Monday, March 09, 2009

SANS 2009: MGT 525

I'm just back from SANS 2009 in Orlando (#SANS2009).  I took MGT525 -- yes, the project management class -- with Jeff Frisk.  I signed up for the class because it is a required component of the degree I am working on.  I had actually heard some negative things about the class, so I was dreading it just a little (sorry Jeff).  But, I'm pleased to report that I found it incredibly useful.  I have been running large projects (large information security projects) for awhile, but I haven't really ever had any formal PM training.  We have a Project Management Office, and they provide guidelines and templates, and I know what a WBS and Gantt chart are for, but I didn't really know the "proper" way to go from one step to the next.

My eyes were opened when we worked through labs on taking the WBS and producing a precedence diagram to figure out the actual critical path -- including identifying what activities had how much float time.

Now project management seems much less like art and more like science.  This makes me happy.

Thanks Jeff!

Wednesday, December 31, 2008

MD5 Considered Harmful Today or Don't Put Too Much Faith in PKI

A group of 7 security researchers from the United States, Switzerland, and the Netherlands has released details of an exploitation ("MD5 considered harmful today") in the now well-known MD5 Hash Collision vulnerability that would allow a rogue web site to issue a rogue SSL certificate... as well as a rogue signing certificate that is trusted by a valid root Certificate Authority.

Putting that all into English (or at least non-geekspeak):

"Secure" web sites can be impersonated by evildoers, even with the cute little lock icon and a completely "valid" certificate as far as your browser is concerned. This web site could be your bank.

The paper discusses countermeasures, mostly aimed at Certificate Authorities (CAs) and browser vendors. One thing you can do is look at your certificate chain for critical sites to see if MD5 is used by the CA's signing certificate.

The Mozilla developers are already working on a patch for Firefox, et al.:
https://bugzilla.mozilla.org/show_bug.cgi?id=471539


--john

Sunday, October 05, 2008

We cannot let this man be elected as President

I am appalled. If John McCain has done even one tenth of the things listed in this Rolling Stone article, we cannot let him take the office of the Commander in Chief:

http://tinyurl.com/3oje6n

Update:
Scary. Someone actually went to the trouble of breaking the above URL. Here is the new one:

http://tinyurl.com/mcmaverick

Or, just google for "mccain maverick rolling stone".