Duane's profileDuane's spacePhotosBlogListsMore ![]() | Help |
Duane's space |
||||||||||||||||||||
|
March 28 Smartgrid Security?I almost titled it Smartgrid Insecurity, but that’d be too cliché and I can’t have that now, can I? There’s been quite a bit of discussion on the vulnerabilities that exist in newer smartgrid technologies, and I agree that many of them need to be worked out before a large scale deployment here in the US. My bigger concern is the lack of talk around the lifecycle management of vulnerabilities within the smartgrid system. Anyone who’s worked in security for more than 3 hours can tell you that all code (and most hardware for that matter) will be subject to some form of security vulnerability at some point, simply because people aren’t perfect, and people write code and design circuitry. What I want to see is that those working on the development of this new tech are thinking about this issue and building in some form of system to manage these issues. Has a unified patch management system been developed to fix problems when they’re discovered 10 years from now? What kind of instantaneous mitigation plans are being built in to stop the new smartgrid worm from spreading when that vulnerability is found by a terrorist or enemy of some type. How do we contain the spread to a few blocks instead of a few hundred? We all know the vulnerabilities and attacks will be there, the question is: How will we respond? March 18 IT Definitions, Goals, and Mass ConfusionI’ve come to realize lately that people tend to set goals for projects, teams, metrics etc. without thoroughly defining the terminology being used in the goals. This tends to lead to confusion or ambiguity in what data is needed to generate the metrics or what steps are required to meet the project goals. Independent workstreams using different processes generated from the central (undefined) goals seem to radically amplify the problem. Some of my recent experiences have amplified the importance of process and definition for me. The scariest part of this is that I feel like I’m rapidly becoming more academic and/or pointy haired in my thought process as I work with these situations more and more. I just left academia less than two years ago… what’s wrong with this picture? Alright, that’s my venting for the evening. I’m gonna pour a pint or two now. Because I love security AND beer! Cheers. March 14 New Awesome BeersSo, I recently purchased some overly expensive beers, because I felt like being stupid. But in the end I think I got to try some really neat, new, and interesting beers. And if you know me, you know how much I love beer! Here’s some notes I jotted down, and pictures I took. Avery Brewing and Russian River Brewing - Collaboration not Litigation batch #2 Russian River Brewing - Consecration Lost Abbey Brewing - Red Poppy New Belgium Brewing - Lips of Faith These are a couple more common beers that I picked up at my local BevMo! tasty nonetheless. Eel River Brewing - Triple Exultation Lost Abbey Brewing - Avant Garde Ale So, I intend to keep jotting down notes on beers, as I think it’ll be useful when it comes time to open the pub, which likely won’t be for another 10 years at least. I’m actually contemplating building a web application to automate and standardize some of this, it’d be more of an exercise to teach myself some LAMP techniques, and learn a bit about web application design. February 24 Holy Hell. Music Win.I love it when multiple good things happen at once… I blogged several months ago about all of the albums coming out that I was stoked for… well two of those (the two I was most excited about) now have titles, release dates, and tours planned… and the bands will tour together! Dredg - The Pariah, The Parrot, The Delusion: Release date (05/19/2009) From Monument to Masses - On Little Known Frequencies: Release date (03/10/2009) Even better, the two bands are playing together on a tour coming up! Unfortunately I see no California tour dates yet… Oh well, they’ll end up back home at the end I’m sure. If you’re outside of California, see them. If you’re up in the bay you can catch FMTM at Bottom of the Hill in The City. Also, musicians using Twitter win. https://twitter.com/leliabroussard <- welcome to the twitterverse Lelia February 22 Dell Mini 9So I just got this Dell Mini 9 a few days ago, and I’ve decided that I love it! With a one minor exception of course… the damned apostrophe/double quote key is way down bottom, so I occasionally hit enter and send messages on accident… I optioned it up from the base, though as a friend so kindly pointed out I really should have gotten the 64GB SSD instead of the 32GB. Originally I’d only intended this to be a dual booting (Ubuntu and Win7) system, then I was shown the OSX install guide for Dell Mini 9’s… sigh. I’ll live with only two OSes for now… But yeah, I optioned it up to a 32GB drive and plan to add a 16 GB SDHC card for data storage soon, it’s got 2GB RAM in it and runs Windows 7 with Aero features like a champ! The portability of the device is awesome, makes a great RSS and e-mail device! My one other disappointment was that Dell switched the integrated WiFi from an Atheros chipset early on to a Broadcom one now… So a lot of wireless tools like Netstumbler don’t work, well… at all. I think I’m going to look for a different card to swap in… Metasploit takes about 10 years to load up as well (decompression doesn’t appear to be the Atom’s strong suit…) I’ll probably migrate from the Mini Ubuntu release from Dell to a real one in the future, as Dell doesn’t seem to maintain their repositories as well (Firefox is still out of date) nor do they include all of the packages you’d find in a full release. Installation of Windows 7 via USB is extremely easy and quick, again in this case noting the decompression of the WIM image due to the Atom inside… and of course as mentioned in my Vista tools posting, EasyBCD get’s the Windows bootloader working well with all OSes (one minor tweak I had to make, I’ll blog on later…) Okay, enough for now… I just did my first blog entry on a netbook! Several interesting blogs worth following in the security space
|
|||||||||||||||||||
|
|