Posts

STFU - A Guide For People Who Talk Too Much

Ask anyone who knows me, and they'll say I'm a talker. Ask anyone who has known me for a few years, and they will likely say I talk too much. Ask someone who just met me, and they might wonder where you got that idea. Years ago, I started to evaluate TTM Syndrome (Talk To Much... don't look for it in medical journals, it ain't there, I'm sure) and as I started to look at other TTMs, I was surprised. Yes, my self-diagnosis started with someone who actually talked more than I did (and had less of a filter; something I wasn't sure was possible). Make no mistake, this was one of the smartest people I had ever met. In our more meritocratic communities (my work in Technology, for example) this wasn't (always) seen as a bad thing, but that kind of behavior doesn't foster brainstorming and creative problem solving in others. So, in light of the fact that I just "talked too much" in the intro, here is a guide I made for myself. Edited and upd...

Capsaicin Headaches - A Cure?

Okay, "cure" might be a bit optimistic, but permit me to relate to you the events of the last two days: I took my family out to Old Chicago. Now, I have not been avoiding restaurants which have hot food because I don't ever want to be "that person". You know, the one where you have to watch what you serve because he doesn't eat fish (which I don't), doesn't eat Chinese (which I don't), doesn't eat meat (which I do!), or has some other dietary restrictions which always seem to be imposed on those around him. Buuuut, after trying to get my family to go to Three Margaritas or another fine Mexican restaurant (knowing I'd have to probably eat off the kids menu), we decided on Old Chicago. For those who are unfamiliar with it, it's an awesome pizza-and-beer joint. I ordered their "Double Deckeroni" pepperoni pizza. No big deal. I took my first bite, and *hot*. Yes, it was too hot to be spiced with Italian spices. I knew righ...

Capsaicin Headaches, Take 3

Okay, now we're at 4 1/2 months. I've seen an allergist (who is supposed to be an expert at allergies and intolerances) and MAN was that worthless. Me: I've had headaches on and off for the last 6 years or so, all year round. Over the last year they increased in frequency to almost daily. Then, in October when I stopped eating capsaicin, they disappeared overnight. Doc: Hmmm. Since they disappeared at the end of allergy season I don't think it's capsaicin. It's probably your grass allergy. Me: Did you catch the fact that it's been going on for SIX FRIGGIN YEARS???? Anyway, a few interesting tidbits... Now, when I *do* have something hot (to test it) I now have NO tolerance for hot sauce! Man, even the lamest, mildest seasoning is hot to me. My impression is also that my intolerance is getting significantly worse. Early on (November), I was able to have 4 drops of Cholula sauce on Mac and Cheese to no effect. It would take a bit more for me to get a ...

Capsaicin Headaches, Take 2

Well, now I am at about the 3 month mark in my experiment ( eliminating capsaicin from my diet ) and I have had a total of 4 headaches in the last three months and all but one were deliberately triggered. This is fascinating to me, as I wonder how many people are suffering the same as I am! ...and I'll tell you what, the idea of taking a capsaicin spray and sticking it up my nose as a "cure" scares the crap outta me. I sure hope it works for other folks who are having a different problem than I, but for me I think I would prolly be in so much pain I would but a bullet through my skull. Short update, and I'm grateful. I feel SOOOOO much better. 4 months ago I would not have even dared to dream I could be headache free for even so much as two weeks in a row...

Capsaicin Intolerance

Okay, so this is neither about God, nor is it about security, but it's too important for me to not post, so here goes. I have had debilitating headaches for years. Probably 6 or 7. They would typically hit one side of my head, often behind the eye, or to the side at the temple. My neck would sometimes hurt as if it were "out of whack". For years I had a "cure." I would take 3 Advil and one red Sudafed pill, then I would lie on my back for 45 minutes. It seemed that, usually, at the 45 minute mark I would feel my sinuses crackle and drain, and my headache would go away. Recently, about a year ago, this stopped working. I'd still do it, in hopes that it was lessening the pain, but it became a case of having to wait them out. This was unfortunate, as they used to also disappear without treatment overnight. Now, they would last for over 24 hours with alarming regularity. They were also happening much more frequently. What used to be an occasional (eve...

Hacking Exposed and Customer Focus

Recently (yesterday) I had the opportunity to chat over a meal with George Kurtz, a Senior Vice President and general manager in charge of McAfee's Risk and Compliance unit. (whew, that's a mouthful). In attendance were a small number of other CSO's (or equivalent) and we listened to George, also a co-founder of Foundstone, the premier vulnerability scanning solution. We also bounced some ideas back and forth and generally shared information like good stewards of our respective enterprises. So, keep in mind that McAfee is a vendor. They sell products and services. I found it fascinating that one of the most common themes to the questions was not technology, rather it was something relating to the "human" side of information security. Question such as: how can we justify headcount? who dictates policy? how do we show value to management? I find this interesting for two reasons. One: security people often tend to be caricatures of other IT folks. Even more ...

CISSP

Okay, so after years of putting of taking the CISSP examination (read: trying to get someone else to pay for it) I finally scheduled my exam and took it in April. There are plenty of posts about it, and I don't want to duplicate what others have said, so I'll just put in this small bit: If you can regularly pass the FreePracticeTest exams online with an 80 or higher, then you are most of the way there. I don't think I ran into a single question on FreePracticeTests(FPT) that was on the actual exam, but they give a *great* fell for what to expect. This means, however, that just learning the answers to FPT won't do you any good. In my case, I had 10+ years of dedicated info security experience by the time I took the test, plus years of consulting and SA/SE work prior to that, so there was little on there to surprise me. What I did was go out and buy Shon Harris' excellent book and read the chapter titles to see what areas I seemed lacking in (based on the FPT)....

Security Incident Cost BS

Sometimes the obvious isn't. Apparently. An organization I'm familiar with recently had a small "virus" outbreak. It wasn't really a virus, but I'll call it that for simplicity. This "virus", though it infected over a score of computers, was largely held at bay due to defense-in-depth. It couldn't communicate with the outside world because of our firewalls and some local policy stuff on the workstations, but it *did* infect them in such a way that McAfee couldn't find them. It took an analysis of firewall logs to track the compromised systems down. All well and good. Nothing new. Now, we have an estimate of how much this incident "cost" the organization. I was peripheral to the cost calculation, but it seemed based on a simple I-CAMP model ( here's a good article on it from 2002 ) where you take the time people put into remediating the issue, and multiply by their wage. Thus, 5 administrators who each put in 10 hours at ...

Skeptical on Skepticism

For every post here on God And Security, 20 posts go never make it out of my head, and instead go "unposted". Throughout the weeks, many items catch my fancy, thoughts come and go, and my job gets in the way (I need to post from home, ya see...). Today, one escaped. Here are some thoughts on skepticism . Many of todays atheists prefer to be called "skeptics". I suppose this is because "atheism" sounds like (and, indeed has largely become) a religion. Skeptics (in this context) are people who proclaim non-theism in light of the lack of proof, and then take the stance that the lack of proof (or acknowledging that they won't likely prove a negative ) is reason enough to take a contradictory stance. These pseudo-scientists seek to show that a lack of first-person, verifiable positive feedback (i.e. proof) is reason to take a stance on (or, more specifically, against) an item. In this case, the case for God. I say "pseudo scientists" becaus...

The New Athiests

I don't have much to add to this. Many interesting point here. Peter, as with many people taking an apologetic view (if you're not familiar with my use of "apologetic", follow the link) don't have the time or space to fully cover the issues, but he does an excellent job of providing some first arguments (which means there are a dozen counter-arguments and counter-counter arguments) to some interesting issues, as well as his classification of what makes the "new athiest", which is what I found the most interesting.

Oh NAC, We Hardly Knew Ye...

...before ye were corrupted by the Forces of Evil(tm). An acquaintance of mine just returned from Interop with a drawerfull of information which he showed to me. Having spent 18 months doing NAC deployments around the country and overseas, I was bummed at the direction many of the security^H^H^H^H^H^H^H^Hsoftware companies are taking this technology. Let me clarify NAC (Network Access Control) for you. NAC is: -Verifying the security posture of a system and the identification of a user to allow the user to use the system to gain access to the appropriate network, such as the enterprise, management or guest network. (Authorization may then allow the user to access resources on said network). NAC is not: -Anti-Virus (A/V) -Anti Spyware (A/S) -Endpoint (personal) firewall (E/F) -posture/profile control (blocking USB devices, for example) -A patching system Once upon a time, NAC was a tool independent of the desktop security posture components (A/V, A/S, E/F, etc...) used to verify the ...

PGP Primer

I recently saw a posting in which the blogger answers a question about "how PGP works. " I have no real context for why the question was asked (there's a reference I didn't follow at the beginning) but I found the description of PGP (Pretty Good Privacy) a bit brief. So I'll give something more lengthy. Anyone who knows me knows that being verbose is *not* one of my gifts. However, I'll shoot for something between a brief one-line definition and a Wikipedia article . First, PGP's primary uses: Encrypting messages and files Digitally signing messages and files Encryption - Many people are familiar with a basic way to encrypt something on a computer. You put a password on it, and anyone who knows that password can read it. PGP is novel in that it uses a different paradigm. Rather than give you the specifics on how it works, I'll give you an illustration on how it functions: You have an unlimited number of safes (as in a safe you would put money or ...

Airport Security Part II: Anticipation is Making Me Wait

Over the last three years, I have probably had to go through an airport security screening line on average of once per business day. I've seen *many* things. While its popular to attack airport screening , and I suppose it's apropos considering some of the lameness we've seen from the TSA , I'd like to take a turn at defending it...a bit. I've read articles about people who have had all kinds of problems. Most of them involve the elderly, the young or the handicapped. I'm not making a judgment call, I'm just relating what *I've* seen and how I feel it probably extends to the world beyond me. My first observation is that the bulk of issues I see at the screening points surround people not being aware of the rules. Let's pick one simple rule that, from my experience, makes up way over half of the "issues" at the TSA checkpoints: liquids. Now, take a walk with me. We're going to start at the ticket counter at Denver International Airp...

Know Thine Enemy

I know it's politically incorrect to generalize about a group of people. A small percentage of Mexicans enter this country illegally, and all Mexican-Americans feel the brunt of criticism. Similarly, when I was in college, if you were white and had a shaved head, you were probably a racist in most people's eyes even though I'd bet that "skinheads" were the minority of bald white men. At what point is something a problem? Recent census information shows about 41 million Hispanics in the US. With somewhere between 6 and 10 million illegal Hispanics in the country, that represents about 15% to 25% of Hispanics being here illegally (with the understanding that the percentage could be lower, as I have no numbers on how well the illegal aliens were counted in the census numbers, and therefore may add to the 41 million, instead of being a part of it.) If I were Hispanic (which I am) and I knew that some double-digit percentage of "my bros" were illegals, ...

Lenox Financial

Okay, you've heard the annoying commercials on the radio with the tagline "the biggest no brainer in the history of Earth." When it came time for me to refi (a few years ago), I decided to give them a shot, skeptical though I was. They did everything as advertised, to my great surprise! Why am I putting this in my blog? Because when I was researching them, I couldn't find anything about them. I couldn't find anyone who had blogged or posted or anything about them. So here you are, I used them and am happy. On an interesting side note, a local company ran a *brief* counter-ad which had the line "don't be fooled by no fee gimmicks..." That ad didn't stick around long, presumably because people are learning that they aren't "gimmicks". Well, at least mine didn't appear to be!

The Countdown to Copycats

Let's review the situation With 105,000 + K-12 schools in the United States, I'll venture to say that we see at least one copycat by the end of this school year. By copycat, I'm saying that some student somewhere will claim to see a few suspicious people with the hopes of shutting down school for a day. Whereas a bomb threat is a felony, and most students know it's a _big_deal_, others might not realize that such a claim as a suspicious intruder can still land them in a comparable world of ...badness.

It's Not What You Know...

Well, actually it is. "What you know" is critical here, because this is a security post. "Whom you know" (who? whom?) if *far* more important on the religious side of my blogging :-) Information Technology (IT) is a fascinating industry. As people jockey for position, I now see and older generation of IT people (35+ years old) and the young upstarts go head-to-head on issues. The "oldsters" say that they have all the experience, and the youngsters say that anything they learned in IT over 5 years ago is of little or no value. While I agree that the fact that I remember how to low-level format an MFM drive from the machine language monitor (debug;g=c800:5 or g=cc00:5) is of absolutely no value today, the same cannot be said for security knowledge. I was reading a random article I picked up from my daily trip to Infosyssec (www.ghosthip.com ) which posed an excellent question: "What basic security knowledge should be expected from security profes...

Idea Explorer: Security

In his blog, Brad Jarvis identifies six of the approaches to maintaining effective security. These approaches are not IT-centric, but rather are for personal and civic security. They are: Offense Defense Containment Alliance Assimilation and Retreat. Specific descriptions may be found at this link: Idea Explorer: Security. I tend to look for "universal truths" as often as I can. In this pursuit, I looked at Bradley's list and attempted to put it towards IT (Information Technology) security. Truly, all of these approaches may be seen, even " alliance " and " assimilation ", in the IT world. While I was going to spend some time expounding upon the parallels, I became enamored with one in particular: offense. Offense, as Bradley identifies it, involves "attacking (destroying) someone perceived as a threat". I have worked in numerous computing cultures, from WFO (Wide Friggin Open) to military and financial uber-controlled. I currently wor...

Mitt Romney is the Antichrist

...and I shouldn't use hyperbole in a blog post title. In a previous post, Dishonesty in Religion , I talk about my concerns with having a Mormon as the President. I few comments on the blog and a few discussions with friends have helped me to amend this position. I would have a problem with Mitt Romney as President. First, let me give you some of my assumptions: -Most things a politician says, s/he says with an agenda in mind. -Most politicians are interested in garnering as much of the vote as possible My problem is that when Mitt presents himself to Christians , he tries to present himself as one of them (see Dishonesty in Religion for why this is a problem). I believe, however, that he is not only being dishonest in how he presents his beliefs to Christians, but I believe he is subtly reaching out to other demographics in dishonest ways. When asked what his favorite novel was, Mitt stated that it was Battlefield Earth , a sci-fi novel by Scientology founder L. Ron Hubbard. ...

Death to Security Companies

Well, that's what Art Coviello from RSA would have us believe . To quote Art, "With the exception of a few exceptional start-ups, there will be no standalone security businesses within three years." There's no way he's just making this comment because RSA has joined forces (read: been absorbed) by EMC, the network storage giant. That is not to say that I disagree with all Art says. He comments that the security industry is too focussed on its own problems, and not enough on trying to perfect security. I wholeheartedly agree. Having worked with and for a number of pure security players, I can safely say that they are focussed on the "business" of security and not the "ideal" of security. Does that make them wrong? No, but it isn't encouraging, either. This particular problem, however, doesn't go away because security vendor "A" has now been purchased by larger corporation "Z". Now, EMC has a cute little securit...