The Wayback Machine - https://web.archive.org/web/20080211133739/http://blogs.zdnet.com:80/threatchaos/
Richard Stiennon
threatchaos image
Bringing order to threat chaos through news, views and analysis
February 9th, 2008

Yippee! Yahoo’s board rejects Microsoft’s bid

Posted by Richard Stiennon @ 9:15 am Categories: Cool Companies Tags: Board, Yahoo! Inc., Microsoft Corp., Corporate Governance, Business Operations, Corporate Law, Richard Stiennon

I hope this is not just an attempt to up the offer. Funny that Google news has not picked up on this yet. I got an alert by text message from the WSJ.

Update. I see Henry Blodget continues to agree with me. He has amended his original arguments against the Yahoo acquisition to point out that MSFT should not be pursuing the ad market. Good thinking!

See my previous post Death Knell for Microsoft.

February 7th, 2008

Funny. 5/3 Bank advertises malware site in brochure

Posted by Richard Stiennon @ 10:25 am Categories: Spyware Tags: Bank, Malware, Brochure, Spyware, Adware & Malware, Cyberthreats, Viruses And Worms, Security, Financial Services, Richard Stiennon

An alert blogger at BuggStompers picked up a brochure at his last visit to the bank. The brochure, titled “Protect Yourself From Malware” points you to a site to download Spybot search and destroy. But it is not Patrick Kolla’s site at Safe Networking that they provide. As you can see from this scanned image 5/3 Bank directs lobby visitors to go to spy-bot.net a dangerous malware site.

Too funny.

February 6th, 2008

Data protection is impossible

Posted by Richard Stiennon @ 10:04 pm Categories: Data Security Tags: Data Protection, Disaster Recovery, Backups, Data Management, Richard Stiennon

That is the title of my keynote Thursday during the Data Protection Virtual Trade Show. Click here to sign up for this free webinar. It is 11 AM Eastern, 8 AM Pacific today, Thursday, February 7th.

February 6th, 2008

Richard Clarke on recent Mideast cable outages

Posted by Richard Stiennon @ 11:10 am Categories: State Sponsored Hacking Tags: Richard Clarke, Outage, Oracle Real Application Cluster, Fiber, Mideast, Cable Outage, Breakpoint, Threatchaos, Cable, Network Technology, Blade Servers, Databases, Enterprise Software, Telecommunications, Personal Technology, Networking, Servers, Hardware, Software, Data Management, Richard Stiennon

I just happened to be reading Breakpoint by Richard Clarke last week. The premise for the book is that the US finds itself undergoing a series of attacks on its infrastructure starting with simultaneous bombings of several beach heads for the main trans-Atlantic fiber cables as well as undersea cuttings of the same fiber.

I thought Mr. Clarke might have some insight into the past week’s undersea cable outages in the Mideast. He was the chief counter-terrorism adviser on the U.S. National Security Council under Bill Clinton. His comments add a little level-headeness to some of the current hype. Here are his responses to my questions.

Threatchaos: After writing about a series of undersea cable outages in your book “Breakpoint” the recent events in the Mideast where four separate cables have been cut must have caught your attention. Do you think this many cable outages could be coincidence?

RAC: Cable cuts occur all the time, as do underwater relay failures.
When you turn the light on any phenomenon for the first time, it often seems that what you are looking at is a crisis when in fact in it is business as usual. What I tried to show in the form of a fast paced thriller in the opening chapter of Breakpoint was how much more damage could be done if an organized group set about to create havoc by attacking these strand that unite the global village. Disconnect cyberspace in key places and the unified global village and world economy can’t operate. And we have no backup economic system.

Threatchaos: Whether or not these outages are nefarious let’s play “what if?”.
What would the next step be for a nation or terrorist organization that
Sought to disrupt communications in the Mideast?

RAC: There are many parts of the world where a few cuts would
disconnect them from cyberspace or so reduce band width as to have
much the same effect. Some of the places where the cuts could occur,
like deep under water, would make repair time consuming.

Threatchaos: “Breakpoint” makes it chillingly obvious that we have done nothing to protect critical assets like undersea cables and the power grid. Do these incidents in the Mideast reflect the vulnerability of undersea cables everywhere?

RAC: Yes, this is a reminder. And while undersea lines were cut in
the novel, there were also attacks on the places where the cables come
up from under the water and go on the beach. Those places are well
known and unprotected.

Threatchaos:
What should the we do to make the Internet less vulnerable to physical attacks like this?

RAC:
No one has the responsibility to insure there are redundant lines. Each company makes a decision based on market forces as to whether to invest in building new capacity. Nobody pays the private firms that own the fiber to build excess capacity. In some places it exists, but there are many point-to-point connections that have single points of failure and insufficient work-arounds available. There ought to be a public-private partnership, an international one, that insures there is adequate capacity to handle large scale outages caused by malevolent actors. That means back up dark fiber, rapid repair and replacement capability, and research to increase the bandwidth for laser uplink/downlink satellite comms.

Threatchaos: What can the typical large enterprise do to prepare for future network outages?

RAC. Large enterprises need to have service from multiple providers.
They need to investigate whether their multiple providers are all using the same fiber or the same conduit at key single points of failure. And they need to have contracts that allow for rapid re- provisioning to shift load from one provider to another.

By the way, Breakpoint is a great read. Opens your eyes to some underlying weaknesses in the world’s infrastructure.

February 4th, 2008

Birth of IPv6

Posted by Richard Stiennon @ 2:06 pm Categories: Secure Network Fabric Tags: IPv6, IP, IP Address, Networking, Telecommunications, Richard Stiennon

Well tonight’s the night. For the first time, IPv6 domain resolution will be possible from a root server. Just a few addresses mind you, according to this article. You may ask “what took so long?”. The answer is that we did not really need it. IPv6 bakes in some security that was addressed by SSL in IPv4 so that driver did not help. The other issue, a rapidly depleting address space, was managed by NAT(Network Address Translation). But now depletion is really staring us in the face. It is getting hard to get address space. Soon you will see the first bidding wars for owners of large blocks of free IP addresses. Technically you are not allowed to sell IP addresses so don’t expect a market for them. But do expect high valuations for shells that control IP address blocks.

So soon there will more than enough IP addresses to go around. How many you say? Here is a great excerpt from Wikipedia:

For example, IPv6 supports 2128 (about 3.4×1038) addresses, or approximately 5×1028 addresses for each of the roughly 6.5 billion people[1] alive today. In a different perspective, this is 252 addresses for every star in the known universe [1] – a million times as many addresses per star than IPv4 supported for our single planet.

That should do it.

Get ready for several years of growing pains. Not the least of which will be all the exploits for the newly deployed IPv6 stacks that have not been well tested in the real world. Routers, servers, desktops, all will have their turn. The bad guys will have fertile ground to work.

February 4th, 2008

Don’t get excited over cable breaks. Yet.

Posted by Richard Stiennon @ 6:45 am Categories: State Sponsored Hacking Tags: Iran, Cable, Network Technology, Telecommunications, Personal Technology, Networking, Richard Stiennon

This weekend there was a lot of hand wringing over some posts to Digg, reddit, and slash dot that pointed to this page at the Internet Traffic Report. There is one router in Iran that is not responding to pings so it shows up red. This led to the rapid development of a conspiracy theory that the US is systematically cutting the undersea cables to the Mideast in preparation for an invasion of Iran!

For a great analysis of the cable breaks and the impact on Mideastern countries check out the Renesys blog. In one post they even track the “winners and losers” in the telecom space as those networks that were cut off scramble to replace their provider. I’ll be checking this blog often from now on!

February 3rd, 2008

Fourth cable cut in Mideast

Posted by Richard Stiennon @ 5:42 pm Categories: State Sponsored Hacking Tags: Ministry, Cable, Network Technology, Telecommunications, Personal Technology, Networking, Richard Stiennon

On top of the news today that yet another cable has been broken connecting the Mideast to the rest of the world we learn that the first two cables were not cut by ships dragging their anchors.

According to at least one report an Egyptian ministry examined 24 hour surveillance cameras and found:

The transport ministry added that footage recorded by onshore video cameras of the location of the cables showed no maritime traffic in the area when the cables were damaged.

Something mighty strange going on here.

Update 2-7-08: See Dick Clarke’s response to my questions on these cable outages.

February 3rd, 2008

More on Microsoft + Yahoo!

Posted by Richard Stiennon @ 1:19 pm Categories: Security Industry News, Windows Tags: Google Inc., Merger, Yahoo! Inc., Microsoft Corp., Mergers & Acquisitions, Investment, Finance, Richard Stiennon
In Focus » See more posts on: Microsoft-Yahoo

Henry Blodget does a plain vanilla analysis of the Microsoft + Yahoo! merger on Sillicon Alley Insider. He agrees with my predictions of disaster but bases his arguments on how difficult it will be to execute on the merger. By the time regulatory hurdles are overcome Blodget thinks it will be at least a year before the deal can happen and in the meantime there will be brain drain and stalled innovation, giving Google a chance to surge ahead.

All good arguments. True for any large merger. But I go further than that. It is a bad deal because MSFT should not be in the online ad business period. Even in a perfect world where everybody dug in and pulled off this merger without a hitch it would be a disaster for both Yahoo! and Microsoft.

Just a few minutes ago Google has chimed in, stating that this merger is “troubling”. In other words Google will be rooting for a long drawn out process that leaves the field clear for them to continue to innovate and do an end run around Microsoft. Google realizes that there is a business model in developing useful apps online. Microsoft has missed that point.

February 1st, 2008

A successful bid for Yahoo! would be death knell for Microsoft

Posted by Richard Stiennon @ 11:50 am Categories: Security Industry News, Windows Tags: Advertisement, Yahoo! Inc., Microsoft Corp., MSFT, Internet, Richard Stiennon
In Focus » See more posts on: Microsoft-Yahoo

Microsoft has weathered two significant challenges to its world wide monopoly. It is facing the third challenge right now and it is not advertising revenue. The first challenge was the Internet. Microsoft almost missed the boat there but thanks to Bill Gate’s mom he was introduced to a local ISP and immediately grasped that the Internet changed everything. He wrote a famous memo and turned the MSFT juggernaut. It is still too bad that he crushed Netscape in process, that was uncalled for. But, by introducing a TCP/IP stack into Windows 95 Microsoft ensured the rapid growth of the Internet and their own place as the platform of choice for accessing the marvels of the web.

The next challange to Microsoft was security. And, another memo outlined their response and what has now proven to be a successful strategy. Microsoft has weathered the vulnerability storm. Thanks for to better patch management than to better software practices, but that is coming too.

I find it ironic that Bill Gates has even identified the next major challenge to Microsoft’s world domination. He recognized back in 2005 that web based applications were the next “sea change”. But, because he had stepped down from day to day operations, and this year is retiring completely, I believe Microsoft has failed to act effectively to address this final challenge.

Maybe it is my years fighting “ad supported software” otherwise know as adware, scumware, shlockware, spyware, that makes me suspect of the “ad economy”. Yes, Google makes obscene levels of money over a few simple but powerful applications. But just because there is money to be made does Microsoft have to be in that space? Was MSFT buying up gold and oil reserves the last few years? Are they getting into bulk shipping? Were they buying New Zealand dollars? There are tons of ways to make money if you are sitting on $19 billion. Ways that have real returns for your stake holders.

This grab for Yahoo! will kill Microsoft if it goes through. The guys at Yahoo! are smarter at generating ad revenue than the guys at MSFT but they are still losing out to Google. Microsoft should open their eyes to the real challenge facing them: software as a service. Chasing after ad dollars is a red herring.

If this deal goes through you will be able to mark this single event as the beginning of the end of the biggest tech giant ever.

February 1st, 2008

Too funny. French employment policies.

Posted by Richard Stiennon @ 11:00 am Categories: Bank security Tags: Bank, Financial Services, Richard Stiennon

I first encountered the difference between French and US employment policy during the dot com boom and I was working with a friend, Gilles Lerat, on an electronic coupon management solution he had developed. His company, a successful security consulting and reseller firm, was worried about the “employment police” who would stake out their parking lot and fine the company if they uncovered evidence that people were working late. Can you imagine? A bunch of 25 year old engineers being told to go home, they had done enough for one day? An example of laws written for post war Europe when “jobs” were different I guess.

In a freaky turn of events we discover that Jerome Kerviel is still employed by Societe Generale, the bank that he fraudulently plundered of $Billions. It turns out that two judges ruled this past weekend that he must stay away from the bank during an ongoing investigation. But, in order for Societe Generale to actually fire Jerome they must sit down with him and a representative in a scheduled meeting. Donc, en empasse! While they have apparently stopped his pay, M. Kerviel is still an employee.

Only in France. In the meantime some are trying to figure out who will play JK in the movie?

Richard Stiennon is an industry consultant. See his full profile and disclosure of his industry affiliations.

advertisement

Recent Entries

Most Popular Posts

advertisement

Archives

ZDNet Blogs

Popular white papers

Favorite Links