Posts

Saturday Night Surfing

Cruising around the Web on this fine Saturday night, I found a few sites I thought I would share. One or two you may recognize, but one or two you might not. The first is Uninformed , a technical journal that appears to have picked up the role previously worn by Phrack . By that I mean that defeating security measures is a strong theme. The second is Codebreakers Journal . This technical journal is peer-reviewed, and also features the same sorts of articles found in Uninformed. The final site is the ElseNot Project . The site lists every Microsoft security bulletin since 1 June 1998, and tries to match an exploit for every vulnerability. As of today there are 138 exploits for 464 bulletins listed.

Review of The Debian System, Debian/GNU Linux 3.1 Bible Posted

Image
Amazon.com just posted my five star review of The Debian System . From the review : "I was extremely impressed by Martin Krafft's The Debian System (TDS). I approached this book as a fairly experienced FreeBSD user and an occasional Linux user. (I run Debian on i386 and PA-RISC, but I wanted to know more about Debian as a system.) I strongly recommend TDS for two types of users. The first group includes anyone who wants to get the most out of the unique techniques and tools found in Debian. The second group includes developers and users of other operating systems who are looking for different ways to approach system administration problems. Both groups benefit from TDS' thorough and commanding coverage of Debian and its community." Amazon.com also posted my four star review of Debian GNU/Linux 3.1 Bible . From the review : " Debian GNU/Linux 3.1 Bible (DGL3B) is a good book if your expectations match its content. This can be difficult when the cover bears t...

DoD Directive 8570.1 Changes Everything

Image
Last night I attended my local ISSA-NoVA meeting. I listened to Steven Busch from the Defense-wide Information Assurance Program (DIAP). He is a "Change and Workforce Management Senior Managing Consultant" with IBM working on implementing DoD Directive 8570.1 , "Information Assurance Training, Certification, and Workforce Management", which I mentioned yesterday. He's also a Marine. (Notice I said "Marine," not "ex-Marine." Even though Mr. Busch is no longer in uniform, I recognize there are no "former Marines.") I will try to summarize what I heard, with the expectation that Mr. Busch's slides will be posted at the ISSA-NoVA Web site soon. I managed to get related material from this earlier briefing (.pdf, slow). There's also a summary at (ISC)2 . The vision for 8570.1 is the following: A professional, efficiently managed IA workforce with knowledge and skills to securely configure information technology, effect...

Army Thin Clients

Last month I posted news about the Navy's adoption of real thin client systems on some of their ships. Last year I said the following: "We have the Air Force barking up the wrong tree with new Microsoft purchases. The Navy and Marine Corps are stuck with a disfunctional NMCI. I guess this leaves the Army to embark on a bold strategy that leaves the broken enterprise desktop computing model behind? Stay tuned." It looks like I was right about the Army. This morning I read Army plans to use thin-client systems at FCW . The Army intends to streamline information technology at its bases by using thin-client systems, which do not require a computer at every worker’s desk... The Army intends to install thin-client computers as it restructures and consolidates bases... “The whole Army is behind this,” Winkler [director of the Army’s Governance, Acquisition and Chief Knowledge Office] told industry executives at a conference on BRAC’s impact. The IT Association of America s...

Bejtlich Interview on PaulDotCom

Paul Asadoorian and Larry Pesce from PaulDotCom interviewed me yesterday. The podcast is available as a 30 MB .mp3. Thanks to Paul and Larry for taking the time to speak with me.

IISFA Is Irrelevant

For the past several months, I've been receiving notices from "Marcus Lawson - ISFA" of the International Information Systems Forensics Association . IISFA is the organization that awards the Certified Information Forensics Investigator™ (CIFI) Certification . I initially thought this would be a good certification for the reasons outlined in that post and previous posts linked within it. The emails from IISFA have said the following. Subject: Your International Information Systems Forensics Association membership is past due for renewal. Dear Richard, I have good news and bad news: Bad news: your membership has, or is about to expire to the Information Systems Forensics Association. This means you will no longer be a part of the "Global Voice of Information Forensics;" you will not longer receive "The Information Forensics Journal;" and you will no longer be able to participate in ISFA events; internationally or locally. Good news: You can renew ...

Notes from Airplane Reading

Image
Last week I read several magazines on the way to DoD Cybercrime. Here are a few thoughts on what I read. From the threat and vulnerability definition department, we have the article DHS offers $765M in risk-based grants from Federal Computer Weekly : The Homeland Security Department has made $765 million available in fiscal 2006 for 35 urban areas to guard against terrorist threats, DHS Secretary Michael Chertoff announced today. The Urban Areas Security Initiative (UASI) this year follows a new, risk-based formula that allots funding according to threat, vulnerability and consequence, Chertoff said... In assigning the grants, DHS also for the first time used threat analysis from the intelligence community to look at different kinds of threats, such as transient populations, Chertoff said. Replace the word "consequence" with "cost of replacement" in the second paragraph and you have the common risk equation found in my books and elsewhere. Nice reporting, Michae...