Priorities…..
I notice little gets reported about Net Neutrality but we’re deluged with iPhone news. Wireless (in)security is no longer a hot topic but Symantec announcing it will speed up it’s products is big news. WAFs are a hot topic but we’ve long forgotten that good basic practices help security more than any tool will. Another annual BS security survey on how bad things are will be reported everywhere, but few will drill down to the question of why the business worlds overall state of security is poor. Everyone is in “the cloud” but no one reports almost 20 years of those company’s previous promises/failures.
Everything is wonderful!
Just don’t mention PCI.


July 17th, 2008 at 3:30 pm
Traditional media is 1.0.
Will be defunct soon.
Demonstrate, model or die.
What about a distributed attack that maxes power utilisation, by co-ordinated rebooting of zombies at a certain pre-allocted time. Like an orchestrated Computer based “Earth Hour”… lather, rinse, repeat?
What org footprint or geographic location would function the most effectively? GIS/Netblock?
July 17th, 2008 at 7:52 pm
D2, I reckon you work part time as a spam writer. Not saying points aren’t valid when I squint my eyes and think hard…just the pattern of writing has me thinking…..
Now BG highlighted it, I look back on some of your posts and I can see things.
http://beastorbuddha.com/forums/index.php?action=vthread&forum=1&topic=90
July 17th, 2008 at 9:47 pm
Sometimes I have to act fast to capture the concept as its ethereal nature is fleeting
Sometimes it’s a moment in between other thoughts; but mainly its me trying to bang out an idea in work without looking like I’m skiving off
Incorrect syllable count for haiku, though in retrospect the first part has that feel!
The last three lines are actually totally unrelated and should be in mine own blog. Was thinking about power utilisation for good and evil and targetting parts of the grid via IP ranges and dodgy code maxing kVAs
Beverages to come… spatial thinking is hard to capture in plain text quickly without being garrellous and overblown, I mean SPAM, I mean erm’ images, and erm’ eh language, yeah that’s it, language!
July 17th, 2008 at 11:24 pm
@D2, seemingly simple ideas are in supposed execution so complex. Why? They are not. You are right. Take a step back from the vulns in apps/systems and the bigger picture issues are far worse. No one tests that stuff. Reason: it takes a more complex and time consuming effort to do the proof of concept. But it will happen so you can look back and say ‘I told you so!’.
July 17th, 2008 at 11:43 pm
@G, I can’t argue with that. It is on the ball! It’s clear cut and obvious. It is just a matter of time (for someone who has it) to do it but for some reason, because it is not done, ie; your “proof of concept” the stakeholders who will be affected show little care-factor. Business and dollars is what counts and if D2’s voicing makes no sense to them, they won’t give a rats. The odds are, D2, will be proven right. But by then, he will have moved on and the “experts” will look like heroes solving the problem post event……even though they should have been aware of the risk well beforehand. Have seen it so many times in my working life. Deep breath….
DD