Category Archives: Security

Press Pass to RSA

Many years ago a friend who is well respected within the security community told me he was going to RSA on a press pass. “It’s free, easy and I don’t really like the conference” he explained as I asked why he did not just register to be a speaker as usual.

I suspected that he was getting some sort of weird satisfaction from getting free access through a legitimate channel, like a soft hack. Perhaps he could argue he was actually doing some press work by being so active in the security community, while at the same time no one really considered him a member of the press.

Since I will be presenting at RSA this year, or to be more accurate “leading” a peer-to-peer session, I get a full conference pass for free. But the thought did cross my mind to use the “FOR PRESS” method…

BTW, this is not just a phenomenon for RSA but any conference you might be interested in attending. The bar to prove press credentials is not terribly high:

Press credentials are restricted to press and industry research analysts who provide a business card with an editorial title, a current masthead that includes their name and a sample of a bylined article or industry-related report published within the past six months. Bloggers are subject to the same press registration process as all other media, and registration will be judged based the credibility of the blog. Information such as the focus of the blog, the longevity of the blog, frequency of updates, Technorati ratings and number of page views will be taken into consideration.

Or maybe it is just high enough?

South Africa Scorpions in Political Row

Managing security sure can be a tricky business. What happens when you have to investigate in places that are sensitive or politically tricky? There is no perfect answer. Consider the situation of a South African group called the Scorpions that was created in 1999 and charged with fighting organized crime and corruption:

Earlier this month, a court provisionally charged the former police chief with corruption, accepting bribes worth 1.2m rand ($160,000, £80,000) and defeating the course of justice, after investigations by the Scorpions.

Two problems jump out here:

  1. The group is relatively new, so their political support base will not be strong. People may not even know how much strength or legitimacy they have in their message
  2. They are old enough to be past their “honeymoon” period and on their own in terms of building credibility and independence

Combine those two and you end up with a tricky situation, especially when they are going after a former police chief.

South Africa’s security minister has tabled a proposal in parliament calling for the FBI-style Scorpions special investigations unit to be disbanded.

This row over the right level of independence needed for security investigations will be an interesting one to watch.

Availability Heuristics

The BBC has a hilarious article called “How to make better decisions“:

Be warned: this article deals primarily with shark attacks, the lottery, beer, and how to get a date using mathematics. Is it a good decision to keep reading? Unfortunately, the answer is “you need to keep reading to find out.”

Sound irrational? Good – your massively irrational mind should have no problem with it, then.

Consider this: every year in the United States, when the Discovery Channel broadcasts “Shark Week” visits to Florida beaches decline. Presumably, the network’s programming makes the waters no less safe (assuming sharks are not, in fact, empowered by cable television).

It could also be that they show the program during a week that people are more likely to be home to watch, as there are no holidays. Need more data, really.

Imagine I handed you a cup of hot coffee and then asked your opinion about a person whom you had recently met; now suppose I instead handed you a cup of ice-cold soda. Experiments show that your opinion of this person would be different because you have been primed to feel warmth or coldness.

Add to the list…

* framing (how you present data is as important as the data itself)
* impact bias (overestimation of possible outcomes),
* confirmation bias (recognising only data that supports your hypothesis)
* loss aversion (we stand to gain more than we would lose, but our fear of loss prevents us)
* selective perception (seeing what you want to see),and
* rosy retrospection (integral to the repeated experience of family Christmas)

…and you seem doomed to blunder through life led by your brain’s clumsy irrationality.

Maybe I’m thinking about this the wrong way, but cultural influence is not listed? No peer pressure? No bias from overconfidence in science, especially mathematical formulas? Excellent food for thought when it comes to understanding the wily hacker.

Subaru Announces Diesel Engine

Amazing. I was excited to hear about the Audi TDI coming to the US, but now I see Subaru is planning a European diesel. I love the boxer engine in the Subaru, as well as their all wheel drive. I suspect this new diesel will have incredible efficiency:

Subaru will use next month’s Geneva motor show to debut its new diesel boxer engine in the Legacy and Outback models. The engine marks the first diesel application for a horizontally opposed engine.

The engine’s rigidity enabled Subaru to shorten it by more than two inches compared with the gasoline version. The diesel 2.0-liter turbocharged H4 produces 147 hp and 258 lb-ft of torque.

Ok, the really amazing thing here is that Subaru’s top-of-the-line Impreza gasoline engine in 2008 produces a Japanese record-setting 304 hp at 6,400 rpm and 311 pound-feet of torque at 4,400 rpm. So their new basic diesel model for daily drivers will produce nearly the same torque as the hottest rally-car on the market (surely at lower rpm), while probably delivering twice the mpg.

Hello, Subaru. Import please.