<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: By their fruits, ye shall know them</title>
	<atom:link href="http://emergentchaos.com/archives/2008/02/by-their-fruits-ye-shall-know-them.html/feed" rel="self" type="application/rss+xml" />
	<link>http://emergentchaos.com/archives/2008/02/by-their-fruits-ye-shall-know-them.html</link>
	<description>The Emergent Chaos Jazz Combo</description>
	<lastBuildDate>Wed, 01 Feb 2012 19:20:40 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
	<item>
		<title>By: Adam</title>
		<link>http://emergentchaos.com/archives/2008/02/by-their-fruits-ye-shall-know-them.html/comment-page-1#comment-4368</link>
		<dc:creator>Adam</dc:creator>
		<pubDate>Mon, 18 Feb 2008 21:05:40 +0000</pubDate>
		<guid isPermaLink="false">http://emergentchaos.com/?p=2649#comment-4368</guid>
		<description>PHB,
I think that attention to the reasons for bad security and breach notice are intertwined.  As we start talking about what&#039;s going wrong and why, we can start to address it better.
</description>
		<content:encoded><![CDATA[<p>PHB,<br />
I think that attention to the reasons for bad security and breach notice are intertwined.  As we start talking about what&#8217;s going wrong and why, we can start to address it better.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: PHB</title>
		<link>http://emergentchaos.com/archives/2008/02/by-their-fruits-ye-shall-know-them.html/comment-page-1#comment-4367</link>
		<dc:creator>PHB</dc:creator>
		<pubDate>Mon, 18 Feb 2008 19:44:49 +0000</pubDate>
		<guid isPermaLink="false">http://emergentchaos.com/?p=2649#comment-4367</guid>
		<description>Perhaps before we go into breach notification in even more depth, perhaps a bit of attention to the reasons for bad security.
Yes I know that some companies are just lazy, but many are not and many of them have breaches as well.
I have been looking at the usability of some well known security applications and the picture is not at all pretty.
I can set ACLs to set up a database, but when I tried to use them to stop the kids from watching random stuff on the media vault I quickly realized that the whole system is broken.
Protecting information according to where it is stored does not work once data starts to move about.
We need to completely rethink some core approaches here. The security usability just sucks, and it is no better on the Mac and much worse on Unix.
</description>
		<content:encoded><![CDATA[<p>Perhaps before we go into breach notification in even more depth, perhaps a bit of attention to the reasons for bad security.<br />
Yes I know that some companies are just lazy, but many are not and many of them have breaches as well.<br />
I have been looking at the usability of some well known security applications and the picture is not at all pretty.<br />
I can set ACLs to set up a database, but when I tried to use them to stop the kids from watching random stuff on the media vault I quickly realized that the whole system is broken.<br />
Protecting information according to where it is stored does not work once data starts to move about.<br />
We need to completely rethink some core approaches here. The security usability just sucks, and it is no better on the Mac and much worse on Unix.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Chris</title>
		<link>http://emergentchaos.com/archives/2008/02/by-their-fruits-ye-shall-know-them.html/comment-page-1#comment-4366</link>
		<dc:creator>Chris</dc:creator>
		<pubDate>Mon, 18 Feb 2008 16:43:31 +0000</pubDate>
		<guid isPermaLink="false">http://emergentchaos.com/?p=2649#comment-4366</guid>
		<description>Benjamin:
What specific guidance in the bill I wrote about is improper?  Issues with AB 779 are irrelevant: that isn&#039;t the bill under discussion.
How is a requirement for &quot;clear language&quot; a technical topic, for example?
It&#039;s not like the CA legislature is providing prescriptive guidance to the people who design or operate the infrastructure used to hold or transmit PII; they&#039;re just saying what you need to do if it is revealed, despite whatever technical measures you&#039;ve used (save encryption) to protect it.
</description>
		<content:encoded><![CDATA[<p>Benjamin:<br />
What specific guidance in the bill I wrote about is improper?  Issues with AB 779 are irrelevant: that isn&#8217;t the bill under discussion.<br />
How is a requirement for &#8220;clear language&#8221; a technical topic, for example?<br />
It&#8217;s not like the CA legislature is providing prescriptive guidance to the people who design or operate the infrastructure used to hold or transmit PII; they&#8217;re just saying what you need to do if it is revealed, despite whatever technical measures you&#8217;ve used (save encryption) to protect it.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Benjamin Wright</title>
		<link>http://emergentchaos.com/archives/2008/02/by-their-fruits-ye-shall-know-them.html/comment-page-1#comment-4365</link>
		<dc:creator>Benjamin Wright</dc:creator>
		<pubDate>Mon, 18 Feb 2008 15:33:56 +0000</pubDate>
		<guid isPermaLink="false">http://emergentchaos.com/?p=2649#comment-4365</guid>
		<description>Adam:  When a legislature wades into a technical topic that it really does not understand, it makes a fool of itself.  The California legislature made a fool of itself when it enacted Assembly Bill 779 in September.  Even though the spirit behind 779 was pure, the legislation was technical mess and the governor vetoed it.  See &lt;a href=&quot;http://hack-igations.blogspot.com/2007/10/i-am-no-fan-of-part-of-californias.html&quot; rel=&quot;nofollow&quot;&gt;&lt;a href=&quot;http://hack-igations.blogspot.com/2007/10/i-am-no-fan-of-part-of-californias.html&quot; rel=&quot;nofollow&quot;&gt;&lt;a href=&quot;http://hack-igations.blogspot.com/2007/10/i-am-no-fan-of-part-of-californias.html&quot; rel=&quot;nofollow&quot;&gt;http://hack-igations.blogspot.com/2007/10/i-am-no-fan-of-part-of-californias.html&lt;/a&gt;&lt;/a&gt;&lt;/a&gt;
</description>
		<content:encoded><![CDATA[<p>Adam:  When a legislature wades into a technical topic that it really does not understand, it makes a fool of itself.  The California legislature made a fool of itself when it enacted Assembly Bill 779 in September.  Even though the spirit behind 779 was pure, the legislation was technical mess and the governor vetoed it.  See <a href="http://hack-igations.blogspot.com/2007/10/i-am-no-fan-of-part-of-californias.html" rel="nofollow"></a><a href="http://hack-igations.blogspot.com/2007/10/i-am-no-fan-of-part-of-californias.html" rel="nofollow"></a><a href="http://hack-igations.blogspot.com/2007/10/i-am-no-fan-of-part-of-californias.html" rel="nofollow">http://hack-igations.blogspot.com/2007/10/i-am-no-fan-of-part-of-californias.html</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Adam</title>
		<link>http://emergentchaos.com/archives/2008/02/by-their-fruits-ye-shall-know-them.html/comment-page-1#comment-4364</link>
		<dc:creator>Adam</dc:creator>
		<pubDate>Mon, 18 Feb 2008 12:16:35 +0000</pubDate>
		<guid isPermaLink="false">http://emergentchaos.com/?p=2649#comment-4364</guid>
		<description>Benjamin,
So you think we need more laws with bits like SarBox 404?  I think a lack of detail can be less wise than detail.
</description>
		<content:encoded><![CDATA[<p>Benjamin,<br />
So you think we need more laws with bits like SarBox 404?  I think a lack of detail can be less wise than detail.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Benjamin Wright</title>
		<link>http://emergentchaos.com/archives/2008/02/by-their-fruits-ye-shall-know-them.html/comment-page-1#comment-4363</link>
		<dc:creator>Benjamin Wright</dc:creator>
		<pubDate>Mon, 18 Feb 2008 09:20:02 +0000</pubDate>
		<guid isPermaLink="false">http://emergentchaos.com/?p=2649#comment-4363</guid>
		<description>A legislature is unwise to get into technical details like &lt;a href=&quot;http://hack-igations.blogspot.com/2008/02/encryption-legislation-goes-overboard.html&quot; rel=&quot;nofollow&quot;&gt;encryption&lt;/a&gt;.
</description>
		<content:encoded><![CDATA[<p>A legislature is unwise to get into technical details like <a href="http://hack-igations.blogspot.com/2008/02/encryption-legislation-goes-overboard.html" rel="nofollow">encryption</a>.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Iang</title>
		<link>http://emergentchaos.com/archives/2008/02/by-their-fruits-ye-shall-know-them.html/comment-page-1#comment-4362</link>
		<dc:creator>Iang</dc:creator>
		<pubDate>Mon, 18 Feb 2008 06:08:27 +0000</pubDate>
		<guid isPermaLink="false">http://emergentchaos.com/?p=2649#comment-4362</guid>
		<description>Calling on the government to solve some problem is almost always a mistake.  SB1386 may be the rare exception.
Calling on the government to improve on this ... has to be treated with some degree of skepticism.  I find it very unlikely that any government decree can cause reliable breach reporting and reliable information gathering.  This mission is unachievable.  There are always methods by which companies will find ways to confuse the data delivery.  If you can&#039;t see how to do that, then ... you&#039;re probably not in the security world!
At some stage we have to think about open governance being run by the people.  That is, expect to see some quality control from open institutions, ones that arise for a need.  E.g., blogs like this and other aggregators of info.
</description>
		<content:encoded><![CDATA[<p>Calling on the government to solve some problem is almost always a mistake.  SB1386 may be the rare exception.<br />
Calling on the government to improve on this &#8230; has to be treated with some degree of skepticism.  I find it very unlikely that any government decree can cause reliable breach reporting and reliable information gathering.  This mission is unachievable.  There are always methods by which companies will find ways to confuse the data delivery.  If you can&#8217;t see how to do that, then &#8230; you&#8217;re probably not in the security world!<br />
At some stage we have to think about open governance being run by the people.  That is, expect to see some quality control from open institutions, ones that arise for a need.  E.g., blogs like this and other aggregators of info.</p>
]]></content:encoded>
	</item>
</channel>
</rss>

