John Pescatore

A member of the Gartner Blog Network

Archives for January, 2011


A Computer Can Play “Jeopardy” But Can’t Keep Users Out of Jeopardy

by John Pescatore  |  January 28, 2011  |  1 Comment

I guess while many of us are at the RSA Conference, we will have to tune in each night to see how IBM’s Watson computer is faring on the Jeopardy TV show. But, you know: I bet 8 out of 10 human Jeopardy winners fall for phishing attacks and use “password” as their password…

1 Comment »

Category: Uncategorized     Tags:

NAC as Maitre d’ or Bouncer?

by John Pescatore  |  January 26, 2011  |  Submit a Comment

The High Assurance Platform program at NSA sees Trusted NAC as a key Trusted Computing technology, especially to detect and mitigate unmanaged endpoints – basically, the guest networking problem many in the commercial world have been dealing with for quite some time. Now, in the commercial world the logo would be more like a maitre [...]

Submit a Comment »

Category: Uncategorized     Tags:

Twelve World Tuesday: Simplified Compliance Hype Cycle

by John Pescatore  |  January 25, 2011  |  Submit a Comment

New Regulation: Security Toy Justification! Soon: Feed Me! Later: Shovel in reports

Submit a Comment »

Category: Uncategorized     Tags:

Does It Matter Whether WikiLeaks is an Active or Passive Publicizer of Other People’s Sensitive Information?

by John Pescatore  |  January 24, 2011  |  Submit a Comment

Network World reports that Tiversa has found sensitive data on peer to peer networks that later on shows up on WikiLeaks. WikiLeaks denies any active role, says all the data it publishes comes from “sources” who send the information to WikiLeaks. This is mostly one of those “inside baseball” kinda things – to the enterprise [...]

Submit a Comment »

Category: Uncategorized     Tags:

If A Toy Breaks in a Work Forest, Will The Toy Vendor Hear a Noise and Fix It?

by John Pescatore  |  January 20, 2011  |  2 Comments

A good piece in Network World by Ellen Messmer points out one of the major risks of consumerization – consumer-facing vendors tend not to take vulnerabilities in their products as seriously as enterprise vendors. Mattel doesn’t rush out patches for the Barbie PC,  Hasbro isn’t concerned about denial of service risks with the Easy-Bake Oven. [...]

2 Comments »

Category: Uncategorized     Tags:

Twelve Word Tuesday: Oracle Patchmageddon Tuesday

by John Pescatore  |  January 18, 2011  |  Submit a Comment

Oracle has  an “Unbreakable” Linux Kernel, 28 other products considerably more fragile. Oracle info here.

Submit a Comment »

Category: Uncategorized     Tags:

Focus on How The Burglar Broke In, Not Where The Burglar Came From

by John Pescatore  |  January 17, 2011  |  Submit a Comment

A piece in the New York Times points to US and Israel as being behind the Stuxnet worm, as a targeted cyber attack against Iran’s nuclear weapon program. Stuxnet exploited many known vulnerabilities, and some day zero vulnerabilities, to deliver a very sophisticated, targeted payload to try and damage industrial machinery used in many power [...]

Submit a Comment »

Category: Uncategorized     Tags:

Watching Wavelengths for Wireless Wikileaks

by John Pescatore  |  January 13, 2011  |  Submit a Comment

From Network World: Police in Taiwan used a set of spectrum analyzers to catch at least three people suspected of cheating on an exam by monitoring them for mobile phone signals, a first case of its type, the equipment maker said on Wednesday. Officers used three FSH4 analyzers specially configured by the German manufacturer Rohde [...]

Submit a Comment »

Category: Uncategorized     Tags:

Security Search Shenanigans – Where is NAC on the Hype Cycle?

by John Pescatore  |  January 12, 2011  |  2 Comments

I once made the mistake of trying to use the Gartner Magic Quadrant metaphor with my kids, along the lines of “the upper right is jobs you love where you earn a lot of money, the lower left is jobs you hate and don’t make any money – that’s why you need to do your [...]

2 Comments »

Category: Uncategorized     Tags:

Twelve Word Tuesday: Raising the Level of Discourse Is Always a Noble Goal

by John Pescatore  |  January 11, 2011  |  1 Comment

One lunatic with semi-automatic weapons emphasizes calling cyber-attacks terror is shameless huckstering.

1 Comment »

Category: Uncategorized     Tags: