<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>John Pescatore &#187; Uncategorized</title>
	<atom:link href="http://blogs.gartner.com/john_pescatore/category/uncategorized/feed/" rel="self" type="application/rss+xml" />
	<link>http://blogs.gartner.com/john_pescatore</link>
	<description>A member of the Gartner Blog Network</description>
	<lastBuildDate>Fri, 20 Nov 2009 11:28:05 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.8.4</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>Friday Filler: If The Sun Rose in the East, You Had a Cyber-Attack Today</title>
		<link>http://blogs.gartner.com/john_pescatore/2009/11/20/friday-filler-if-the-sun-rose-in-the-east-you-had-a-cyber-attack-today/</link>
		<comments>http://blogs.gartner.com/john_pescatore/2009/11/20/friday-filler-if-the-sun-rose-in-the-east-you-had-a-cyber-attack-today/#comments</comments>
		<pubDate>Fri, 20 Nov 2009 11:24:43 +0000</pubDate>
		<dc:creator>John Pescatore</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://blogs.gartner.com/john_pescatore/?p=957</guid>
		<description><![CDATA[For some reason, the SANS Newsbites didn&#8217;t use my comments on the item below, so here it is to fill the Friday blog:
US Government Agencies Say Incidents Are a Daily Occurrence (November 10 &#38; 11, 2009) 
A CDW-Government survey of 300 US government IT professionals found that 44 percent of agencies noted an increase in [...]]]></description>
			<content:encoded><![CDATA[<p><em>For some reason, the SANS Newsbites didn&#8217;t use my comments on the item below, so here it is to fill the Friday blog:</em></p>
<blockquote><p><em><span style="font-style: normal">US Government Agencies Say Incidents Are a Daily Occurrence (November 10 &amp; 11, 2009) </span></em></p></blockquote>
<blockquote><p><em><span style="font-style: normal">A CDW-Government survey of 300 US government IT professionals found that 44 percent of agencies noted an increase in the number of security incidents over last year.  Thirty-one percent of respondents said their agencies experienced at least one cyber security incident every day.  The top areas of concern reported by respondents were malware, inappropriate employee activity or network use, managing access for approved remote users, and data encryption.</span></em></p></blockquote>
<p><em><span style="font-style: normal"><strong>Pescatore</strong> &#8211; I&#8217;m really worried about the 69% who *don&#8217;t* think they are having daily security incidents. Basically, a day without a security incidents is a day without any Internet connectivity and with no human beings using any computers that have any software running on them.</span></em></p>
]]></content:encoded>
			<wfw:commentRss>http://blogs.gartner.com/john_pescatore/2009/11/20/friday-filler-if-the-sun-rose-in-the-east-you-had-a-cyber-attack-today/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Is Apple an &#8220;Enterprise-class Vendor&#8221; From a Security Perspective? Nah</title>
		<link>http://blogs.gartner.com/john_pescatore/2009/11/19/is-apple-an-enterprise-class-vendor-from-a-security-perspective-nah/</link>
		<comments>http://blogs.gartner.com/john_pescatore/2009/11/19/is-apple-an-enterprise-class-vendor-from-a-security-perspective-nah/#comments</comments>
		<pubDate>Thu, 19 Nov 2009 11:56:00 +0000</pubDate>
		<dc:creator>John Pescatore</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://blogs.gartner.com/john_pescatore/?p=953</guid>
		<description><![CDATA[This week&#8217;s Twelve Word Tuesday was about all those holiday season presents showing up on your network when everyone comes back to work on January 5th.  Apple is one of the major vendors of those &#8220;toys&#8221; and last week colleague Nick Jones asked for input on this question: &#8220;Is Apple an Enterprise-class Vendor?&#8221; At Gartner&#8217;s [...]]]></description>
			<content:encoded><![CDATA[<p>This week&#8217;s <a href="http://blogs.gartner.com/john_pescatore/2009/11/17/twelve-word-tuesday-only-50-days-until-all-those-christmas-presents-show-up-on-your-network/" target="_blank">Twelve Word Tuesday</a> was about all those holiday season presents showing up on your network when everyone comes back to work on January 5th.  Apple is one of the major vendors of those &#8220;toys&#8221; and last week colleague Nick Jones asked for input on this question: &#8220;Is Apple an Enterprise-class Vendor?&#8221; At Gartner&#8217;s Asia Pacific Symposium this week, Nick debated another Gartner analyst (Robin Simpson) on this topic, and Nick blogged about it <a href="http://blogs.gartner.com/nick_jones/2009/11/18/is-apple-an-enterprise-vendor/" target="_blank">here</a>.</p>
<p>Here is the response I sent Nick from the security perspective:</p>
<blockquote><p>On the iPhone side, the  fact that there is no actually supported management app and that any user can  change any policy setting pretty much says it all.</p>
<p>Pretty much the same  thing on the Mac side, plus patching issues – Apple  vulnerabilities go unpatched for long periods of time, patches come out with any  warning or much information at all.</p>
<p>Years ago I did a Research Note on  how to quickly judge how serious a vendor was about enterprise security, and I  graded lots of vendors. The easy test: go to <a title="http://www.vendorname.com/security" href="http://www.vendorname.com/security">www.vendorname.com/security</a> and  see what you find. Vendors fall into 3 categories:</p>
<ol>
<li><strong>They get it</strong> &#8211; /security has good  security info, an easy place to report bugs, etc.</li>
<li><strong>They don’t really get it, but they  are in the enterprise business</strong> &#8211; /security tries to sell you on how secure they  are, vs. help you stay secure.</li>
<li><strong>Consumer-grade compan</strong><strong>y</strong> – you get  error 404 or equivalent</li>
</ol>
<p>Check out <a title="http://www.apple.com/security" href="http://www.apple.com/security">www.apple.com/security</a> and you find  they are clearly type 3 – nice picture of a snow leopard  though…</p></blockquote>
<p>Take a look and compare <a href="http://www.apple.com/security" target="_blank">Apple</a>, <a href="http://www.google.com/security" target="_blank">Google</a>, <a href="http://www.nintendo.com/security" target="_blank">Nintendo</a>, <a href="http://www.microsoft.com/security" target="_blank">Microsoft</a>, <a href="http://www.cisco.com/security" target="_blank">Cisco</a>, <a href="http://www.oracle.com/security" target="_blank">Oracle</a>, <a href="http://www.juniper.net/security/" target="_blank">Juniper</a>, <a href="http://www.nintendo.com/security" target="_blank">Nintendo</a>, etc. and you see the differences and similarities between consumer-oriented vendors and enterprise oriented vendors &#8211; and which enterprise-oriented vendors &#8220;get&#8221; security.</p>
<p>This litmus test doesn&#8217;t really work for security vendors &#8211; some of them (like Symantec) make good use of the /security real estate, while for some reason others (like McAfee and Checkpoint) let it waste away in error 404 land.</p>
]]></content:encoded>
			<wfw:commentRss>http://blogs.gartner.com/john_pescatore/2009/11/19/is-apple-an-enterprise-class-vendor-from-a-security-perspective-nah/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Wednesday Whimsy: Invest in Prevention, or Legislate Away Threats?</title>
		<link>http://blogs.gartner.com/john_pescatore/2009/11/18/wednesday-whimsy-invest-in-prevention-or-legislate-away-threatsy/</link>
		<comments>http://blogs.gartner.com/john_pescatore/2009/11/18/wednesday-whimsy-invest-in-prevention-or-legislate-away-threatsy/#comments</comments>
		<pubDate>Wed, 18 Nov 2009 12:53:20 +0000</pubDate>
		<dc:creator>John Pescatore</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://blogs.gartner.com/john_pescatore/?p=948</guid>
		<description><![CDATA[Back in 2007, I nominated Fireeye as a Gartner &#8220;Cool Vendor&#8221; since I&#8217;m constantly looking for vendors doing interesting things to deal with the &#8220;arbitrary malware&#8221; problem &#8211; developing wire-speed techniques to determine if in-bound executables are malicious or not.
Today there is an announcement that In-Q-Tel (IQT,) the CIA&#8217;s &#8220;venture capital&#8221; organization, has invested in Fireeye:
“FireEye [...]]]></description>
			<content:encoded><![CDATA[<p>Back in 2007, I nominated Fireeye as a Gartner &#8220;<a href="http://my.gartner.com/resources/146300/146381/cool_vendors_in_infrastructu_146381.pdf?h=0BF242BE928453596EFFAC3D0A4D948C23A650C8" target="_blank">Cool Vendor</a>&#8221; since I&#8217;m constantly looking for vendors doing interesting things to deal with the &#8220;arbitrary malware&#8221; problem &#8211; developing wire-speed techniques to determine if in-bound executables are malicious or not.</p>
<p>Today there is an announcement that <a href="http://www.iqt.org/" target="_blank">In-Q-Tel</a> (IQT,) the CIA&#8217;s &#8220;venture capital&#8221; organization, has invested in Fireeye:</p>
<blockquote><p>“FireEye is a critical addition to our strategic investment portfolio for security technologies,” said T.J. Rylander, a Partner at IQT. “FireEye offers a valuable combination of next-generation malware protection, and its approach to detecting and defeating malware is unique and potentially game changing.”</p></blockquote>
<p>This is no guarantee of success &#8211; the vast majority of In-Q-Tel&#8217;s investments do not break through to the commercial side &#8211; but it is nice to see the US Government making more investment in techniques to deal with current and next generation threats.</p>
<p>Contrast that with another government announcement this week in this AP <a href="http://www.msnbc.msn.com/id/34001958/ns/technology_and_science-security/" target="_blank">piece</a>:</p>
<blockquote><p>WASHINGTON &#8211; Stung by an embarrassing electronic leak last month revealing ethics investigations into dozens of lawmakers, Congress moved Tuesday to prohibit federal employees from using the same type of Internet file-sharing software blamed for the disclosure.</p></blockquote>
<p>Oy &#8211; I knew this was coming, as I <a href="http://blogs.gartner.com/john_pescatore/2009/11/02/the-security-risks-of-consumerization-hit-home-for-us-congress/" target="_blank">blogged</a> back on November 2nd when the sensitive government information leaked out via employees with file sharing software installed:</p>
<blockquote><p>Now, the knee-jerk reaction will likely be to try to legislate bans on P2P software but that is dealing with the symptom, not the problem. The problem is that normal users can never keep up with what needs to be done to keep business data secure on their home PCs or on consumer-grade web sites and services. Enterprises have to put security controls in place to monitor, contain and ultimately secure the use of all business information, whether in the data center, on a managed PC or on a home PC.</p></blockquote>
<p>This &#8220;let&#8217;s legislate the problem away&#8221; approach never works. The users violated security policy and they will break laws, too. Some of it is as simple as speed limits don&#8217;t stop speeding, radar traps and traffic cameras do. But, the other issue is threats continually evolve and users can not be expected to keep up &#8211; let alone will legislators or legislation ever keep up. Remember back in 2001 when some politicians wanted to make buffer overflows illegal?</p>
<p>The government investing in using advanced forms of protection is a much better use of tax dollars than more legislation.</p>
]]></content:encoded>
			<wfw:commentRss>http://blogs.gartner.com/john_pescatore/2009/11/18/wednesday-whimsy-invest-in-prevention-or-legislate-away-threatsy/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Twelve Word Tuesday: Only 50 Days Until All Those Christmas Presents Show Up On Your Network</title>
		<link>http://blogs.gartner.com/john_pescatore/2009/11/17/twelve-word-tuesday-only-50-days-until-all-those-christmas-presents-show-up-on-your-network/</link>
		<comments>http://blogs.gartner.com/john_pescatore/2009/11/17/twelve-word-tuesday-only-50-days-until-all-those-christmas-presents-show-up-on-your-network/#comments</comments>
		<pubDate>Tue, 17 Nov 2009 13:22:52 +0000</pubDate>
		<dc:creator>John Pescatore</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://blogs.gartner.com/john_pescatore/?p=946</guid>
		<description><![CDATA[How will you secure those iPhone and Android stocking stuffers on 1/5/2010?
]]></description>
			<content:encoded><![CDATA[<p>How will you secure those iPhone and Android stocking stuffers on 1/5/2010?</p>
]]></content:encoded>
			<wfw:commentRss>http://blogs.gartner.com/john_pescatore/2009/11/17/twelve-word-tuesday-only-50-days-until-all-those-christmas-presents-show-up-on-your-network/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>Friday Follies: A Busy Week for Hacking of Consumer-Grade Social Networks</title>
		<link>http://blogs.gartner.com/john_pescatore/2009/11/13/friday-follies-a-busy-week-for-hacking-of-consumer-grade-social-networks/</link>
		<comments>http://blogs.gartner.com/john_pescatore/2009/11/13/friday-follies-a-busy-week-for-hacking-of-consumer-grade-social-networks/#comments</comments>
		<pubDate>Fri, 13 Nov 2009 13:37:07 +0000</pubDate>
		<dc:creator>John Pescatore</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://blogs.gartner.com/john_pescatore/?p=943</guid>
		<description><![CDATA[MSNBC has a piece on a &#8220;vigilante&#8221; hijacking a number of Facebook group sites. Facebook&#8217;s statement helpfully pointed out &#8220;We are still investigating this situation, but an extremely small number of groups have been affected.&#8221; Sort of like a doctor saying &#8220;I haven&#8217;t really finished checking, but at first glance the tumor I did find [...]]]></description>
			<content:encoded><![CDATA[<p>MSNBC has a <a href="http://www.msnbc.msn.com/id/33838186/ns/technology_and_science-security/" target="_blank">piece </a>on a &#8220;vigilante&#8221; hijacking a number of Facebook group sites. Facebook&#8217;s statement helpfully pointed out &#8220;<em>We are still investigating this situation, but an extremely small number of groups have been affected.&#8221; </em>Sort of like a doctor saying &#8220;I haven&#8217;t really finished checking, but at first glance the tumor I did find is pretty tiny.&#8221;</p>
<p>MSNBC must be ramping up their security coverage &#8211; they had another <a href="http://www.msnbc.msn.com/id/33835046/ns/technology_and_science-security/" target="_blank">item</a> on attacks on Twitter sending bogus Direct Messages (private messages between Twitterers) in phishing attacks. MSNBC quotes Twitter&#8217;s spokeperson as helpfully pointing out:</p>
<blockquote><p>Twitter also suggested users who may have gotten the fake Direct Messages to <a href="http://twitter.com/account/password">change their log-ins and passwords</a> to prevent unauthorized use of their accounts. Users &#8220;should &#8220;feel free&#8221; to change their passwords if they are worried,&#8221; the company said.</p></blockquote>
<p>That is sort of like the bank saying &#8220;Users should &#8220;feel free&#8221; to use a different ATM machine if the one you were using gave your money to someone else.&#8221;</p>
<p>NetworkWorld weighed in with <a href="http://www.networkworld.com/news/2009/111209-facebook-tips-staying-safe-while.html" target="_blank">guidance </a>for Facebook users about steps they should take to be safe from &#8220;scammy&#8221; games that are popular on Facebook. Playing games on Facebook pretty means you agree to give the game company full access to your profile &#8211; but even if you <strong>don&#8217;t </strong>play the game, if friends have access to your profile when <strong>they</strong> play it turns out often they are giving away access to <strong>your </strong>profile info.  The piece points out that Facebooks &#8220;privacy&#8221; policies are &#8220;ever-changing,&#8221; like most consumer-grade sites, so users need to constantly check and keep up with changes.</p>
<p>This is sort of the like if the cellphone companies occasionally decided that if someone in your speed dial list signed up for direct marketing calls, then your phone number would be given to the phone scammers, too.</p>
<p>Looks like responsible users have to be pretty busy keeping themselves safe out there. Sort of like if on an airplane all the passengers had keep looking out the window to avoid other planes, and also remember to lower the landing gear&#8230;</p>
]]></content:encoded>
			<wfw:commentRss>http://blogs.gartner.com/john_pescatore/2009/11/13/friday-follies-a-busy-week-for-hacking-of-consumer-grade-social-networks/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Addressing Credit Card Vulnerabilities</title>
		<link>http://blogs.gartner.com/john_pescatore/2009/11/11/addressing-credit-card-vulnerabilities/</link>
		<comments>http://blogs.gartner.com/john_pescatore/2009/11/11/addressing-credit-card-vulnerabilities/#comments</comments>
		<pubDate>Wed, 11 Nov 2009 13:52:17 +0000</pubDate>
		<dc:creator>John Pescatore</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://blogs.gartner.com/john_pescatore/?p=940</guid>
		<description><![CDATA[I commented here yesterday, and in this weeks SANS NewsBites, about the overhype in Sunday&#8217;s 60 Minutes piece on cybersecurity.  One thing that was mentioned was &#8220;white card fraud,&#8221; where card data stolen on line is put on blank credit, debit or ATM cards and waves of &#8220;card present&#8221; fraud happens. Nothing new &#8211; I [...]]]></description>
			<content:encoded><![CDATA[<p>I commented here <a href="http://blogs.gartner.com/john_pescatore/2009/11/10/twelve-word-tuesday-60-minutes-mike-mcconnell-and-the-fbi-say-the-world-has-already-ended/" target="_blank">yesterday</a>, and in this weeks SANS <a href="http://www.sans.org/newsletters/newsbites/newsbites.php?vol=11&amp;issue=89#sID300" target="_blank">NewsBites</a>, about the overhype in Sunday&#8217;s 60 Minutes piece on cybersecurity.  One thing that was mentioned was &#8220;white card fraud,&#8221; where card data stolen on line is put on blank credit, debit or ATM cards and waves of &#8220;card present&#8221; fraud happens. Nothing new &#8211; I think MSNBC had a piece on this in 2006.  But, this is one of the ways that cybercrime makes its &#8220;revenue,&#8221; and raises the question: why is it so easy to counterfeit cards?</p>
<p>There are various approaches to making it harder. Chip and pin cards raise the bar but they make the cards more expensive. Techniques like Magtek&#8217;s Magneprint work with low cost magnetic stripe cards but require their technology in the card readers, and require card issuers to alter their registration process a bit &#8211; but nothing all that complicated.</p>
<p>The biggest obstacle is the odd multi-party relationship between card issues, acquirers, merchants and card brands &#8211; nothing moves quickly in the credit card industry if it might in anyway impact transaction growth. Seems like merchants lose out the most in this area &#8211; consumers have lots of legal protections and the banks and card brands make the rules. Making &#8220;white card fraud&#8221; harder would certainly be a good thing but seems like it doesn&#8217;t have enough benefit for those who make the rules vs. those who have to live by them.</p>
]]></content:encoded>
			<wfw:commentRss>http://blogs.gartner.com/john_pescatore/2009/11/11/addressing-credit-card-vulnerabilities/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Twelve Word Tuesday: 60 Minutes, Mike McConnell and the FBI Say The World Has Already Ended</title>
		<link>http://blogs.gartner.com/john_pescatore/2009/11/10/twelve-word-tuesday-60-minutes-mike-mcconnell-and-the-fbi-say-the-world-has-already-ended/</link>
		<comments>http://blogs.gartner.com/john_pescatore/2009/11/10/twelve-word-tuesday-60-minutes-mike-mcconnell-and-the-fbi-say-the-world-has-already-ended/#comments</comments>
		<pubDate>Tue, 10 Nov 2009 12:56:01 +0000</pubDate>
		<dc:creator>John Pescatore</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://blogs.gartner.com/john_pescatore/?p=937</guid>
		<description><![CDATA[For hype, focus on the threat; for security, focus on the vulnerabilities.
(By the way, here&#8217;s an alternate view of the cause of the  Brazilian black-out)
]]></description>
			<content:encoded><![CDATA[<p>For hype, focus on the threat; for security, focus on the vulnerabilities.</p>
<p>(By the way, <a href="http://www.wired.com/threatlevel/2009/11/brazil_blackout/" target="_blank">here&#8217;s</a> an alternate view of the cause of the  Brazilian black-out)</p>
]]></content:encoded>
			<wfw:commentRss>http://blogs.gartner.com/john_pescatore/2009/11/10/twelve-word-tuesday-60-minutes-mike-mcconnell-and-the-fbi-say-the-world-has-already-ended/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Consumer-grade IT: Facebook/MySpace Coding Flaws</title>
		<link>http://blogs.gartner.com/john_pescatore/2009/11/09/consumer-grade-it-facebookmyspace-coding-flaws/</link>
		<comments>http://blogs.gartner.com/john_pescatore/2009/11/09/consumer-grade-it-facebookmyspace-coding-flaws/#comments</comments>
		<pubDate>Mon, 09 Nov 2009 12:50:16 +0000</pubDate>
		<dc:creator>John Pescatore</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://blogs.gartner.com/john_pescatore/?p=935</guid>
		<description><![CDATA[Most of the discussion on &#8220;opening up to social networking&#8221; seems to focus on the simplistic problem of allowing access from work or blocking it. That&#8217;s an easy one &#8211; businesses and government agencies will allow access, generally sooner rather than later. The real issue is what security controls need to be added to make [...]]]></description>
			<content:encoded><![CDATA[<p>Most of the discussion on &#8220;opening up to social networking&#8221; seems to focus on the simplistic problem of allowing access from work or blocking it. That&#8217;s an easy one &#8211; businesses and government agencies will allow access, generally sooner rather than later. The real issue is what security controls need to be added to make sure that use of those sites is safe enough for business use &#8211; because by themselves, they are <strong>not </strong>safe enough for business use.</p>
<p>A piece in <a href="http://www.networkworld.com/news/2009/110509-developer-finds-major-coding-errors.html" target="_blank">NetworkWorld</a> on major cross-site vulnerabilities in Facebook and MySpace points this out.  The business model behind social networking sites is to put ads in front of users and to get high prices for those ads by making sure they are targeted to match users behavior and profiles. There is a built-in incentive to gather information on users and make it available to 3rd parties &#8211; a perfect breeding ground for cross-domain leakage problems.</p>
<p>Now, those sites also have a built-in incentive to have loyal users, so they can&#8217;t completely lose the trust of users. However, growing ad revenue 20% will always trump temporarily slowing user growth because of data exposure incidents &#8211; but if your customer&#8217;s data has been exposed through one of those events, the costs to your business will continue for a long time. Especially if you are relying on the &#8220;we assumed they were responsible users &#8211; we told them not to do that&#8221; approach.</p>
]]></content:encoded>
			<wfw:commentRss>http://blogs.gartner.com/john_pescatore/2009/11/09/consumer-grade-it-facebookmyspace-coding-flaws/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>Is Google Android The Same &#8220;Most Secure Operating System&#8221; That Windows XP Was Supposed to Be?</title>
		<link>http://blogs.gartner.com/john_pescatore/2009/11/04/is-google-android-the-same-most-secure-operating-system-that-windows-xp-was-supposed-to-be/</link>
		<comments>http://blogs.gartner.com/john_pescatore/2009/11/04/is-google-android-the-same-most-secure-operating-system-that-windows-xp-was-supposed-to-be/#comments</comments>
		<pubDate>Wed, 04 Nov 2009 09:53:22 +0000</pubDate>
		<dc:creator>John Pescatore</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://blogs.gartner.com/john_pescatore/?p=932</guid>
		<description><![CDATA[Eweek published a puff piece promoting the security of Google&#8217;s Android operating system that is starting to show up on some mobile phones. It read like a rip and read job from a Google marketing brochure:
1 &#8211; not really valid –  we’ve said open source code gets more secure, more quickly but it is [...]]]></description>
			<content:encoded><![CDATA[<p>Eweek published a <a href="http://www.eweek.com/c/a/Security/10-Reasons-Why-Google-Android-Is-Secure-793289/?kc=EWKNLNAV11032009STR1" target="_blank">puff piece</a> promoting the security of Google&#8217;s Android operating system that is starting to show up on some mobile phones. It read like a rip and read job from a Google marketing brochure:</p>
<p>1 &#8211; not really valid –  we’ve said open source code gets more secure, more quickly but it is the security  focus of the development cycle that determines if code starts out and ends up  more secure.</p>
<p>2 – Running  applications in multiple processes by no means guarantees that “no application  gains critical access to system components”</p>
<p>3 &#8211; Starting from Linux  does not guarantee a more secure OS.</p>
<p>4 – Access restrictions  that somehow guarantee that applications won’t harm the user or touch sensitive  data would be very nice. No evidence that they have actually achieved  this.</p>
<p>5 – Code signing  support, nothing new here, but a good thing.</p>
<p>6 – Total hogwash:  “Google has shown  time and again that it is focused on user security.” Not been true to date  any more than any other software vendor.</p>
<p>7. – More hogwash –  putting the bug reporting email address on your web site is pretty standard for  every software vendor. I did a RN grading IT vendor web sites on this and other  web site security pages over 5 years ago.</p>
<p>8 &#8211;  Sounds like the UAC  feature in Windows Vista, which didn’t exactly prove to be effective, let alone  popular.</p>
<p>9 &#8211; Not building a media  player into the OS is a good thing, but the claims that “One of the most common ways attackers  gain entry to a mobile phone is through audio and video running in a web  browser” is a totally false  strawman.</p>
<p>10 &#8211; “Google gets the  web” is certainly valid, but so was “Microsoft gets the desktop” – Google  certainly does have a good view of web sites and through acquisitions of  security companies like Postini does have a good view of malware running out  there.  However, talking with Gartner clients at our security conference and the recent Symposium I listened to many complaints from unhappy Postini customers  since Google acquired them – it is not clear that Google actually “gets” how to  secure the web.</p>
<p><a href="http://blogs.gartner.com/john_pescatore/2009/11/03/twelve-word-tuesday-openess-good-newness-bad/" target="_blank">Yesterday</a>, I pointed out that <em>&#8220;Transparency plus inspection is the friend of security, freshness not so much.</em>&#8221;  This certainly holds true for Android &#8211; transparency and freshness, yes &#8211; inspection, not so much yet.</p>
]]></content:encoded>
			<wfw:commentRss>http://blogs.gartner.com/john_pescatore/2009/11/04/is-google-android-the-same-most-secure-operating-system-that-windows-xp-was-supposed-to-be/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Twelve Word Tuesday: Openess Good, Newness Bad</title>
		<link>http://blogs.gartner.com/john_pescatore/2009/11/03/twelve-word-tuesday-openess-good-newness-bad/</link>
		<comments>http://blogs.gartner.com/john_pescatore/2009/11/03/twelve-word-tuesday-openess-good-newness-bad/#comments</comments>
		<pubDate>Tue, 03 Nov 2009 13:30:47 +0000</pubDate>
		<dc:creator>John Pescatore</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://blogs.gartner.com/john_pescatore/?p=929</guid>
		<description><![CDATA[Transparency plus inspection is the friend of security, freshness not so much.
]]></description>
			<content:encoded><![CDATA[<p>Transparency plus inspection is the friend of security, freshness not so much.</p>
]]></content:encoded>
			<wfw:commentRss>http://blogs.gartner.com/john_pescatore/2009/11/03/twelve-word-tuesday-openess-good-newness-bad/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
	</channel>
</rss>
