John Pescatore

A member of the Gartner Blog Network

Archives for August, 2009


Post Vacation Attention Deficit Disorder – Security Tidbit Time

by John Pescatore  |  August 31, 2009  |  Submit a Comment

A week off always causes me to assume the merry-go-round will have slowed down while I was away, but noooooooo – I’ve spend the first 3 hours today just digging out from under email and administrivia. So, for today just some short comments on events that I didn’t delete as I shoveled email into the [...]

Submit a Comment »

Category: Uncategorized     Tags:

NAC is a Knack

by John Pescatore  |  August 21, 2009  |  7 Comments

From Merriam-Webster: Main Entry: knack Pronunciation: \ˈnak\ Function: noun Etymology: Middle English knak Date: 14th century 1 a : a clever trick or stratagem b : a clever way of doing something 2 : a special ready capacity that is hard to analyze or teach 3 archaic : an ingenious device; broadly : toy, knickknack synonyms see gift Back in 2003, Gartner [...]

7 Comments »

Category: Uncategorized     Tags:

Thanks for Thursday: Hats Off to the FTC

by John Pescatore  |  August 20, 2009  |  Submit a Comment

I love the FTC. It is an independent agency founded way back in 1914. It seems like regardless of who is president or what the state of the economy is, the FTC stays focused on its mission of consumer protection. The FTC doesn’t seem to need new laws or more money, it just keeps fighting [...]

Submit a Comment »

Category: Uncategorized     Tags:

What Does The College Class of 2013 Think About Security?

by John Pescatore  |  August 19, 2009  |  2 Comments

It is just about time for high school seniors and returning college students to pack up and head off to college. Every year Beloit College puts out a “mindset list” that documents what they call the “cultural touchstones” of the incoming freshman class. It basically lays out what common experiences the current crop of 18 [...]

2 Comments »

Category: Uncategorized     Tags:

Twelve Word Tuesday: Isn’t It Nice When the Grocery Store Removes the Rotten Bananas Before They Try to Sell Them to You?

by John Pescatore  |  August 18, 2009  |  1 Comment

Choose ISPs, search engines, browsers that block (or adequately differentiate) bad stuff.

1 Comment »

Category: Uncategorized     Tags:

Taking a Leap

by John Pescatore  |  August 17, 2009  |  2 Comments

I’m participating this week in the National Cyber Leap Year Summit, run by The White House Office of Science and Technology Policy (OSTP) and the agencies of the Federal Networking and Information Technology Research and Development (NITRD) Program. Good concept, hard to execute on – but if no one charges the hill periodically, you never get [...]

2 Comments »

Category: Uncategorized     Tags:

Is Security an Enabler or an Obstacle to Happy Customers?

by John Pescatore  |  August 14, 2009  |  1 Comment

Two interesting security/privacy related news bits this week: Researchers at UC Berkeley reported that Quancast, one of the biggest traffic measuring and online tracking firms, was using Flash cookies to track users even after the users had deleted browser cookies. Once outed, Quancast claimed to stop this practice. Palm was outed for the Palm Pre [...]

1 Comment »

Category: Uncategorized     Tags:

On The Internet, No One Knows If You Are Really Just a Dozen Lines of Code

by John Pescatore  |  August 13, 2009  |  Submit a Comment

I do a lot of calls with Gartner clients on the various aspects of protecting their corporate Internet-exposed web servers. Web server security is a tough problem – web servers are like the parking lots outside of sports stadiums. You basically have to let everyone in, let them tailgate (party) and have a good time [...]

Submit a Comment »

Category: Uncategorized     Tags:

A Token Effort Might Be The Right Approach

by John Pescatore  |  August 12, 2009  |  1 Comment

Avivah Litan and I just published a research note “Using Tokenization to Reduce PCI Compliance Requirements.” Tokenization does not replace encryption, but in many scenarios it can help reduce the number of places that card data (or any other type of sensitive data) is stored – which is invariably a good thing. However, tokenization is [...]

1 Comment »

Category: Uncategorized     Tags:

Does Private Cloud Equal Secure Cloud?

by John Pescatore  |  August 10, 2009  |  3 Comments

I’m continually having conversations with Gartner clients along the line of “We are getting pressure to use cloud computing services, what are the security issues?” As I mentioned here, 90% of the time it turns out the pressure is really to consume some application as a service, not really cloud computing. 9.9% of the remaining [...]

3 Comments »

Category: Uncategorized     Tags: