I have been trying to get the motivation together to blog about my predictions for 2008 but I'm not finding it. So, I've decided to break it up into smaller pieces and hopefully that will make it easier.
So, looking back...
2007 started with me being very motivated, excited and happy. It was going to be a great year with lots of promise. It ended with me feeling very down, de-motivated and depressed. But I am still optimistic for 2008 which either means I am hard to get down or just really naive. I guess time will tell.
My first prediction for 2008 is that I will be a very different person by this time next year. And I will be sitting in a very different place. If I am not - I will have failed.
I don't like to get too much into the personal aspects of my job but a lot of the energy I put into getting security to move forward has been in vain and I am feeling that I am now wasting my time trying to move forward. I have put myself into "cruise" mode while I work behind the scenes to improve myself and then with a big bang I'll be back.
There were some some really excellent moments in 2007. I think that the most important was when I started my blog. I highly recommend blogger. I also recommend feedburner. Both companies are owned by the big G.
A big thank you goes out to Alan from Still Secure who got me motivated and introduced me to the Security Bloggers Network.
While it helps that I am a member of the network and that drives some views to my blog, it has helped me more to explore and find people on the network. I have been able to populate my RSS feed list from a number of bloggers and I hope to add more. I just need the time.
So, who is honoured to be in my RSS feed?
First up is my brother-from-another-mother - Andy the IT guy. I call him that because he has a very similar job, a wife and two daughters and he has had a very similar career path to me. More importantly, I usually see eye-to-eye with him.
Next up is "Security Mike" - Mike Rothman. The daily incite is an amazing tool to get an idea of what is happening in the security blog world. How Mike can read so much still amazes me. One day I'll have saved up enough. The new Audio is also worthwhile.
Next is (this is the order I read my blogs in - obviously I'd want to get the best first) the Mogull. One can see from his postings just how much research he has done into the security field. They are well written and very useful.
Just as wordy and usually more fun is the Hoff. The Hoff is worth reading because of how he pushes the boundaries of what security (or survivability) is all about. He does not pull his punches and is not afraid to sacrifice a few sacred cows along the way.
There are other bloggers that I respect and read too - Anton Chuvakin, Randy Armknecht, Richard Bejtlich, etc etc
I think that the best part of reading all of the above blogs is that the authors all read each others blogs too. This leads to debates, arguments but hopefully lessons learned.
2007 was also the year that I learned about the Security Catalyst Forums where more debate happens. This just proves how new our industry is and how much passion is being put into finding out the answers. This can only be a good thing.
Locally I've kept up with my visits to ISG Africa which has great presentations every month.
I completed almost 100 blog entries over the year, putting into word my thoughts about our exciting industry. My "70s" entries show where we went wrong in the 80s with our IT plans and how we are putting things right again. My 7 habits show how popular business and life philosophies can be used in InfoSec to move us in the right direction. I will hopefully finish those off shortly. (Prediction 2?)
Thank you everyone who has shared their views and hard work with me via their blogs and forums and I hope all that read this blog have learned something and will continue to follow my progress and read my thoughts.
Soon I will post my predictions for 2008.
Showing posts with label alan shimel. Show all posts
Showing posts with label alan shimel. Show all posts
Thursday, January 17, 2008
Monday, June 11, 2007
And Now for Some Bible Education (Part 1)
Information Security is new and fresh and waiting for ideas to mold it. So, I like to look around at older pieces of wisdom in which to help me make decisions on a daily basis.
I was reading the debate between Alan and Michael and it reminded me about an email I got a while back sent to me by a mailing list of interesting lessons from the Torah (Bible books: Genesis to Deuteronomy). I lost the email but I have never forgotten the lesson due to it being very powerful and insightful.(Not inciteful).
Bare with me... there are Information Security lessons and life lessons to be learned here.
Yitro who is Moses' father-in-law comes to visit him after he has left Egypt and tells Moses to appoint judges for his own well being and those of the people. Which makes sense for Moses - he is a busy guy, let someone else do the judging.
But why for the people? They have access to the greatest prophet in history. Moses could judge perfectly. The reason is that you don't want someone who can judge perfectly. Sometimes you need someone who can compromise. This person was Aaron who saw the grey and not the black and white of being sure.
So, Aaron can do something Moses can't which makes him more important than Moses. Wrong. It makes him different.
And here is the moral of the story. Some people are Moses and see black and white and some people are Aaron. And most people are both but at different times.
I think the challenge is to be able to see when to be one or the other.
[TBC]
I was reading the debate between Alan and Michael and it reminded me about an email I got a while back sent to me by a mailing list of interesting lessons from the Torah (Bible books: Genesis to Deuteronomy). I lost the email but I have never forgotten the lesson due to it being very powerful and insightful.(Not inciteful).
Bare with me... there are Information Security lessons and life lessons to be learned here.
Yitro who is Moses' father-in-law comes to visit him after he has left Egypt and tells Moses to appoint judges for his own well being and those of the people. Which makes sense for Moses - he is a busy guy, let someone else do the judging.
But why for the people? They have access to the greatest prophet in history. Moses could judge perfectly. The reason is that you don't want someone who can judge perfectly. Sometimes you need someone who can compromise. This person was Aaron who saw the grey and not the black and white of being sure.
So, Aaron can do something Moses can't which makes him more important than Moses. Wrong. It makes him different.
And here is the moral of the story. Some people are Moses and see black and white and some people are Aaron. And most people are both but at different times.
I think the challenge is to be able to see when to be one or the other.
[TBC]
Thursday, March 15, 2007
Missed out...maybe next year
It seems all the guys who I read online have been honoured by it security.com. I missed out by coming late to the party. Maybe next time I'll be able to slot in just above Alan Shimel.
It has been an interesting few months and I look forward to doing this for a while.
It is an honour ("honor" for Alan and his American friends) to be part of the Security Bloggers Network (and hence number 19 on the list!)
I check the RSS feed of the Security Blogger Network every day and have added a few websites like SSAATY to my list of have to reads.
It has been an interesting few months and I look forward to doing this for a while.
It is an honour ("honor" for Alan and his American friends) to be part of the Security Bloggers Network (and hence number 19 on the list!)
I check the RSS feed of the Security Blogger Network every day and have added a few websites like SSAATY to my list of have to reads.
Friday, March 2, 2007
My 2 cents - NAC and FLOSS (Part 1 - FLOSS)
Since I started my blog and subsequently joined the Security Bloggers Network (see the side panel), I have been following a number of stories posted by other blog members.
Ok, two debates on SSAATY - open source and NAC. I have my opinion on each and here goes:
Alan contends, and I agree with him to a point, that users shouldn't be concerned with the making of software -ie, is it open source, commercial, closed, powered by little rodents, etc. They should only make sure that the software does what they want it to. And I agree to a point.
However, we are security people and we deal in risks and mitigation. Using closed source software does present one with certain risks that open source software does not and that is: what happens if the product is discontinued.
I have seen companies spend millions on closed source software only to wind up with a solution that can not be upgraded or changed. There are some programs that only run on dos and are so closed and so important the company lives with this outdated operating system. I'm not picking on DOS, think of all the proprietary financial systems that had to be quickly fixed or rewritten for Y2K on Unix. A proprietary system that at least has published and open standards (preferably industry-wide standards) would mitigate this risk to a point.
An example that just popped into my head is Internet Explorer. I know of an IT company that has built its entire way of working around an Intranet site. Good for them but they used IE6 specific "features" in the website and it doesn't work with IE7. Had they stuck to standards they would have no problems but they didn't.
You may argue - but Open Source and Open Standards are not the same but Open Source they usually go together whereas closed standards are usually in place to protect market share and don't work very well with Open Source software (where the standards are open as soon as the code is read and analyzed).
To Be Continued.
Ok, two debates on SSAATY - open source and NAC. I have my opinion on each and here goes:
Alan contends, and I agree with him to a point, that users shouldn't be concerned with the making of software -ie, is it open source, commercial, closed, powered by little rodents, etc. They should only make sure that the software does what they want it to. And I agree to a point.
However, we are security people and we deal in risks and mitigation. Using closed source software does present one with certain risks that open source software does not and that is: what happens if the product is discontinued.
I have seen companies spend millions on closed source software only to wind up with a solution that can not be upgraded or changed. There are some programs that only run on dos and are so closed and so important the company lives with this outdated operating system. I'm not picking on DOS, think of all the proprietary financial systems that had to be quickly fixed or rewritten for Y2K on Unix. A proprietary system that at least has published and open standards (preferably industry-wide standards) would mitigate this risk to a point.
An example that just popped into my head is Internet Explorer. I know of an IT company that has built its entire way of working around an Intranet site. Good for them but they used IE6 specific "features" in the website and it doesn't work with IE7. Had they stuck to standards they would have no problems but they didn't.
You may argue - but Open Source and Open Standards are not the same but Open Source they usually go together whereas closed standards are usually in place to protect market share and don't work very well with Open Source software (where the standards are open as soon as the code is read and analyzed).
To Be Continued.
Monday, February 26, 2007
A shout out to Alan Shimel
Hi there Alan (et al),
Thank you for the little blog post on me. I hope I can respond with some good, insightful (incite-ful?) posts to keep you interested.
Congrats firstly on your anniversary.
I consider myself a lay-expert (in other words I spent way too much time on slashdot for my career's good) on GPL so I'll add in my 2c.
The GPL severly restricts what you can do with the source in order to try keep the source available. It is known as "viral" in that if you want to use the source in a project - all the source of that project must also be GPL or compatible.
The big news of a project being GPL compatible is that once the source is GPL compatible it can be added to other GPL projects and in turn other GPL code can be pulled into this project.
Being GPL compatible is also a nice buzzword to use. And it would make coding easier - "Oh, its GPL. I know that". (No need to read the license and compare it to GPL to understand how compatible it is.)
I'm not sure exactly in this case how it benefits everyone but the above may give a good idea of why GPL is better to have than just "open source".
Thank you for the little blog post on me. I hope I can respond with some good, insightful (incite-ful?) posts to keep you interested.
Congrats firstly on your anniversary.
I consider myself a lay-expert (in other words I spent way too much time on slashdot for my career's good) on GPL so I'll add in my 2c.
The GPL severly restricts what you can do with the source in order to try keep the source available. It is known as "viral" in that if you want to use the source in a project - all the source of that project must also be GPL or compatible.
The big news of a project being GPL compatible is that once the source is GPL compatible it can be added to other GPL projects and in turn other GPL code can be pulled into this project.
Being GPL compatible is also a nice buzzword to use. And it would make coding easier - "Oh, its GPL. I know that". (No need to read the license and compare it to GPL to understand how compatible it is.)
I'm not sure exactly in this case how it benefits everyone but the above may give a good idea of why GPL is better to have than just "open source".
Subscribe to:
Posts (Atom)