Showing posts with label humor. Show all posts
Showing posts with label humor. Show all posts

Thursday, April 29

Steve Jobs on Flash

A little off-topic for Identity Management, but once a year or so I post something just for amusement.

In Jobs' open letter on why Apple doesn't support Flash, he makes some valid points. Among them, he states:

We strongly believe that all standards pertaining to the web should be open. Rather than use Flash, Apple has adopted HTML5, CSS and JavaScript – all open standards.
and

HTML5, the new web standard that has been adopted by Apple, Google and many others, lets web developers create advanced graphics, typography, animations and transitions without relying on third party browser plug-ins (like Flash).
So, then, what's wrong with this picture?


Hint: click to enlarge and notice the message:
This website wants to run the following add-on: 'Quick-Time' from 'Apple, Inc.'

Perfect.

Tuesday, February 23

"Automated Provisioning Machine" (in quotes)

I like the cartoon at this Imanami blog entry. It's funny and makes a clear point about identity management (provisioning) solutions. I'll let them make the point rather than re-write it here. But like the old cliche says, a (moving) picture is worth a thousand words.

Wednesday, June 24

Online Identity Privacy - Users Don't Take Precautions

One of my tenets for online privacy is:
Don't do anything online that you absolutely want to keep private.
Case in point:

I was looking through the form submissions to my company's web site. There is consistently some percentage of submissions that are auto-submitted SPAM. Sometimes, it's obvious and sometimes not.

Today, I was researching one submission and googled her name and email. The search brought me to a page that listed a spreadsheet of form submissions to another site - complete with names, email, phone numbers, and comments. Some obvious spam, but others obviously real.

They're showing up because of a technical glitch or security issue on the site. The google search brought me directly to the site's administrative page with no logon.

What makes this story interesting is that the site is a Las Vegas escort service and some of the form submissions read as follows:
  • From a student (@uwec.edu) - "very interested"
  • From a student (@wvu.edu) - "I need a price on ____"
  • From someone claiming to work at Microsoft - "Hi, I'm planning a trip to Vegas with my fiance but I wanna get away from her for one night. What is the limit to your services and who would you recommend? I need a girl with _____. Thank you for your time." (how polite) ...he may not have put his real company, but another quick search found his email address with a profile telling me that he lives in Seattle(!)
  • From a Web Developer in MN - "I am interested in an escort to accompany me to dinner" - (I found his LinkedIn profile because he provided his real company name)
...you get the idea.


Two lessons:
  • First, the obvious one - don't trust web sites to keep your information private.
  • Second, (to the security practitioners who read this blog) - don't underestimate how willing people are to give up their personal information to even the most suspect organizations.

btw - Who thinks this privacy breach will be reported?

Thursday, March 12

Sara: I’m sort of a hero

In addition to keeping up with general topics, there are a number of specific blogs that I try to stay on top of. One is CSI's Security Provoked. where Sara Peters just posted two entertaining stories about how her work in security has left her less secure. I can relate.

Last night, I wasted four hours manually removing a virus that I pretty much knew would come back, but I had to try just to see if I could identify the how-to. (Kudos to Microsoft for XP's restore feature building a restore point without me having to enable it.)

If you've ever purposely went to a phishing site or intentionally opened an email attachment that you knew was malicious, you might want to give it a read. And next time it goes bad, just remind yourself that you're sort of a hero.

...and good job Kristen pushing Sara to deliver the goods!

Friday, November 21

Identity Management is Like Watching Paint Dry

This from a Dark Reading article titled Identity Management: Low On Excitement, High On Payback.

On the humorous side, twenty one percent of respondents in an Imanami research report found managing Active Directory to be more boring than filling out expense reports. (It's great that they even included that option in the survey - it could be fodder for OfficeSpace 2?)

On the serious side (from the research):

5.8 person-hours per 1,000 users is spent during a typical week on updating or otherwise managing groups in Active Directory.

81% of respondent organizations manage groups manually, while 55% use scripts and 34% use some sort of automated solution.

And back to the article:

"User provisioning and multifactor authentication are two projects you should keep if you are thinking about cutting back," said Forrester Research's Andras Cser about identity management today. "These are areas where there's a real opportunity to increase efficiency and cost savings."

42% of organizations report that someone has accessed information from Active Directory that they were not authorized to access.

This issue becomes even more acute during difficult financial times, when employees may become disgruntled following layoffs or pay disputes, experts noted. During such times, the ability to quickly provision and deprovision employees may play an important role in the enterprise's overall security, they said.

I've talked about the motivations behind Identity Management projects before, but I wasn't accounting for the current economic climate. There's definitely an argument to be made that the pendulum is swinging back toward cost savings as the prime mover of Identity projects.

Friday, September 12

DIDW 2008

I saw, heard, and did a lot of interesting things this week at DIDW in Anaheim.

First, thank you Ping Identity for a good mid-week party at the HoB. (We should all publicly thank Ping and give them reason to continue hosting such events.)

We had a bloggers meet-up, though you won't hear too many others talk about that (maybe Ash). I did get to meet a number of folks who I've only previously met online. And I had many good conversations.

I heard more about the consulting (and other) capabilities of companies like Identropy, CoreBlox, and Optimal IdM – all worth a conversation if you need some Identity consulting help. And each has unique strengths. I wonder if you would all benefit from some kind of cooperative network rather than having the perception of competition. I'll have to think about that.

We gave away a lot of sticky eye balls. One became known as the eye in the sky.

I learned about important things like:
And heard a lot of interesting discussions and tidbits, including:
  • The US Treasury Dept transfers more than $1 Billion each day via PKI
  • There seems to be consensus that enterprises will be affected by market forces on consumer identity and Web 2.0. ...perhaps TPS reports will be replaced by Twitter.
  • Searching on "Identity Management" has declined throughout 2006, 2007, and 2008. My own research reveals that searching on "Microsoft", "Oracle" and "Active Directory" have all declined at a similar rate. So, it may mean nothing.
  • One interesting case for synchronization vs. virtualization: If you front-end data that you don't own (and therefore can't control), you should replicate data and sync rather than using a totally virtual approach. It sounded like someone learned that the hard way.
  • Not all Virtual Directories are created equal. I heard a panelist ask vendors for a feature that I know exists in at least two Virtual Directory products.
  • Virtual Directories might be able to fill a gap in the real-time link between physical and logical security (grant access only when employee is swiped in).
On the flight back, a crazy thing happened. I heard a horrible scream outside the window of the airplane and when I looked outside, I saw something that seemed to be flying past us at a close distance. I quickly grabbed my camera and got a shot of it. (OK - you probably had to be at DIDW to appreciate that.) If you weren't, use this short waste of your time as inspiration to go check out Symplified and see what they're doing with SaaS-based Web Access Management. Pretty cool stuff. Their model removes a lot of the pain that gave Identity Management a bad name in its early days. And no, that's not Che.

I guess that's it for my DIDW update. For now.

Sample A. Sample

I just got an email from my credit card company offering an indulgent golf getaway. It's a cross-marketed card from a hotel chain and financial org with points, rewards, etc.. The email was addressed to:

Sample A. Sample

I realize that was probably human error, but with all of the cross-brand marketing that's happening, it's a shame that they didn't look at my past history to see that:

- I don't golf very often (I've never used this card for anything Golf related)
- I spend most of my rewards points on electronics

We talk a lot about privacy, but there is some value in these two companies looking at the information I have already given them to provide a better product for me. At a minimum, though, get my name right.

Sincerely,
Sample A. Sample

Friday, August 22

Criminal Data Loss

Seems like some people just aren't paying attention. Every time I think we've gotten past a point as an industry, someone proves me wrong. I would think by now we wouldn't be carrying very large highly confidential data sets on unencrypted USB sticks.

Can you imagine how the exposed data on 130,000 criminals will be used? I'm sure someone would find a way to monetize a list like that. I can see a few angles:

----

SUBJECT: WORK FROM HOME!!

Dear _____,

Why break into homes and cars when you can steal from the comfort of home?!? Try our latest web site phishing kit and collect credit card information from unsuspecting shoppers. No black ski masks, no up-front discovery work, and no commute!

----

Or maybe...

----

ATTN Hiring Manager:

Are you having trouble staffing up for your next big heist? Contact CriminalTemps where we can provide full or part time criminals. 100% no-police guarantee!!

Thursday, April 17

Bulletproof Identity Process

(file under stupid humor)

I forgot to mention, there was one company in San Francisco last week who really knows how to implement a bulletproof identity authentication process. But, they weren't on the expo floor. They weren't even at the Moscone.

This is an actual photo from the back of my hotel room door. They really get it. Just call "operator" for assistance.

Thursday, March 13

Overheard in the Cube Farm...

Do any of the techies in your company choose Pizza Over Process?

And how can a 12 oz. can of soda bring down your entire provisioning process? Find out in You Owe Me a Soda.


...and we aren't joking when we say Based on a True Story. Sad but true. Have you overheard these conversations? Got a better one?

Friday, September 14

Identity Cartoon

A little identity humor for your viewing pleasure...

identity cartoon