All posts by Davi Ottenheimer

This Day in History: 1863 Quantrill Ambushes, Kills Badger Band

On this day in 1863, two and a half years after the start of the Civil War, hundreds of pro-slavery Confederates led by Captain William Quantrill disguised themselves as Federal soldiers, then ambushed and killed more than 50 Wisconsin men stationed in “Bloody Kansas”.

Amongst the killed were the brigade band’s 11 men. Several of them had been pinioned to the band wagon by swords driven through them while still alive and the wagon then set afire. Among these served in this way were T.L. Davis, of Platteville, and Johnny Fritz a 15-year-old drummer boy; a sword had been driven through his thigh and then into the woodwork of the wagon.

Quantrill’s group was known to not only torture and burn men alive but kill them even after surrender. Quantrill himself had earned a reputation as a liar and spy.

By the end of 1863 his methods were a clear burden to the Confederate Army, which had to assign soldiers to protect civilians from his men. He eventually was arrested in Texas by a Confederate General in early 1864 on charges of ordering the murder of an officer.

Civilians were accosted, homes were broken into, church steeples were shot up, and a Confederate recruiting officer, Major George N. Butts, was found shot to death on the side of a road. “They regard the life of a man less than you would that of a sheep-killing dog,” said [General] McCulloch. “I regard them but one shade better than highwaymen.” In Sherman, drunken guerrillas rode their horses into a hotel lobby and shot out the gaslights.

Quantrill easily escaped arrest by McCulloch and then tried to continue his style of guerrilla raids, leading men like Jesse James on campaigns North and East of Texas. He was shot in 1865, as he claimed he wanted to march on the US President, and died while in a hospital.

“Nobody Expects Volvo to Sell Many”

The title of this post comes from a quote on Plugincars.com.

The analyst says no one expects Volvo to sell many plug-in electric-diesel hybrid cars despite a 117mpg rating (I’ve read claims of 149mpg elsewhere) and 30 mile range on the electric motor. The US$70K might be the problem, but the site also points out it’s less expensive than a Lexus. And the Lexus engineers only offer 40mpg with their hybrid!

T3 offers the following conclusion:

The V60 is every bit the luxury car and despite government grants beyond most budgets, but with exceptional energy savings, zero road tax, congestion charge and reduced fuel costs it should be a no-brainer for company car drivers who want power and their bosses who crave efficiency.

An all-wheel-drive, plug-in electric-diesel hybrid full-size luxury car that goes 0-60 in 6 seconds yet stays over 100mpg? Are you kidding me? I’ll take ten.

Dear Volvo, I would buy one and I know many others who would too…just tell me, what will it take for us to get it in America?

Green V60

Partying With Security Instead of Compliance

DarkReading has posted the following analysis of the difference between security and compliance. I can’t tell if it’s meant to be a joke. It reads a bit like something you might find in The Onion.

I’ll say it. “Security is exciting.” Security is where the fighting with the bad guys takes place. It is where spies (malware) operate, attacks take place (denial of service, breaches), and the kingdom is heroically defended (firewalls, access control, passwords).

The information princess is protected by the secret service agents of the business kingdom. Just like a cool video game, the security teams have new battles to face each day, filled with new technology threats, clever enemies, and often, lots of caffeine.

Meanwhile, most would say that compliance is boring. It is administrative in nature: Meet the requirements on a checklist, convince people to follow rules that don’t interest them and create more work for them, prepare for exams (audits), and try to make everyone generally behave. Compliance is the uptight adult that tells security their party is making a big mess and disturbing everyone else in the house.

Here is the giant gaping hole in the analysis: compliance is an extension of security. It is not an either-or dichotomy.

The Dark Reading analogy to me reads like being a loner at a party who thinks he is cooler than everyone else is far more fun than being a socialite that everyone gets along with. It sounds backwards because it is. The better analysis is that after you decide how cool you are you have the option to convince others of the same. Of course if you can have fun on your own…go ahead, but don’t call it a party.

Security is an isolated, singular, view of controls whereas compliance is a group, shared, view of the same controls.

For example, if you think disabling grauitous ARP is absolutely critical to protecting your network and you are master and commander of your network then you go right ahead and disable it and pat yourself on the back. Self high-five. Was that exciting for you? Now try walking into a global enterprise. Do you think you are going to convince every network and system admin, their managers, not to mention product vendors, that you are going to disable the beloved ARPs? Talk about a party.

Some might want to call the isolated view of the dictator more fun because they are unprepared or willing to put themselves up against any real economic and social/political challenges.

If you are thrilled to meet with experts across many lines of business, listen carefully to their unique requirements and logic, and work together with them on finding the best security fit/solutions to help them fight against bad guys, then compliance will excite you. In other words, if you enjoy taking the theoretical and making it practical, security becomes far more exciting when it becomes compliance. Unfortunately some devolve compliance into checklists, but that’s bad compliance. Hey, there’s bad security too.

Compliance is security applied.