Perimeter
2/18/2013
12:59 PM
Gunnar Peterson
Gunnar Peterson
Commentary
50%
50%

RSA: What To Watch For And What Vaccinations To Get Before Rocking The Casbah

Pro tip: It's not threats, it's not capabilities -- it's integration

Spending on security and identity continues to progress and vendors, nothing if not observant, have tried their best to productize the gap between enterprise want and what currently exists. Shopping for rugs in Tangier feels sedate compared to walking the RSA showroom floor.

RSA Conference 2013
Click here for more articles.

This trade show is a necessary part of the industry because as Whit Diffie said, "I understood the importance of cryptography and, in a sense, I understood the scale. I imagined myriad devices encrypting billions of bits communicated among millions of people. What I didn't understand was the business aspect, how many thousands of people had to be hustling to turn a buck to make it happen."

One problem is that all this hustling around a pretty abstract topic like security can create a lot of confusion. I have observed over the years a large number of otherwise sane, pragmatic people who board the plane for SFO and return dazzled by bright and shiny "solutions" that were apparently whispered to them, said behind closed doors or inside a reality distortion field.

So here is the antidote, the vaccination regime before your flight lands at SFO. There is an endless stream of "solutions", each with some ability to foster reasonable doubt that, ceteris paribus, they may lay claim to a marginal security improvement for your company. Here is the part that matters in that sentence for your company.

The focus will, of course, be on the heavy threats they've seen (the whisper part), and their double secret IP (another whisper part best left til we're behind closed doors, or a couple drinks in). These are enough to fool even smart observers, consider Bruce Schneier's time inside the reality distortion field circa 2008:

    Talk to the exhibitors, though, and the most common complaint is that the attendees aren't buying.

    It's not the quality of the wares. The show floor is filled with new security products, new technologies, and new ideas. Many of these are products that will make the attendees' companies more secure in all sorts of different ways. The problem is that most of the people attending the RSA Conference can't understand what the products do or why they should buy them. So they don't.

I think the quality of the wares has a lot to do with it, but leaving that aside, what I think matters much more is not how is any particular product or service, its how good is it for your company. This means integration.

So here is the Pro Tip, before landing at SFO have in mind a checklist of how any product set you are looking at, what are the key questions around process, organizational and technical integration? Sure solution X maybe improves authentication in some way, but what does the API look like, how will my developers work with it, how does it work with my existing web apps' authorization services? What protocols does it use, what type of communications, what endpoints, synchronous or asynchronous, what's the session manager, what identity providers does it work with, what relying parties, what's the token type, what are the failure modes, what security gaps remain? What development or operational processes need to change, what training do my people need, can my people even do this or is it a outsourced only? Question one is for sure on product efficacy and what its trying to solve, but questions two through two hundred should focus on process, organization and technical integration, the steps necessary to realize the efficacy in your company. Gunnar Peterson (@oneraindrop) works on AppSec - Cloud, Mobile and Identity. He maintains a blog at http://1raindrop.typepad.com. View Full Bio

Comment  | 
Print  | 
More Insights
Register for Dark Reading Newsletters
White Papers
Cartoon
Current Issue
Dark Reading Tech Digest, Dec. 19, 2014
Software-defined networking can be a net plus for security. The key: Work with the network team to implement gradually, test as you go, and take the opportunity to overhaul your security strategy.
Flash Poll
Title Partner’s Role in Perimeter Security
Title Partner’s Role in Perimeter Security
Considering how prevalent third-party attacks are, we need to ask hard questions about how partners and suppliers are safeguarding systems and data.
Video
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2014-9676
Published: 2015-02-27
The seg_write_packet function in libavformat/segment.c in ffmpeg 2.1.4 and earlier does not free the correct memory location, which allows remote attackers to cause a denial of service ("invalid memory handler") and possibly execute arbitrary code via a crafted video that triggers a use after free.

CVE-2014-9682
Published: 2015-02-27
The dns-sync module before 0.1.1 for node.js allows context-dependent attackers to execute arbitrary commands via shell metacharacters in the first argument to the resolve API function.

CVE-2015-0655
Published: 2015-02-27
Cross-site scripting (XSS) vulnerability in Unified Web Interaction Manager in Cisco Unified Web and E-Mail Interaction Manager allows remote attackers to inject arbitrary web script or HTML via vectors related to a POST request, aka Bug ID CSCus74184.

CVE-2015-0884
Published: 2015-02-27
Unquoted Windows search path vulnerability in Toshiba Bluetooth Stack for Windows before 9.10.32(T) and Service Station before 2.2.14 allows local users to gain privileges via a Trojan horse application with a name composed of an initial substring of a path that contains a space character.

CVE-2015-0885
Published: 2015-02-27
checkpw 1.02 and earlier allows remote attackers to cause a denial of service (infinite loop) via a -- (dash dash) in a username.

Dark Reading Radio
Archived Dark Reading Radio
How can security professionals better engage with their peers, both in person and online? In this Dark Reading Radio show, we will talk to leaders at some of the security industry’s professional organizations about how security pros can get more involved – with their colleagues in the same industry, with their peers in other industries, and with the IT security community as a whole.