Perimeter
2/18/2013
12:59 PM
Gunnar Peterson
Gunnar Peterson
Commentary
Connect Directly
RSS
E-Mail
50%
50%

RSA: What To Watch For And What Vaccinations To Get Before Rocking The Casbah

Pro tip: It's not threats, it's not capabilities -- it's integration

Spending on security and identity continues to progress and vendors, nothing if not observant, have tried their best to productize the gap between enterprise want and what currently exists. Shopping for rugs in Tangier feels sedate compared to walking the RSA showroom floor.

RSA Conference 2013
Click here for more articles.

This trade show is a necessary part of the industry because as Whit Diffie said, "I understood the importance of cryptography and, in a sense, I understood the scale. I imagined myriad devices encrypting billions of bits communicated among millions of people. What I didn't understand was the business aspect, how many thousands of people had to be hustling to turn a buck to make it happen."

One problem is that all this hustling around a pretty abstract topic like security can create a lot of confusion. I have observed over the years a large number of otherwise sane, pragmatic people who board the plane for SFO and return dazzled by bright and shiny "solutions" that were apparently whispered to them, said behind closed doors or inside a reality distortion field.

So here is the antidote, the vaccination regime before your flight lands at SFO. There is an endless stream of "solutions", each with some ability to foster reasonable doubt that, ceteris paribus, they may lay claim to a marginal security improvement for your company. Here is the part that matters in that sentence for your company.

The focus will, of course, be on the heavy threats they've seen (the whisper part), and their double secret IP (another whisper part best left til we're behind closed doors, or a couple drinks in). These are enough to fool even smart observers, consider Bruce Schneier's time inside the reality distortion field circa 2008:

    Talk to the exhibitors, though, and the most common complaint is that the attendees aren't buying.

    It's not the quality of the wares. The show floor is filled with new security products, new technologies, and new ideas. Many of these are products that will make the attendees' companies more secure in all sorts of different ways. The problem is that most of the people attending the RSA Conference can't understand what the products do or why they should buy them. So they don't.

I think the quality of the wares has a lot to do with it, but leaving that aside, what I think matters much more is not how is any particular product or service, its how good is it for your company. This means integration.

So here is the Pro Tip, before landing at SFO have in mind a checklist of how any product set you are looking at, what are the key questions around process, organizational and technical integration? Sure solution X maybe improves authentication in some way, but what does the API look like, how will my developers work with it, how does it work with my existing web apps' authorization services? What protocols does it use, what type of communications, what endpoints, synchronous or asynchronous, what's the session manager, what identity providers does it work with, what relying parties, what's the token type, what are the failure modes, what security gaps remain? What development or operational processes need to change, what training do my people need, can my people even do this or is it a outsourced only? Question one is for sure on product efficacy and what its trying to solve, but questions two through two hundred should focus on process, organization and technical integration, the steps necessary to realize the efficacy in your company. Gunnar Peterson (@oneraindrop) works on AppSec - Cloud, Mobile and Identity. He maintains a blog at http://1raindrop.typepad.com. View Full Bio

Comment  | 
Print  | 
More Insights
Register for Dark Reading Newsletters
White Papers
Flash Poll
Current Issue
Cartoon
Video
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2013-6306
Published: 2014-08-22
Unspecified vulnerability on IBM Power 7 Systems 740 before 740.70 01Ax740_121, 760 before 760.40 Ax760_078, and 770 before 770.30 01Ax770_062 allows local users to gain Service Processor privileges via unknown vectors.

CVE-2014-0232
Published: 2014-08-22
Multiple cross-site scripting (XSS) vulnerabilities in framework/common/webcommon/includes/messages.ftl in Apache OFBiz 11.04.01 before 11.04.05 and 12.04.01 before 12.04.04 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors, which are not properly handled in a (1)...

CVE-2014-3525
Published: 2014-08-22
Unspecified vulnerability in Apache Traffic Server 4.2.1.1 and 5.x before 5.0.1 has unknown impact and attack vectors, possibly related to health checks.

CVE-2014-3563
Published: 2014-08-22
Multiple unspecified vulnerabilities in Salt (aka SaltStack) before 2014.1.10 allow local users to have an unspecified impact via vectors related to temporary file creation in (1) seed.py, (2) salt-ssh, or (3) salt-cloud.

CVE-2014-3594
Published: 2014-08-22
Cross-site scripting (XSS) vulnerability in the Host Aggregates interface in OpenStack Dashboard (Horizon) before 2013.2.4, 2014.1 before 2014.1.2, and Juno before Juno-3 allows remote administrators to inject arbitrary web script or HTML via a new host aggregate name.

Best of the Web
Dark Reading Radio
Archived Dark Reading Radio
Three interviews on critical embedded systems and security, recorded at Black Hat 2014 in Las Vegas.