=1344</link>
			</item>
	<item>
		<title>Quick Question: Any Public Cloud Providers Using Intel TXT?</title>
		<description><![CDATA[Does anyone know of any Public Cloud Provider (or Private for that matter) that utilizes Intel&#8217;s TXT? Specifically, does anyone know if Amazon makes use of Intel&#8217;s TXT via their Xen-derivative VMM? Anyone care to share whether they know of any Cloud provider that PLANS to? Thanks in advance. Email responses welcome also [hoff @ [...]]]></description>
		<link>http://www.rationalsurvivability.com/blog/?p=1341</link>
			</item>
	<item>
		<title>DDoS &#8211; A Moose On Cloud&#8217;s Table Or A Pea Under The Mattress?</title>
		<description><![CDATA[Readers of my blog will no doubt be familiar with Roland Dobbins.  He&#8217;s commented on lots of posts here and whilst we don&#8217;t always see eye-to-eye, I really respect both his intellect and his style. So it&#8217;s fair to say that Roland is not a shy lad.  Formerly at Cisco and now at Arbor, he&#8217;s [...]]]></description>
		<link>http://www.rationalsurvivability.com/blog/?p=1333</link>
			</item>
	<item>
		<title>Proof Of How I Almost Took The Internet Down&#8230;</title>
		<description><![CDATA[I&#8217;ve tripped over it a couple of times. I&#8217;ve done things to it and with it that perhaps I shouldn&#8217;t have. I&#8217;ve even rebooted it once or twice. On Thursday, I tried &#8212; unsuccessfully &#8212; to once and for all take down the Internet. It&#8217;s he&#8217;s just too damned resilient for his own good. One [...]]]></description>
		<link>http://www.rationalsurvivability.com/blog/?p=1319</link>
			</item>
	<item>
		<title>Variety &amp; Darwinism In Solutions Is Innovation, In Standards It&#8217;s A War?</title>
		<description><![CDATA[I find it quite interesting that in the last few months or so, as Cloud has emerged as a full-fledged business opportunity, we&#8217;ve seen the rise of many new companies, strategies and technologies. For the most part, hype aside, people praise this as innovation and describe it as a natural evolutionary process. Strangely enough, with [...]]]></description>
		<link>http://www.rationalsurvivability.com/blog/?p=1316</link>
			</item>
	<item>
		<title>NESSessary Question: Will Virtualization Undermine Network Equipment Vendors?</title>
		<description><![CDATA[Greg Ness touched off an interesting discussion when he asked &#8220;Will Virtualization Undermine Network Equipment Vendors?&#8221;  It&#8217;s a great read summarizing how virtualization (and Cloud) are really beginning to accelerate how classical networking equipment vendors are re-evaluating their portfolios in order to come to terms with these disruptive innovations. I&#8217;ve written so much about this [...]]]></description>
		<link>http://www.rationalsurvivability.com/blog/?p=1310</link>
			</item>
	<item>
		<title>A Note On Multitenancy As A &#8216;Defining&#8217; Cloud Attribute&#8230;</title>
		<description><![CDATA[Balakrishna Narasimh and I were discussing the recent hoohaa on Public and Private Clouds when he made an observation on Twitter: Starting to think public vs private clouds is misleading terminology. more meaningful distinction is single-tenant vs multi-tenant clouds. I suggested that multitenancy can certainly be an attribute of Cloud deployment, but that I don&#8217;t [...]]]></description>
		<link>http://www.rationalsurvivability.com/blog/?p=1307</link>
			</item>
	<item>
		<title>Calling All Private Cloud Haters: Amazon Just Peed On Your Fire Hydrant&#8230;</title>
		<description><![CDATA[Werner Vogels brought a smile to my face today with his blog titled &#8220;Seamlessly Extending the Data Center &#8211; Introducing Amazon Virtual Private Cloud.&#8221;  In short: We have developed Amazon Virtual Private Cloud (Amazon VPC) to allow our customers to seamlessly extend their IT infrastructure into the cloud while maintaining the levels of isolation required [...]]]></description>
		<link>http://www.rationalsurvivability.com/blog/?p=1294</link>
			</item>
	<item>
		<title>On Appirio&#8217;s Prediction: The Rise &amp; Fall Of Private Clouds</title>
		<description><![CDATA[I was invited to add my comments to Appirio&#8217;s corporate blog in response to my opinions of their 2009 prediction &#8220;Rise and Fall of the Private Cloud,&#8221; but as I mentioned in kind on Twitter, debating a corporate talking point on a company&#8217;s blog is like watch two monkeys trying to screw a football; it&#8217;s [...]]]></description>
		<link>http://www.rationalsurvivability.com/blog/?p=1285</link>
			</item>
	<item>
		<title>Do We Need CloudNAPs? It&#8217;s A Virtually Certain Maybe.</title>
		<description><![CDATA[Allan Leinwand from GigaOm wrote a really interesting blog the other day titled: &#8220;Do Enterprises Need a Toll Road to the Cloud?&#8221; in which he suggested that perhaps what is needed to guarantee high performance and high security Cloud connectivity is essentially a middleman that maintains dedicated aggregate connectivity between &#8220;&#8230;each of the public cloud [...]]]></description>
		<link>http://www.rationalsurvivability.com/blog/?p=1281</link>
			</item>
	<item>
		<title>Follow-On: The Audit, Assertion, Assessment, and Assurance API (A6)</title>
		<description><![CDATA[Update 2/1/10: The A6 effort is in full-swing.  You can find out more about it at the Google Groups here. A few weeks ago I penned a blog discussing an idea I presented at a recent Public Sector Cloud gathering that later inherited the name &#8220;Audit, Assertion, Assessment, and Assurance API (A6)&#8221; The case for [...]]]></description>
		<link>http://www.rationalsurvivability.com/blog/?p=1276</link>
			</item>
	<item>
		<title>Cloudifornication: Indiscriminate Information Intercourse Involving Internet Infrastructure</title>
		<description><![CDATA[The talk I was scheduled to give at Blackhat in Vegas had that title.  Due to a timing issue, I couldn&#8217;t make Vegas. The summary of CI^6 goes something like this: What was in is now out. This metaphor holds true not only as an accurate analysis of what happens to our data with the [...]]]></description>
		<link>http://www.rationalsurvivability.com/blog/?p=1271</link>
			</item>
</channel>
</rss>
