<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Mark Masterson&#8217;s Brilliant Cloud Security Presentation</title>
	<atom:link href="http://www.rationalsurvivability.com/blog/?feed=rss2&#038;p=1010" rel="self" type="application/rss+xml" />
	<link>http://www.rationalsurvivability.com/blog/?p=1010</link>
	<description>Hoff&#039;s Ramblings about Information Survivability, Information Centricity, Risk Management and Disruptive Innovation. Oh, I have a fondness for virtualization and cloud computing security, too...</description>
	<lastBuildDate>Thu, 09 Sep 2010 02:54:50 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0.1</generator>
	<item>
		<title>By: Andrew Hay &#187; Blog Archive &#187; links for 2009-06-12</title>
		<link>http://www.rationalsurvivability.com/blog/?p=1010&#038;cpage=1#comment-4710</link>
		<dc:creator>Andrew Hay &#187; Blog Archive &#187; links for 2009-06-12</dc:creator>
		<pubDate>Fri, 12 Jun 2009 21:05:05 +0000</pubDate>
		<guid isPermaLink="false">http://www.rationalsurvivability.com/blog/?p=1010#comment-4710</guid>
		<description>[...] Rational Survivability » Mark Masterson’s Brilliant Cloud Security Presentation Chris is right, this is a great presentation. (tags: cloud thinking security) [...]</description>
		<content:encoded><![CDATA[<p>[...] Rational Survivability » Mark Masterson’s Brilliant Cloud Security Presentation Chris is right, this is a great presentation. (tags: cloud thinking security) [...]</p>
<p>Like or Dislike: <img style="padding: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="up-4710" src="http://www.rationalsurvivability.com/blog/wp-content/plugins/comment-rating/images/1_14_up.png" alt="Thumb up" onclick="javascript:ckratingKarma('4710', 'add', 'www.rationalsurvivability.com/blog/wp-content/plugins/comment-rating/', '1_14_');" title="" /> <span id="karma-4710-up" style="font-size:12px; color:#009933;">0</span>&nbsp;<img style="padding: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="down-4710" src="http://www.rationalsurvivability.com/blog/wp-content/plugins/comment-rating/images/1_14_down.png" alt="Thumb down" onclick="javascript:ckratingKarma('4710', 'subtract', 'www.rationalsurvivability.com/blog/wp-content/plugins/comment-rating/', '1_14_')" title="" /> <span id="karma-4710-down" style="font-size:12px; color:#990033;">0</span></p>]]></content:encoded>
	</item>
	<item>
		<title>By: Gunnar</title>
		<link>http://www.rationalsurvivability.com/blog/?p=1010&#038;cpage=1#comment-4647</link>
		<dc:creator>Gunnar</dc:creator>
		<pubDate>Wed, 10 Jun 2009 22:54:52 +0000</pubDate>
		<guid isPermaLink="false">http://www.rationalsurvivability.com/blog/?p=1010#comment-4647</guid>
		<description>My favorite part was &quot;hard problems like federated identity can not be solved with Russellian techniques&quot;, federation is likely to be one of the biggest opportunities and threats in the cloud, largely because of naming. Which brings up this:

&quot;There are only two hard things in Computer Science: cache invalidation and naming things.&quot; -Phil Karlton

Also, reminds me of something I remember Dan Geer saying once he got security figured out he would move onto something hard like naming.

And finally, 
&quot;You can&#039;t complete authorization in someone else&#039;s namespace&quot; -me

But federation has been reasonably working well for the last 200 years or so, and so I would not worry too much.</description>
		<content:encoded><![CDATA[<p>My favorite part was &#8220;hard problems like federated identity can not be solved with Russellian techniques&#8221;, federation is likely to be one of the biggest opportunities and threats in the cloud, largely because of naming. Which brings up this:</p>
<p>&#8220;There are only two hard things in Computer Science: cache invalidation and naming things.&#8221; -Phil Karlton</p>
<p>Also, reminds me of something I remember Dan Geer saying once he got security figured out he would move onto something hard like naming.</p>
<p>And finally,<br />
&#8220;You can&#8217;t complete authorization in someone else&#8217;s namespace&#8221; -me</p>
<p>But federation has been reasonably working well for the last 200 years or so, and so I would not worry too much.</p>
<p>Like or Dislike: <img style="padding: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="up-4647" src="http://www.rationalsurvivability.com/blog/wp-content/plugins/comment-rating/images/1_14_up.png" alt="Thumb up" onclick="javascript:ckratingKarma('4647', 'add', 'www.rationalsurvivability.com/blog/wp-content/plugins/comment-rating/', '1_14_');" title="" /> <span id="karma-4647-up" style="font-size:12px; color:#009933;">0</span>&nbsp;<img style="padding: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="down-4647" src="http://www.rationalsurvivability.com/blog/wp-content/plugins/comment-rating/images/1_14_down.png" alt="Thumb down" onclick="javascript:ckratingKarma('4647', 'subtract', 'www.rationalsurvivability.com/blog/wp-content/plugins/comment-rating/', '1_14_')" title="" /> <span id="karma-4647-down" style="font-size:12px; color:#990033;">0</span></p>]]></content:encoded>
	</item>
	<item>
		<title>By: Richard Bejtlich</title>
		<link>http://www.rationalsurvivability.com/blog/?p=1010&#038;cpage=1#comment-4639</link>
		<dc:creator>Richard Bejtlich</dc:creator>
		<pubDate>Wed, 10 Jun 2009 17:53:03 +0000</pubDate>
		<guid isPermaLink="false">http://www.rationalsurvivability.com/blog/?p=1010#comment-4639</guid>
		<description>Hi Hoff,

Take more credit for your work!  I didn&#039;t see anything special in that presentation.  The whole &quot;safe = healthy&quot; idea is hardly novel.  Any comparisons to nature fall short because our adversaries are far more intelligent than those in the wild.  

One other thought: my reaction to the so-called &quot;Healthy&quot; cloud showing multiple data repositories was this -- now I can exploit vulnerabilities or exposures in any one of those three clouds in order to get the same data.  Go ahead, add more clouds -- the probability of me find a V or E in the infrastructure as a whole just keeps increasing.

By the way, my criticism of the presentation doesn&#039;t mean I think 1990s approaches to security are appropriate for the cloud!</description>
		<content:encoded><![CDATA[<p>Hi Hoff,</p>
<p>Take more credit for your work!  I didn&#8217;t see anything special in that presentation.  The whole &#8220;safe = healthy&#8221; idea is hardly novel.  Any comparisons to nature fall short because our adversaries are far more intelligent than those in the wild.  </p>
<p>One other thought: my reaction to the so-called &#8220;Healthy&#8221; cloud showing multiple data repositories was this &#8212; now I can exploit vulnerabilities or exposures in any one of those three clouds in order to get the same data.  Go ahead, add more clouds &#8212; the probability of me find a V or E in the infrastructure as a whole just keeps increasing.</p>
<p>By the way, my criticism of the presentation doesn&#8217;t mean I think 1990s approaches to security are appropriate for the cloud!</p>
<p>Like or Dislike: <img style="padding: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="up-4639" src="http://www.rationalsurvivability.com/blog/wp-content/plugins/comment-rating/images/1_14_up.png" alt="Thumb up" onclick="javascript:ckratingKarma('4639', 'add', 'www.rationalsurvivability.com/blog/wp-content/plugins/comment-rating/', '1_14_');" title="" /> <span id="karma-4639-up" style="font-size:12px; color:#009933;">0</span>&nbsp;<img style="padding: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="down-4639" src="http://www.rationalsurvivability.com/blog/wp-content/plugins/comment-rating/images/1_14_down.png" alt="Thumb down" onclick="javascript:ckratingKarma('4639', 'subtract', 'www.rationalsurvivability.com/blog/wp-content/plugins/comment-rating/', '1_14_')" title="" /> <span id="karma-4639-down" style="font-size:12px; color:#990033;">0</span></p>]]></content:encoded>
	</item>
	<item>
		<title>By: Andreas</title>
		<link>http://www.rationalsurvivability.com/blog/?p=1010&#038;cpage=1#comment-4637</link>
		<dc:creator>Andreas</dc:creator>
		<pubDate>Wed, 10 Jun 2009 17:34:42 +0000</pubDate>
		<guid isPermaLink="false">http://www.rationalsurvivability.com/blog/?p=1010#comment-4637</guid>
		<description>This is a great preso indeed. It&#039;s interesting how we are moving from a definition of &quot;secure&quot; as a binary variable (like pregnant) to healthy which is really a scalar. A lot of the zombie/botnet stuff is also not as malignant (lower lethality) as stuff in the past. You don&#039;t get a BSOD or a corrupted boot block, because after all if the infection kills you then the botnet doesnt make any more money from spamming. See nature: ebola is a crappy virus - it&#039;s too lethal for its own good. Flu is the model: exploit and propagate, every season for millenia, without killing too many hosts. This is what the zombies are looking like. In fact, it is amusing to note that today&#039;s AV puts a much less subtle load on your CPU that the malware it&#039;s chasing!

I live with thousands of relatively harmless, symbiotic organisms in my body. If any of them got too strong they would harm me but at low levels I can ignore them. Is that going to be the go-forward model of computer health? Tolerate the mild ones?</description>
		<content:encoded><![CDATA[<p>This is a great preso indeed. It&#8217;s interesting how we are moving from a definition of &#8220;secure&#8221; as a binary variable (like pregnant) to healthy which is really a scalar. A lot of the zombie/botnet stuff is also not as malignant (lower lethality) as stuff in the past. You don&#8217;t get a BSOD or a corrupted boot block, because after all if the infection kills you then the botnet doesnt make any more money from spamming. See nature: ebola is a crappy virus &#8211; it&#8217;s too lethal for its own good. Flu is the model: exploit and propagate, every season for millenia, without killing too many hosts. This is what the zombies are looking like. In fact, it is amusing to note that today&#8217;s AV puts a much less subtle load on your CPU that the malware it&#8217;s chasing!</p>
<p>I live with thousands of relatively harmless, symbiotic organisms in my body. If any of them got too strong they would harm me but at low levels I can ignore them. Is that going to be the go-forward model of computer health? Tolerate the mild ones?</p>
<p>Like or Dislike: <img style="padding: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="up-4637" src="http://www.rationalsurvivability.com/blog/wp-content/plugins/comment-rating/images/1_14_up.png" alt="Thumb up" onclick="javascript:ckratingKarma('4637', 'add', 'www.rationalsurvivability.com/blog/wp-content/plugins/comment-rating/', '1_14_');" title="" /> <span id="karma-4637-up" style="font-size:12px; color:#009933;">0</span>&nbsp;<img style="padding: 0px; border: none; cursor: pointer;" onmouseover="this.width=this.width*1.3" onmouseout="this.width=this.width/1.2" id="down-4637" src="http://www.rationalsurvivability.com/blog/wp-content/plugins/comment-rating/images/1_14_down.png" alt="Thumb down" onclick="javascript:ckratingKarma('4637', 'subtract', 'www.rationalsurvivability.com/blog/wp-content/plugins/comment-rating/', '1_14_')" title="" /> <span id="karma-4637-down" style="font-size:12px; color:#990033;">0</span></p>]]></content:encoded>
	</item>
</channel>
</rss>
