Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Perimeter

2/18/2013
12:59 PM
Gunnar Peterson
Gunnar Peterson
Commentary
50%
50%

RSA: What To Watch For And What Vaccinations To Get Before Rocking The Casbah

Pro tip: It's not threats, it's not capabilities -- it's integration

Spending on security and identity continues to progress and vendors, nothing if not observant, have tried their best to productize the gap between enterprise want and what currently exists. Shopping for rugs in Tangier feels sedate compared to walking the RSA showroom floor.

RSA Conference 2013
Click here for more articles.

This trade show is a necessary part of the industry because as Whit Diffie said, "I understood the importance of cryptography and, in a sense, I understood the scale. I imagined myriad devices encrypting billions of bits communicated among millions of people. What I didn't understand was the business aspect, how many thousands of people had to be hustling to turn a buck to make it happen."

One problem is that all this hustling around a pretty abstract topic like security can create a lot of confusion. I have observed over the years a large number of otherwise sane, pragmatic people who board the plane for SFO and return dazzled by bright and shiny "solutions" that were apparently whispered to them, said behind closed doors or inside a reality distortion field.

So here is the antidote, the vaccination regime before your flight lands at SFO. There is an endless stream of "solutions", each with some ability to foster reasonable doubt that, ceteris paribus, they may lay claim to a marginal security improvement for your company. Here is the part that matters in that sentence for your company.

The focus will, of course, be on the heavy threats they've seen (the whisper part), and their double secret IP (another whisper part best left til we're behind closed doors, or a couple drinks in). These are enough to fool even smart observers, consider Bruce Schneier's time inside the reality distortion field circa 2008:

    Talk to the exhibitors, though, and the most common complaint is that the attendees aren't buying.

    It's not the quality of the wares. The show floor is filled with new security products, new technologies, and new ideas. Many of these are products that will make the attendees' companies more secure in all sorts of different ways. The problem is that most of the people attending the RSA Conference can't understand what the products do or why they should buy them. So they don't.

I think the quality of the wares has a lot to do with it, but leaving that aside, what I think matters much more is not how is any particular product or service, its how good is it for your company. This means integration.

So here is the Pro Tip, before landing at SFO have in mind a checklist of how any product set you are looking at, what are the key questions around process, organizational and technical integration? Sure solution X maybe improves authentication in some way, but what does the API look like, how will my developers work with it, how does it work with my existing web apps' authorization services? What protocols does it use, what type of communications, what endpoints, synchronous or asynchronous, what's the session manager, what identity providers does it work with, what relying parties, what's the token type, what are the failure modes, what security gaps remain? What development or operational processes need to change, what training do my people need, can my people even do this or is it a outsourced only? Question one is for sure on product efficacy and what its trying to solve, but questions two through two hundred should focus on process, organization and technical integration, the steps necessary to realize the efficacy in your company. Gunnar Peterson (@oneraindrop) works on AppSec - Cloud, Mobile and Identity. He maintains a blog at http://1raindrop.typepad.com. View Full Bio

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
10 Ways to Keep a Rogue RasPi From Wrecking Your Network
Curtis Franklin Jr., Senior Editor at Dark Reading,  7/10/2019
The Security of Cloud Applications
Hillel Solow, CTO and Co-founder, Protego,  7/11/2019
Where Businesses Waste Endpoint Security Budgets
Kelly Sheridan, Staff Editor, Dark Reading,  7/15/2019
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Write a Caption, Win a Starbucks Card! Click Here
Latest Comment: "Jim, stop pretending you're drowning in tickets."
Current Issue
Building and Managing an IT Security Operations Program
As cyber threats grow, many organizations are building security operations centers (SOCs) to improve their defenses. In this Tech Digest you will learn tips on how to get the most out of a SOC in your organization - and what to do if you can't afford to build one.
Flash Poll
The State of IT Operations and Cybersecurity Operations
The State of IT Operations and Cybersecurity Operations
Your enterprise's cyber risk may depend upon the relationship between the IT team and the security team. Heres some insight on what's working and what isn't in the data center.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2019-1575
PUBLISHED: 2019-07-16
Information disclosure in PAN-OS 7.1.23 and earlier, PAN-OS 8.0.18 and earlier, PAN-OS 8.1.8-h4 and earlier, and PAN-OS 9.0.2 and earlier may allow for an authenticated user with read-only privileges to extract the API key of the device and/or the username/password from the XML API (in PAN-OS) and p...
CVE-2019-1576
PUBLISHED: 2019-07-16
Command injection in PAN-0S 9.0.2 and earlier may allow an authenticated attacker to gain access to a remote shell in PAN-OS, and potentially run with the escalated user?s permissions.
CVE-2018-19629
PUBLISHED: 2019-07-16
A Denial of Service vulnerability in the ImageNow Server service in Hyland Perceptive Content Server before 7.1.5 allows an attacker to crash the service via a TCP connection.
CVE-2019-10100
PUBLISHED: 2019-07-16
Quake3e < 5ed740d is affected by: Buffer Overflow. The impact is: Possible code execution and denial of service. The component is: Argument string creation.
CVE-2019-10100
PUBLISHED: 2019-07-16
UPX 3.95 is affected by: Integer Overflow. The impact is: attacker can cause a denial of service. The component is: src/p_lx_elf.cpp PackLinuxElf32::PackLinuxElf32help1() Line 262. The attack vector is: the victim must open a specially crafted ELF file.