Some great insight on thinking about security

TaoSecurity: Marcus Ranum Highlights from USENIX Class
There's some very good points here in TaoSecuritys summary of a Marcus Ranum session at Usenix.
I've not seen the original talk but the summary makes me wish I'd been there.
The point on the perimeter being a complexity management tool is very well made in reference to de-perimeterization. It's all very well saying that each individual device needs to be able to stand alone from a security perspective but it's still a lot easier to manage the security of the wider environment when you've got some control over what can get in at all, and the perimeter can and does provide that.
The points about quantification problems seem to have provoked a response from Alex . I actually think having seen these arguments come up repeatedly on blogs and on the CISSP forum and also having started reading "Security Metrics" by Andrew Jaquaith, that there's less distance between the people who are strong proponents of quantitative analysis and those who are proponents of qualitative analysis. One thing that has struck me in these debates is when you look at the examples on both sides they tend to be in different areas of security.
My feeling is that there needs to be a mix of the two styles depending on where they're most appropriate, but I'll reserve expanding on that till I've sorted my thoughts on the matter out better as it's a bit of a minefield...

SaaS vendor security.

Rational Security: On-Demand SaaS Vendors Able to Secure Assets Better than Customers?
An interesting post from Hoff on whether having data with SaaS vendors may leave you more or less secure overall.
I've had a couple of experiences of this over the years and I'll say that generally where I'm seeing data hosted out of the company using SaaS I tend to get less of a feeling of security rather than more.
A couple of reasons for this. Using SaaS adds complexity to areas like leavers/movers/starters procedures as there's another notification point for these, and as we know most companies aren't perfect at leavers policies, so you can introduce risks that people who have left can still get access to company data.
Also there's no really good way to easily assure the 3rd parties security. As Hoff alludes to, a lot of companies think SAS70 == Security, which just ain't the case (although it can be useful for getting assurance over the performance of some security related procedures). So you're left with either engaging in a lengthy assurance process which probably isn't practical if you have a lot of SaaS vendors, or relying on a combination of Pen Test/SAS 70/contract.
Of course, this is complicated even more where the SaaS vendor outsources some of their functions like site hosting, as then you have hierarchies of trust with each agent having similar difficulties in trying to assure the security of the companies they rely on.

Handy Footprinting/research tool

Came across a tool that should help make light work of the research phase of a penetration test today. Paterva Evolution.
Essentially seem to be a nice graphical way of establishing connections related to a specific resource. So for example, any email addresses that are findable relating to a given domain name.
Of course that kind of research can be done manually, but this is an awful lot slicker!

Back and RoraScanner

Well I'm back from (sometimes) sunny shetland. Thanks to some rain and a laptop I'd taken I got some work done on a tool I've started developing for my SANS GSOC gold paper.
RoraScanner is a Oracle 10G security scanner written in ruby. I'm enjoying writing it at the moment as it's let me develop my ruby skills and my oracle skills at the same time.
Hopefully it'll also become a reasonably useful security scanner!

Away for a bit

well like some others in the security blogosphere I'm off on my holidays for the next couple of weeks to lovely shetland. Nice place, but not renowned for the density of it's Wi-Fi hotspots so I'll probably be offline for a bit...

More random thoughts on OWASP

Matasano Chargen Random Thoughts On OWASP
One of those times when I start writing a comment on a post and end up rambling for so long that it ends up being worth a post...
--
I'll chime in on the OWASP needs some staff line. I know they've got loads of great people running it but I reckon they could benefit from some people to focus on specific areas of OWASP.
A good example.. the website. Wikis are great for some types of site and information but personally I think that finding things on the current OWASP site is harder than it should be.
The only way that I've found to tell what's happening on the site seems to be to look at the wiki recent changes list, which isn't a very user friendly experience.
Also some of the great information that is on there is not well flagged up. An example would be this page which has a really cool list of web app. security stuff but I only found it digging through the diffs, usually I wouldn't think to go into a specific chapter to find that.
Another example, where I think a permanent staff member would be useful, is administering the SPOC projects and chivying the people assigned to them for updates.
Right now it's rapidly turning into a summer/autumn of code not spring ;o) . the status page that's gone up has all the projects at 0% complete !
All In all I think OWASP are doing some great work, a lot of which may be less appreciated 'cause it's not as discoverable as it could be....

Comments and Trackbacks off...

I've had to switch comments and trackbacks off on the blog at the moment. Turns out that my little converted NAS box that I've moved over to is great at static content but not so good a CGIs, so when comment/trackback spammers hit it a lot it overheats!
Going to look into maybe moving the blog to a hosted solution, so hopefully get all back to normal when that happens...
Edit: I've tried something which *may* sort the problem so comments back on for now...

Moved Again..

I've had the blog running in a virtual machine for a while since the power supply on my server blew, but that's it back onto dedicated hardware now..
In fact it's a nice little debian server using a Buffalo Linkstation Pro reflashed with FreeLink.
Pretty good deal as you get a perfectly good linux server based on a 130 pound piece of hardware. I've got two of them running now, one as a web server and one as a file/print server. There a lot smaller an quieter than running full-tower cases in the office!