<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/"
     xmlns:pp="http://www.presspage.com/rss/"
     version="2.0"
     xmlns:atom="http://www.w3.org/2005/Atom">
                <channel>
                    <title><![CDATA[Silicon Valley Watcher]]></title>
                    <link>https://www.siliconvalleywatcher.com/</link>
                    <description></description>
                    <language>en-us</language>
                    <lastBuildDate>Tue, 08 Sep 2026 01:38:44 +0200</lastBuildDate>
                    <pubDate>Mon, 11 Mar 2019 21:30:49 +0100</pubDate>
                    <image>
                        <title><![CDATA[Silicon Valley Watcher]]></title>
                        <url>https://content.presspage.com/clients/150_2054.jpeg</url>
                        <link>https://www.siliconvalleywatcher.com/</link>
                        <width>144</width>
                    </image><item>
                        <title>The Dismal Nature Of The Cyber Security Industry ... And Other RSA Conference Notes</title>
                        <link>https://www.siliconvalleywatcher.com/the-dismal-nature-of-the-cyber-security-industry--and-other-rsa-conference-notes/</link>
                        <guid>https://www.siliconvalleywatcher.com/the-dismal-nature-of-the-cyber-security-industry--and-other-rsa-conference-notes/</guid><pp:caseid>325746</pp:caseid><pp:subtitle>Leon Panetta&#039;s nightmare; Cyber-currencies are boosting cybercrime; Jobs for life; Outsourcing security to the cloud</pp:subtitle><description><![CDATA[<p><img alt="" src="//content.presspage.com/uploads/2054/rsa2019-401392.jpg?x=1552335932202" style="width: 840px; height: 630px; margin: 5px; float: left;" /></p>

<p><strong>Walking around the giant show floor at RSA I was struck by a thought: what a dismal industry this must be.&nbsp;If you are good at your job, you haven't created any new technology that makes processes more productive, or could be used to create new types of products --&nbsp;you plug up the holes in the bucket that are known. You cannot reliably stop future attacks -- only the ones that are known. And all that work and cyber crime continues to grow and prosper.&nbsp;&nbsp;</strong></p>

<p>The cost of cyber crime is the loss itself-- predicted to be $6 trillion a year in 2021 -- plus the cost of buying the cyber security needed to bolt the stable door &mdash; plus all the engineers involved in developing the software, and then on the customer side implementing it,&nbsp; all the sales people, field&nbsp;support staff, marketing,&nbsp; VCs, etc.</p>

<p>It all seems such a dismal waste of human energies that could be used for other things rather than trying to frustrate computer hackers who seem to have no problem getting around those brilliant defenses and gallant efforts.</p>

<p><strong>SECURING THE NEWS</strong></p>

<p>Leon Panetta, the former Secretary of Defense and former Director of the CIA is an Oracle board member. Speaking at an evening RSA related event he said that&nbsp;attacks by nation state hackers is a huge problem. "Pay attention. National defense is not just the responsibility of government, everyone has a role."</p>

<p>His biggest nightmare is of a computer virus that attacks and disables US infrastructure. He estimates that such an attack&nbsp;could result in millions of lost lives -- it would be a digital Pearl Harbor.&nbsp;&nbsp;</p>

<p>He warned that Russian and Chinese state financed hackers are starting to work together and share technologies to produce sophisticated cyber weapons.</p>

<p>Panetta also warned about&nbsp;attempts to divide US society -- a reference to fake news in elections. But fake news is in the realm of&nbsp;cultural hacking.&nbsp; A meme acts like a computer virus but it cannot be stopped with the same cybersecurity tools. I asked him if there were any defenses developed by US agencies against fake news but he shook his head saying it was a different class of problem.</p>

<p><strong>CYBERCURRENCY BOOSTS CRIME</strong></p>

<p>Oded Vanunu runs a team of more than 200 people researching product vulnerabilities for Checkpoint. He says that nation states are well ahead of the cybersecurity industry in terms of discovering new vulnerabilities. There's no talent shortage here. He says the governments pay well for the best talent and they have developed very sophisticated attack technologies. He believes that malware might already be implanted in many different places and could be triggered by a code.&nbsp;</p>

<p>"There are also many online markets that will pay people huge sums of money if they discover a vulnerability. Plus the rise of cyber-currencies makes it easy for criminals to hide their money," are fueling cybersecurity losses. Vanunu says the industry is behind and needs to catch up.&nbsp;</p>

<p><strong>JOBS FOR LIFE</strong></p>

<p>John Chambers, the former CEO of Cisco is now a venture capitalist. He said computer security professionals had nothing to worry about from job losses due to AI and other technologies. He predicted that at least 30 million jobs would be lost over the next ten years. He said the problem with cybersecurity is that CEOs don't know if they have spent enough money on protection and they don't know how much protection they have bought. One of his startups is helping companies figure out this question.</p>

<p><strong>CLOUDY SECURITY ISSUES...</strong></p>

<p>Oracle and KPMG released their "<a href="https://www.oracle.com/a/ocom/docs/dc/final-oracle-and-kpmg-cloud-threat-report-2019.pdf?elqTrackId=063c9f4a2a5b465ab55b734007a900f0&elqaid=79797&elqat=2">Cloud Threat Report 2019</a>" and one of the many interesting discoveries was that cloud users seem to misunderstand their security risk.</p>

<p>The use of cloud-based IT has been boosted by the complexity of the security architectures and the difficulties in keeping up with the fast patching pace of new vulnerabilities.&nbsp;The report found that 73% believe the cloud offers better security than they can provide in-house.</p>

<p>But cloud users need to read the fine print because according to the report they don't all understand that security is a shared responsibility.&nbsp;</p>

<p>"Confusion around the shared responsibility security model has resulted in cybersecurity incidents. A lack of clarity on this foundational cloud security construct has had real consequences for many enterprises, including the introduction of malware and loss of data."</p>

<p>&nbsp;</p>]]></description><category><![CDATA[TechnologyWatch,Take,Security]]></category>
            <pubDate>Mon, 11 Mar 2019 13:30:49 -0700</pubDate>
            <enclosure url="https://content.presspage.com/uploads/2054/500_rsa2019-401392.jpg?10000" length="0" type="image/jpg" />
                <pp:image>https://content.presspage.com/uploads/2054/500_rsa2019-401392.jpg?10000</pp:image>
                <pp:imageOriginal>https://content.presspage.com/uploads/2054/rsa2019-401392.jpg?10000</pp:imageOriginal><pp:imageTitle><![CDATA[RSA2019]]></pp:imageTitle></item><item>
                        <title>Cybersecurity Costs - An Unsustainable Tax On Business</title>
                        <link>https://www.siliconvalleywatcher.com/cybersecurity-costs---an-unsustainable-tax-on-business/</link>
                        <guid>https://www.siliconvalleywatcher.com/cybersecurity-costs---an-unsustainable-tax-on-business/</guid><pp:caseid>238961</pp:caseid><description><![CDATA[<p><img style="display: block; margin-left: auto; margin-right: auto;" title="RayRothrock-0004.jpg" src="https://s3-eu-west-1.amazonaws.com/presspage-production-content/uploads/2054/RayRothrock-0004.jpg" alt="RayRothrock 0004" width="639" height="387" border="0" /></p><p>The cost of cybersecurity has become a burdensome tax on business and with 1.5 million IT security jobs unfilled, US corporations are losing to sophisticated criminal gangs, said security experts at a recent event in San Francisco.</p><p>"Cyber is a tax on business. Jamie Dimon [JP Morgan Chase CEO] has had to double his cybersecurity budget to $500 million. Things can't continue this way forever, we have to get ahead of the problem," said Ray Rothrock (photo), a veteran VC, now chairman and CEO of <a href="https://redseal.co/">RedSeal</a>, a startup that measures the effectiveness of enterprise security.</p><p>He said that the size of the problem and the opportunities are what lured him out of retirement in early 2014 to run RedSeal. He made 53 startup investments including "over a dozen" in cybersecurity when he worked at VC firm Venrock.</p><p>JP Morgan Chase last year <a href="http://www.wsj.com/articles/j-p-morgan-to-accelerate-timeline-for-cybersecurity-spending-boost-1438641746">doubled</a> cybersecurity budgets to $500 million and expects to spend the same amount this year. The financial services giant had a bad computer security breach in 2014 when 76 million household accounts -- two-thirds of all US households -- were compromised.</p><p>Chris Webber, security strategist at ID security startup <a href="https://www.centrify.com/">Centrify</a> said there are1.5 million IT security jobs unfilled. It shows the size of the problem and that the criminals are winning. </p><p> "There are new security risks such as Apple's recent decision to speed up approval for software in its app stores. Will this let more malware escape scrutiny?" asked Domingo Guerra, co-founder and president of <a href="https://www.appthority.com/">Appthority</a>, a startup that monitors mobile apps for data risks in the enterprise.</p><p>Dwayne Hall, CEO of startup Opaque Communications, said his company is working with government security agencies on a way of preventing some people downloading its technologies for secure and untraceable messaging. "If they are on any watch lists then they could be blocked from downloading our software," Hall said.</p><p>Andy Grolnick from <a href="https://logrhythm.com/about/">LogRhythm</a>, a startup that analyzes data to spot security risks from within, said that companies cannot rely on perimeter defenses and that spotting criminal behavior relies on being able to normalize massive amounts of machine data.</p><p> Foremski's Take: Is enterprise security achievable? I could buy everything at the annual RSA Data Security show and still not feel secure. There are countless new exploits being discovered, which means they could have been exploited for a long time before.</p><p>Add the fact that large enterprises don't know the location of all their sensitive data and therefore can't protect it or even know if it has been breached. Cybersecurity is a mess. </p><p>Buying things online used to be a one-click process but that was many years ago. Additional security checks of different types make buying things online a chore and certainly not the frictionless experience we were promised.</p><p>Anything that disrupts the consumer experience is ultimately a danger to the entire economy of society. Ray Rothrock at RedSeal is right: we have to get ahead of the problem.</p>]]></description><category><![CDATA[A Top Story,Security]]></category>
            <pubDate>Thu, 04 Aug 2016 02:40:42 -0700</pubDate>
            <enclosure url="https://content.presspage.com/clients/150_2054.jpeg?10000" length="0" type="image/jpeg" />
                <pp:image>https://content.presspage.com/clients/150_2054.jpeg?10000</pp:image>
                <pp:imageOriginal>https://content.presspage.com/clients/150_2054.jpeg?10000</pp:imageOriginal><pp:imageTitle><![CDATA[logo]]></pp:imageTitle></item><item>
                        <title>Enterprise Security: The Easiest Hacks Are The Toughest To Stop With Technology</title>
                        <link>https://www.siliconvalleywatcher.com/enterprise-security-the-easiest-hacks-are-the-toughest-to-stop-with-technology/</link>
                        <guid>https://www.siliconvalleywatcher.com/enterprise-security-the-easiest-hacks-are-the-toughest-to-stop-with-technology/</guid><pp:caseid>238980</pp:caseid><description><![CDATA[<p><img style="display: block; margin-left: auto; margin-right: auto;" title="Corporate700 (1).jpg" src="https://s3-eu-west-1.amazonaws.com/presspage-production-content/uploads/2054/Corporate700 (1).jpg" alt="Corporate700  1" width="639" height="425" border="0" /></p><p><em>The challenge of protecting the enterprise from simple email phishing scams.</em></p><p>There’s no need to use advanced Black Hat technologies to get access to sensitive corporate data if you have a copy of a staff directory — as more than 21,000 employees of Sprouts supermarket chain found out recently. All had their social security numbers and other personal details exposed after an employee in the payroll department responded to an email from what looked like a senior executive asking for a copy of every employee’s W2. </p><p>All of the Sprouts employees now face many years of anxiety over hackers patiently waiting to use and abuse their illicit data haul of taxpayer identities.</p><p> <strong>Doug Oleic, at SC Magazine</strong> says that <a href="http://www.scmagazine.com/w-2-data-breach-places-21k-sprouts-farmers-market-employees-at-risk/article/485044/">many others</a> have fallen for a similar trick, </p><blockquote><br /><p>Sprouts joins Seagate, Snapchat and several other high profile firms that have been hit with a similar attack. Security executives all pointed out the difficulty of preventing socially engineered phishing attacks…</p></blockquote><br /><p>At first look it would seem that there is no technical solution to such socially engineered data breaches beyond educating staff about such nefarious techniques. Even then, phishing has becoming a lot more sophisticated, making it even harder to distinguish a scam from the real thing. </p><p><strong>Here’s some views from two security experts:</strong></p><p>Jonathan Sander, vice president at <a href="http://www.liebsoft.com/">Lieberman Software</a>: </p><p>"You will never stop phishing, nor will you make perfect humans who are never fooled by bad guys in some way. What you can do is say that when systems are asked to give people extraordinary privilege to access sensitive information, those systems should be made smart enough to put a check on that power.” </p><p>Brad Bussie, director of product management at <a href="http://www.stealthbits.com/">STEALTHbits Technologies</a>: </p><p>“As a best practice, personal identifiable information should never be transmitted in an un-encrypted format. You want to ensure the integrity and confidentiality of the data related to employees at all times.”</p><p><strong>Bussie warns that Sprouts employees will likely face years of problems from the “Dark Web.”</strong></p><p>"Studies show that the dark web will often light up initially when a company has been compromised, but will then go dormant for a year or more. You will then see a massive resurgence of global hackers buying leaked data under the assumption that a year of scrutiny has expired and they can get to work capitalizing on the stolen information."</p><p>The IRS recently reported a massive 400% jump in phishing and malware disguised as its own official communications. It estimates <strong>tax fraud will reach a record $21 billion in 2016</strong> - compared with $6 billion in 2014. </p><p>Digital data plus online tax returns enables criminals to engage in fraud on a national scale compared to filing individual paper based tax returns. </p>]]></description><category><![CDATA[A Top Story,Security]]></category>
            <pubDate>Thu, 24 Mar 2016 07:32:41 -0700</pubDate>
            <enclosure url="https://content.presspage.com/clients/150_2054.jpeg?10000" length="0" type="image/jpeg" />
                <pp:image>https://content.presspage.com/clients/150_2054.jpeg?10000</pp:image>
                <pp:imageOriginal>https://content.presspage.com/clients/150_2054.jpeg?10000</pp:imageOriginal><pp:imageTitle><![CDATA[logo]]></pp:imageTitle></item><item>
                        <title>Data Masking Saves CIO Jobs And Makes IT Heroes</title>
                        <link>https://www.siliconvalleywatcher.com/data-masking-saves-cio-jobs-and-makes-it-heroes/</link>
                        <guid>https://www.siliconvalleywatcher.com/data-masking-saves-cio-jobs-and-makes-it-heroes/</guid><pp:caseid>239078</pp:caseid><description><![CDATA[<p><img style="display: block; margin-left: auto; margin-right: auto;" title="Halloween-3.jpg" src="https://s3-eu-west-1.amazonaws.com/presspage-production-content/uploads/2054/Halloween-3.jpg" alt="Halloween 3" width="639" height="425" border="0" /></p><p>Working at <a href="http://www.delphix.com/? utm_source=SVW&utm_medium=social&utm_campaign=delphix" target="_blank">Delphix</a>, a virtual technologies startup in the heart of Silicon Valley, I've been learning a lot about enterprise software and the challenges facing global corporations as business becomes ever more digital. </p><p>Data security is critical and its importance was underscored by the recent RSA Conference in San Francisco -- the world's largest gathering of computer security experts. About 40,000 people -- a jump of nearly 20% compared with last year -- attended its awards ceremonies, hundreds of presentations, and demonstrations from thousands of vendors of data protection technologies.</p><p>But if you bought everything at RSA would your organization be completely secure? </p><p>Likely not -- you will always need to buy something new. This is troubling, especially if your job security relies on effective data security.</p><p><strong>Computer security and CIO job security</strong></p><p>A <a href="http://www.actian.com/about-us/blog/the-results-are-in-from-our-huhdoop-project-big-data-and-hadoop-need-help/" target="_blank">2015 study by Big Data company Actian</a> found that 43 percent of CEOs said they would fire their Chief Information Officer or Chief Technology Officer (CIO/CTO) in the event of a significant security event.</p><p>But with so many high-profile data breaches lately, even those with large IT budgets haven't been able to spend enough, or choose the right technologies to protect their organization.</p><p>And current trends don't bode well for CIO job security because they increase the risk of a major data breach. For example, the rush by global enterprises to develop more applications is particularly troubling.</p><p>Application development teams require fresh copies of the production database for testing. Finding bugs early is vital and speeding up application delivery speeds up business initiatives. But every database copy multiplies the risk of sensitive data being exposed in some way.</p><p>Protecting 20 database copies is hard and it is easy to lose track of where they are being used.</p><p>If you don't know where your data is, then you don't know if it has been stolen.<strong> A <a href="http://www.rsaconference.com/press/53/survey-82-of-boards-are-concerned-about" target="_blank">recent survey by RSA and ISACA</a> found that 24 % of computer security professionals had no way of knowing if they had suffered a data loss.</strong></p><p>But there is a solution -- at least for the increasingly common user case of cloning the production database: data masking.</p><p><a href="http://www.delphix.com/solutions/data-masking-solutions/? utm_source=SVW&utm_medium=social&utm_campaign=data-masking" target="_blank">Data masking</a> removes the sensitive data and replaces it with realistic looking social security numbers, credit card numbers, etc. Data replacement would be a more accurate term.</p><p>If hackers get access to a cloned production database that has been data masked then there is no danger of any sensitive data leaking out because it is not there. It is a 100% secure data protection. You cannot steal something that isn't there. </p><p>Encryption is vulnerable to decryption but data masking is irreversible. </p><p>So why is data masking such a poorly understood security technology? Why were there only four companies out of hundreds at RSA, offering data masking? </p><p>Why isn't data masking more widely used to deal with the security issues caused by the epidemic of proliferating database copies? </p><p>I don't have the answers. One answer is that data masking can be hard and labor intensive.  And you have to do it again and again for each copy. The shortcut quickly becomes: skip it. As a CIO it can be a shortcut to losing your job but the pressure to support key business initiatives is high. </p><p><strong>Data protection is often juxtaposed against business innovation.</strong></p><p>Gartner <a href="http://www.gartner.com/technology/topics/information-security.jsp" target="_blank">warns</a>,</p><blockquote style="margin: 50px 0px; padding-left: 80px; position: relative; font-style: italic; font-size: 24px; line-height: 38px; font-family: Georgia; color: rgba(0, 0, 0, 0.85098); padding-right: 80px; text-align: center; widows: 1;"><br /><p>Is your information security program a roadblock to business progress?...You must protect enterprise data from compromise and drive innovation at the same time.</p></blockquote><br /><p>CIO Magazine's "<a href="http://www.cio.com/article/3022833/cio-role/state-of-the-cio-2016-its-complicated.html?" target="_blank">State of the CIO 2016</a>" states</p><blockquote style="margin: 50px 0px; padding-left: 80px; position: relative; font-style: italic; font-size: 24px; line-height: 38px; font-family: Georgia; color: rgba(0, 0, 0, 0.85098); padding-right: 80px; text-align: center; widows: 1;"><br /><p>...you [the CIO] are expected to be the driver of enterprise digital transformations. However... you face a wide range of tactical challenges -- from defending against increasingly sophisticated and potentially damaging cybersecurity threats to managing mass cloud migrations to leading agile development projects. </p></blockquote><br /><p>Data protection and driving business goals are not in opposition if you choose the right approach.</p><p><strong>Mask Once -- Copy Many</strong></p><p>By combining <a href="http://www.delphix.com/products/how-delphix-data-virtualization-works/? utm_source=SVW&utm_medium=social&utm_campaign=delphix" target="_blank">data masking</a> with <a href="http://www.delphix.com/products/how-delphix-data-virtualization-works/? utm_source=SVW&utm_medium=social&utm_campaign=delphix" target="_blank">data virtualization</a> you only need to mask one database copy-- then you can create <em>unlimited</em> virtual copies  -- or let the app dev teams do it themselves with the self-service user interface.</p><p>That's the unique <a href="http://www.delphix.com/? utm_source=SVW&utm_medium=social&utm_campaign=delphix" target="_blank">Delphix</a> approach: mask once - copy as many times as you want while keeping data fresh. It's a true Data as a Service technology - data where it's needed on demand.</p><p>By allowing developers to self-service their test environments in minutes compared with hours or days,  application delivery can be accelerated by as much as a factor of ten. Data security with faster app delivery is a killer combination.</p><p><a href="http://www.delphix.com/solutions/data-masking-solutions/? utm_source=SVW&utm_medium=social&utm_campaign=data-masking" target="_blank">Data masking</a> with data virtualization not only saves CIO jobs but also makes them look like IT heroes. </p>]]></description><category><![CDATA[A Top Story,Enterprise IT,Security]]></category>
            <pubDate>Thu, 10 Mar 2016 09:26:09 -0800</pubDate>
            <enclosure url="https://content.presspage.com/clients/150_2054.jpeg?10000" length="0" type="image/jpeg" />
                <pp:image>https://content.presspage.com/clients/150_2054.jpeg?10000</pp:image>
                <pp:imageOriginal>https://content.presspage.com/clients/150_2054.jpeg?10000</pp:imageOriginal><pp:imageTitle><![CDATA[logo]]></pp:imageTitle></item><item>
                        <title>Secure Islands: Protecting Corporate Data As Soon As It&#039;s Created</title>
                        <link>https://www.siliconvalleywatcher.com/secure-islands-protecting-corporate-data-as-soon-as-its-created/</link>
                        <guid>https://www.siliconvalleywatcher.com/secure-islands-protecting-corporate-data-as-soon-as-its-created/</guid><pp:caseid>239167</pp:caseid><description><![CDATA[<p><img style="display: block; margin-left: auto; margin-right: auto;" title="Islands2.jpg" src="https://s3-eu-west-1.amazonaws.com/presspage-production-content/uploads/2054/Islands2.jpg" alt="Islands2" width="613" height="367" border="0" /></p><p><a href="http://secureislands.com/">Secure Islands</a>, a privately held Israeli computer security company, opened its <a href="http://secureislands.com/secure-islands-opens-us-office/">US HQ</a> earlier this year in New York City. The company is confident in repeating the success it has enjoyed in Europe,  here in US enterprise security markets, with its approach to data protection.</p><p>Its technology automatically classifies and if required, encrypts sensitive data upon creation, as opposed to when it leaves the organization, which is traditionally how encryption has been managed.</p><p>This process, which it calls "Data Immunization," enables organizations to set classification polices which are automatically applied when a file or email is created. If encryption is required, the protection stays with the data wherever it ends up.  This way, if it is stolen, no one can read the data except the intended readers. </p><p>I recently spoke with Aki Eldar, co-founder and CEO of Secure Islands. Here are some of my notes:</p><p>- Secure Islands was founded about eight years ago by two brothers. One had skills in sales and marketing in enterprise IT markets, and the other was a software developer.</p><p>- The brothers realized that you can't win against cyber criminals because they always have a head start. Breaking into a computer network, or having sensitive files leaked from inside, will continue to happen no matter how good an organization's perimeter security is.  But, if those files are encrypted and can only be opened by specific people, it no longer matters if the data was lost or stolen, as it will be useless to anyone but its intended recipients. </p><p>- Secure Islands product, called the IQProtector Suite,  is a real-time monitoring technology that will detect [it classifies the content and checks if a security policy applies] data that's sensitive -- as it is being created. It will then encrypt the files and assign user access rights, if a policy applies. It also has a services arm where it can help its customers create data security policies appropriate for their business. </p><p>-Secure Islands also has an audit function and once data is tagged, it can track all of the unstructured data of the organization. </p><p>- Unstructured data is a big problem for organizations because as it moves around an organization and onto a variety of mobile devices, and beyond -- there's a loss of control over sensitive company information. </p><p>- Had Sony used Secure Islands products, it could have prevented the embarrassing emails from executives at Sony Pictures from being leaked with a single policy: "Encrypt all of executive management's emails."</p><p>- Secure Islands says a big part of its success is that it works transparently across platforms and apps, and does not disrupt existing uses.</p><p>-It's important to encrypt the data files at the point of creation, before it gets changed or "tainted."  </p><p>- The technology works with Microsoft's Active Directory for ID management and it uses Microsoft's encryption engine, which is the standard in European financial industry.</p><p>-The protection is persistent as the data is managed over its life cycle.</p><p>- I asked about the need for regulators, lawyers and auditors to be able to access archival business data for a variety of reasons. The company said that because its protection is policy driven, there is no problem complying with all legal and fiduciary data access requirements. </p><p>- Its technology can understand the content and context of the data and index the information. It's too costly to encrypt everything created by an organization, and also unnecessary.</p><p>- Secure Islands received an investment of unspecified amount, last year <a href="http://secureislands.com/secure-islands_cs_next_investors/">from Credit Suisse</a>, one of its first customers. That investment is helping to fund the company's US HQ and marketing push. </p>]]></description><category><![CDATA[Enterprise IT,Security]]></category>
            <pubDate>Mon, 09 Mar 2015 04:38:14 -0700</pubDate>
            <enclosure url="https://content.presspage.com/clients/150_2054.jpeg?10000" length="0" type="image/jpeg" />
                <pp:image>https://content.presspage.com/clients/150_2054.jpeg?10000</pp:image>
                <pp:imageOriginal>https://content.presspage.com/clients/150_2054.jpeg?10000</pp:imageOriginal><pp:imageTitle><![CDATA[logo]]></pp:imageTitle></item><item>
                        <title>A Nevada Developer Creates Fingerprint Wordpress Login</title>
                        <link>https://www.siliconvalleywatcher.com/a-nevada-developer-creates-fingerprint-wordpress-login/</link>
                        <guid>https://www.siliconvalleywatcher.com/a-nevada-developer-creates-fingerprint-wordpress-login/</guid><pp:caseid>238979</pp:caseid><description><![CDATA[<p><img style="display: block; margin-left: auto; margin-right: auto;" title="sec-blog-banner-lay-03.jpg" src="https://s3-eu-west-1.amazonaws.com/presspage-production-content/uploads/2054/sec-blog-banner-lay-03.jpg" alt="Sec blog banner lay 03" width="600" height="338" border="0" /></p><p>I recently received this note from Pablo at <a href="https://www.secsign.com/">Secsign Technologies</a>... It looks like an interesting application especially for the enterprise market where security is a never ending battle. </p><blockquote><br /><p>Sorry for disturbing you, sure you get 1000000 emails per day :-)</p><p>We are a small tech company from Nevada that just released the World´s first fingerprint login for Wordpress, using iOS 8 Beta.</p><p>It's free for beta developers and we also made a tutorial on how to use it: <a href="https://www.secsign.com/fingerprint-validation-as-an-alternative-to-passcodes/">https://www.secsign.com/fingerprint-validation-as-an-alternative-to-passcodes/</a></p><p>We will really appreciate if you can help us, we are small company trying to fight hard. Your help, for us is like the top of the sky, and we will do literally what ever you ask, to have the chance that you write some lines about us. We don't have budget for a professional PR firm, and our future truly depends on getting a bit of help from you.</p><p>- We solved the problem to integrate Apple's Fingerprint with current back-end and IAM systems from corporations, so now any business can use iPhone Touch ID to login in their intranet , etc.</p><p>- We also have a secure storage portal solution and a two factor authentication app and free plugins.</p></blockquote>]]></description><category><![CDATA[Enterprise IT,Security]]></category>
            <pubDate>Fri, 08 Aug 2014 04:09:10 -0700</pubDate>
            <enclosure url="https://content.presspage.com/clients/150_2054.jpeg?10000" length="0" type="image/jpeg" />
                <pp:image>https://content.presspage.com/clients/150_2054.jpeg?10000</pp:image>
                <pp:imageOriginal>https://content.presspage.com/clients/150_2054.jpeg?10000</pp:imageOriginal><pp:imageTitle><![CDATA[logo]]></pp:imageTitle></item><item>
                        <title>NSA&#039;s Crypto-Kids - It&#039;s Never To Early To Start Recruitment</title>
                        <link>https://www.siliconvalleywatcher.com/nsas-crypto-kids---its-never-to-early-to-start-recruitment/</link>
                        <guid>https://www.siliconvalleywatcher.com/nsas-crypto-kids---its-never-to-early-to-start-recruitment/</guid><pp:caseid>239040</pp:caseid><description><![CDATA[<p><img style="display: block; margin-left: auto; margin-right: auto;" title="NSA -2.jpg" src="https://s3-eu-west-1.amazonaws.com/presspage-production-content/uploads/2054/NSA -2.jpg" alt="NSA  2" width="620" height="348" border="0" /></p><p>The National Security Agency (NSA) has lots of computer power but what it needs the most is brain power. It's not too early to plan ahead. A friend gave me a copy of an activity book for kids published by the NSA. Here's a few pages:</p><p><img style="display: block; margin-left: auto; margin-right: auto;" title="NSA -13.jpg" src="https://s3-eu-west-1.amazonaws.com/presspage-production-content/uploads/2054/NSA -13.jpg" alt="NSA  13" width="620" height="1103" border="0" /></p><p><img style="display: block; margin-left: auto; margin-right: auto;" title="NSA -32.jpg" src="https://s3-eu-west-1.amazonaws.com/presspage-production-content/uploads/2054/NSA -32.jpg" alt="NSA  32" width="620" height="1103" border="0" /></p><p><img style="display: block; margin-left: auto; margin-right: auto;" title="NSA -16.jpg" src="https://s3-eu-west-1.amazonaws.com/presspage-production-content/uploads/2054/NSA -16.jpg" alt="NSA  16" width="620" height="1103" border="0" /></p><p><img style="display: block; margin-left: auto; margin-right: auto;" title="NSA -49.jpg" src="https://s3-eu-west-1.amazonaws.com/presspage-production-content/uploads/2054/NSA -49.jpg" alt="NSA  49" width="620" height="1103" border="0" /></p>]]></description><category><![CDATA[Security]]></category>
            <pubDate>Mon, 21 Jul 2014 07:20:48 -0700</pubDate>
            <enclosure url="https://content.presspage.com/clients/150_2054.jpeg?10000" length="0" type="image/jpeg" />
                <pp:image>https://content.presspage.com/clients/150_2054.jpeg?10000</pp:image>
                <pp:imageOriginal>https://content.presspage.com/clients/150_2054.jpeg?10000</pp:imageOriginal><pp:imageTitle><![CDATA[logo]]></pp:imageTitle></item><item>
                        <title>Cyphort&#039;s  ATD Suite Detects Target Malware Variants</title>
                        <link>https://www.siliconvalleywatcher.com/cyphorts--atd-suite-detects-target-malware-variants/</link>
                        <guid>https://www.siliconvalleywatcher.com/cyphorts--atd-suite-detects-target-malware-variants/</guid><pp:caseid>239255</pp:caseid><description><![CDATA[<p><a href="http://www.cyphort.com/">Cyphort</a>, a San Jose, CA, based security firm, this week said it has emerged from stealth mode with the official launch of its <a href="http://www.cyphort.com/products/">advanced threat detection</a> (ATD) platform, which is able to detect malware variants used in the recent Target attack.</p><p>Here’s my notes from a conversation with Anthony James, VP of marketing and product at Cyphort:</p><p> </p><p>- Advanced Threat Detection (ATD)  is based on behaviors rather than signatures because those change all the time.  We can detect malware without needing a signature. By then its too late.</p><p>- We use different types of sandboxing to isolate the threats because advanced malware knows how to protect itself from generic sandboxing.</p><p>- There is a much higher risk from malware today because of rising use of the cloud, the large number of devices people use in the enterprise, and the increased sophistication of malware developers.</p><p>- We are able to classify malware into the serious and the less important. Our customers can focus getting rid of the serious malware first. </p><p>- We also share information with other customers if we find malware and we provide the tools on how to get rid of it. </p><p>- We can tell where the malware is within its life cycle. </p><p>- We ran some tests and we would have been able to have detected the malware used in the Target data theft, and its variants.</p>]]></description><category><![CDATA[Security]]></category>
            <pubDate>Wed, 26 Feb 2014 03:45:43 -0800</pubDate>
            <enclosure url="https://content.presspage.com/clients/150_2054.jpeg?10000" length="0" type="image/jpeg" />
                <pp:image>https://content.presspage.com/clients/150_2054.jpeg?10000</pp:image>
                <pp:imageOriginal>https://content.presspage.com/clients/150_2054.jpeg?10000</pp:imageOriginal><pp:imageTitle><![CDATA[logo]]></pp:imageTitle></item><item>
                        <title>Enterprise Security Startups Are Booming - So Why Is Security Getting Worse?</title>
                        <link>https://www.siliconvalleywatcher.com/enterprise-security-startups-are-booming---so-why-is-security-getting-worse/</link>
                        <guid>https://www.siliconvalleywatcher.com/enterprise-security-startups-are-booming---so-why-is-security-getting-worse/</guid><pp:caseid>238947</pp:caseid><description><![CDATA[<p><img style="display: block; margin-left: auto; margin-right: auto;" title="Eastwick dinner-10.jpg" src="https://s3-eu-west-1.amazonaws.com/presspage-production-content/uploads/2054/Eastwick dinner-10.jpg" alt="Eastwick dinner 10" width="620" height="933" border="0" /></p><p>I attended a dinner organized by Eastwick Communications that featured several of their security clients and a security industry analyst. The discussion grew ever more interesting as the wine glasses emptied and refilled. Here’s my notes from the evening:</p><p>- List of participants is below. Each of the security companies is working in important areas and focused on helping enterprises deal with the many risks.</p><p>- One of the companies said that security used to be difficult for startups to get funding but these days, it’s a very good sector and VCs love security companies. There’s also lots of revenue potential because of the complexity of enterprise security.</p><p>- The complexity of the security risks facing companies was repeated time and again by each of the companies.</p><p>- Deborah Gage from the Wall Street Journal asked a good question: Can private industry deal with the security issues or does it need government involvement? She didn’t receive a good answer beyond the usual response that government involvement isn’t necessary .</p><p>- We were reminded of the “fiduciary duties” that executives have towards making sure their business is protected from security risks.</p><p>- I asked what exactly are those fiduciary duties when it comes to security risks? How much is enough security? Is there a standard set?</p><p>- Private Core has an interesting approach to it’s goal of making cloud IT services as secure as your own data center. It encrypts the entire computation of an app from within the cache memory of microprocessors. It’s a much smaller attack surface. </p><p>- NSA revelations haven’t caused much concern among US enterprises but in Europe it is having a very large effect on enterprises. </p><p>- Enterprises often don’t know what devices they have connected to their networks. There are typically 5,ooo applications used by staff in a large organization.</p><p>- Apps such as Dropbox are a problem because they have APIs and their contents are shareable by many other applications, greatly magnifying risks.</p><p>- “Free” apps on phones and tablets are a worry because they are making money by sharing data on their enterprise users — it’s one of the problems with the bring-your-own-device trend.</p><p>- Security is a very good business because it is one of the few things that will get a CEO out of bed at night. </p><p> Jon Oltsik, senior analyst at the Enterprise Strategy Group, said security risks have increased because of the use of mobile, the increase in malware, and the problem that no one talks about: a big shortage of people with cyber security skills.</p><p>- I mentioned that people were still the biggest security risk and that people such as Edward Snowden were motivated by ethics and not money. It’s difficult to guard against ethical hackers  — at least with money theft there’s a silver trail to follow. And I’m surprised we’ve only had one Edward Snowden.</p><p>- There was some discussion that Millennials might be a security threat because they are upset with large college debts and poor salaries. I disagree, they are much more likely to be motivated by ethics — doing the right thing — than by money.</p><p><strong><em>- Security analyst Jan Oltsik ended the evening with a bang.</em></strong><strong> </strong>(Despite all the security companies at the table, and the many more in the industry), he said that the enterprise security situation is bad and will worsen further unless there is a radical new approach/technology developed. But what is that radical new technology? No one had an answer. </p><p><strong>Foremski’s Take:</strong> The security industry is constantly warning of ever greater risks to enterprises — the sky is always falling. When has a business bought enough security?</p><p>The answer seems to be that there is never enough security that you can buy. You can never have enough security is great for vendors but it’s very bad for enterprises because it leads to indecision. </p><p>The complexity of the security risks is another issue. Some of the exploits are extremely sophisticated and can only be understood by experts in their fields. To expect CIO’s to be able to asses the risks of exotic malware and other new exploits, and then take appropriate steps is not realistic. It’s overwhelming.</p><p>The complexity needs to be outsourced in some way, even though the legal liabilities can’t be outsourced easily. Enterprises need specialist service providers that stay up to date on threats and can quickly implement protective measures and policies. Otherwise, the security situation will get worse.</p><p>Also, I wonder about the competitions that companies are advertising to find bugs and flaws in their software. Only a few people are rewarded but many others become familiar with the software and better able to discover and exploit additional weaknesses. Are the bug competitions training grounds for a new generation of hackers?</p><p>What was clear from the evening’s discussion is that security is a shimmering mirage that can never be reached, and can never quench your thirst for more. It’s a very good business to be in. Between the money lost to criminals and the money spent to prevent that loss, it’s a costly tax on doing business. And it does absolutely nothing to enable commerce or improve productivity. </p><p>- - -</p><p><em>Participants:</em><br /> <br /><strong>Lasse Andresen, CEO, ForgeRock</strong><br />ForgeRock is the only unified open source identity stack to protect enterprise, cloud, social and mobile applications at Internet scale.<br /> <br /><strong>Patrick Peterson, CEO, Agari</strong><br />Agari provides global brands with the experience, tools, and analytics they need to eliminate email threats, protect customers and their personal data, and proactively guard brand reputation.<br /> <br /><strong>Arvind Purushotham, Citi Ventures</strong><br />Citi Ventures is Citi's global corporate venturing arm, chartered to collaborate with internal and external partners to conceive, partner, launch, and scale new ventures that have the potential to disrupt and transform the financial services industry, drive client success, and generate new value for Citi.</p><p><strong>Peter Long, CEO, Lockbox</strong><br />Lockbox is an end-to-end, client-side encryption platform that allows users to generate and maintain encryption keys for secure and private file sharing and storage in the cloud.<br /> <br /><strong>Paul Stich, CEO, Appthority</strong><br />Appthority provides the industry’s first all-in-one App Risk Management service that employs static, dynamic and behavioral analysis to immediately discover the hidden actions of apps and empower organizations to apply custom policies to prevent unwanted app behaviors.<br /> <br /><strong>Rob Rachwald, Senior Director, FireEye</strong><br />FireEye is the leader in next generation threat protection, stopping advanced malware, zero-day, and targeted APT attacks that bypass traditional defenses.<br /> <br /><strong>Steve Weis, CTO, Private Core</strong><br />Private Core is a venture-backed company delivering an industry first: the ability to protect enterprise data in use by encrypting memory.<br /> <br /><strong>Scott Gordon, CMO, ForeScout</strong><br />ForeScout delivers pervasive network security by allowing organizations to continuously monitor and mitigate security exposures and cyber attacks.</p>]]></description><category><![CDATA[A Top Story,Enterprise IT,Security]]></category>
            <pubDate>Wed, 13 Nov 2013 07:55:58 -0800</pubDate>
            <enclosure url="https://content.presspage.com/clients/150_2054.jpeg?10000" length="0" type="image/jpeg" />
                <pp:image>https://content.presspage.com/clients/150_2054.jpeg?10000</pp:image>
                <pp:imageOriginal>https://content.presspage.com/clients/150_2054.jpeg?10000</pp:imageOriginal><pp:imageTitle><![CDATA[logo]]></pp:imageTitle></item><item>
                        <title>Is Google Using NSA Spying As Excuse To Boost Ad Revenues?</title>
                        <link>https://www.siliconvalleywatcher.com/is-google-using-nsa-spying-as-excuse-to-boost-ad-revenues/</link>
                        <guid>https://www.siliconvalleywatcher.com/is-google-using-nsa-spying-as-excuse-to-boost-ad-revenues/</guid><pp:caseid>239025</pp:caseid><description><![CDATA[<p><img style="display: block; margin-left: auto; margin-right: auto;" title="RestoretheFourthAug (7 of 13).jpg" src="https://s3-eu-west-1.amazonaws.com/presspage-production-content/uploads/2054/RestoretheFourthAug (7 of 13).jpg" alt="RestoretheFourthAug  7 of 13" width="600" height="903" border="0" /></p><p class="photocaption">Daniel Ellsberg (above), famed whistle-blower of "Pentagon Papers" spoke at a recent protest to NSA spying at "Restore the Fourth" in San Francisco.</p><p>Google has begun to encrypt all searches made by users even if they aren't signed in to Google but it reveals the searches to its advertising customers. The search giant appears to be taking advantage of the NSA spying scandal to increase the number of its advertisers.</p><p>Danny Sullivan reports:<a href="http://searchengineland.com/post-prism-google-secure-searches-172487">Post-PRISM, Google Confirms Quietly Moving To Make All Searches Secure, Except For Ad Clicks</a></p><blockquote><br /><p>Google says this has been done to provide “extra protection” for searchers, and the company may be aiming to block NSA spying activity. Possibly, it’s a move to increase ad sales. Or both. </p><p>…what prompted Google to make such a change out of the blue. And it was sudden.</p></blockquote><br /><p>Google used to allow users of its Google Analytics tool to view the search terms that brought people to their sites. Then it began hiding those terms for users that were signed in. And then it stopped provided search terms for users of other browsers, even when not signed into Google.</p><p>Since September 4th, there has been a dramatic spike according to a site called <a href="http://www.notprovidedcount.com/">Not Provided Count</a>, with an increase of nearly 50% of search terms not provided to around 74% of all Google searches.</p><p>However, if you are a Google advertiser on its Adwords network you still get the search terms. If it were designed to thwart NSA then there is a big hole in that intent.</p><p>It also means that publishers don't know what brought users to their site but the advertisers do. It's an asymmetric distribution of information that favors Google's paying customers.  Yet the Google tool is designed to help webmasters create content that people want.</p><p>Danny Sullivan concludes:  "Increased privacy to thwart the NSA? Or a handy excuse to do that and increase potential ad sales?"</p><p>It seems the latter given that paying customers get the data.</p><p>Please see:</p><p><a href="http://www.siliconvalleywatcher.com/mt/archives/2013/07/us_spy_and_enforcemen.php">US Spy And Law Enforcement Agencies Should Buy 'Big Data' Like Everyone Else -SVW</a></p><p><a href="http://www.siliconvalleywatcher.com/mt/archives/2013/09/spies_in_disguise_nsa.php">Spies In Disguise: NSA Pretends To Be Google -SVW</a></p>]]></description><category><![CDATA[A Top Story,Security]]></category>
            <pubDate>Mon, 23 Sep 2013 05:03:49 -0700</pubDate>
            <enclosure url="https://content.presspage.com/clients/150_2054.jpeg?10000" length="0" type="image/jpeg" />
                <pp:image>https://content.presspage.com/clients/150_2054.jpeg?10000</pp:image>
                <pp:imageOriginal>https://content.presspage.com/clients/150_2054.jpeg?10000</pp:imageOriginal><pp:imageTitle><![CDATA[logo]]></pp:imageTitle></item><item>
                        <title>F5 Acquires Israeli Startup Versafe For Its Security Software</title>
                        <link>https://www.siliconvalleywatcher.com/f5-acquires-israeli-startup-versafe-for-its-security-software/</link>
                        <guid>https://www.siliconvalleywatcher.com/f5-acquires-israeli-startup-versafe-for-its-security-software/</guid><pp:caseid>239342</pp:caseid><description><![CDATA[<p><a href="http://www.versafe-login.com/">Versafe</a>, the Israeli security startup acquired today by <a href="http://finance.yahoo.com/news/f5-networks-acquires-versafe-help-145000198.html">F5 Networks</a>, in Seattle, Washington, recently introduced its <a href="http://www.versafe-login.com/sites/default/files/Versafe%20Americas%20Launch%20Press%20Release.pdf">TotALL</a> online fraud protection suite, which claims to protect financial institutions against all forms of fraud and malware without requiring any client software downloads.</p><p>It is a very bold claim but one that Versafe is comfortable in supporting because of its unique technology. It is also the prime reason that F5 said it acquired the company.</p><p>I recently spoke with Jens Hinrichsen VP, Marketing & Business Development at Versafe. Here are my notes:</p><p>- The company was co-founded by Eyal Gruner who made a name for himself when he was just 20 years old discovering a vulnerability in ATM machines. He also co-founded BugSec, which tests the security of banking systems.</p><p>- The TotALL suite is designed to protect financial systems no matter the architecture of client devices. It consists of two components, Websafe and MobileSafe.</p><p>- WebSafe claims to protect all users across all devices from threats such as zero-day attacks, man in the middle, etc., It also prevents personal information and login details from being stolen by third-parties. And it stops automated attacks intended to steal money from user accounts. Plus it stops phishing attacks in which fake web sites are used to fool bank customers.</p><p>- MobileSafe can detect if a mobile device has been jail broken, and it also can match the devices ID against behavioral information to spot suspicious behavior.</p><p>- Versafe assumes that all customers of financial institution are infected by some type of malware.</p><p>- There is no good reason to develop client based security software because it requires users to keep software updated.  And there are many changes in architecture that can easily open up new vulnerabilities. This relieves financial institutions from trying to secure a large range of mobile devices and have to update those security measures as those platforms change.</p><p>- Versafe installs its protection at the application level. By assuming every user is potentially infected with malware, the security system monitors the application and block any behaviors that are a security risk.</p><p>- The goal is to protect the financial applications from becoming modified by any malware by using polymorphic protection.</p><p>- Versafe says the security suite can quickly be integrated with customer's IT systems in as little as one day.</p><p>- The key benefit is that there is no need to install new software on client devices, the entire protection is transparent to users, requiring no additional steps. </p><p>- The Versafe solution works with any browser -- another key advantage. Since the architecture of smartphones and browsers is in constant flux the best place for security is at the server level.</p><p>- The way TotALL works is confidential, to stop hackers from figuring out a way around the security. Part of the solution involves using one-time public keys on the server.</p><p>- F5 was a partner of Versafe and <a href="https://devcentral.f5.com/articles/f5-and-versafe-because-mobility-matters#.UjjQlGS0VoI">says</a> it was this ability to work with any mobile device and any browser that led to its decision to acquire the company for an undisclosed amount.</p><p> </p>]]></description><category><![CDATA[Security]]></category>
            <pubDate>Tue, 17 Sep 2013 06:18:53 -0700</pubDate>
            <enclosure url="https://content.presspage.com/clients/150_2054.jpeg?10000" length="0" type="image/jpeg" />
                <pp:image>https://content.presspage.com/clients/150_2054.jpeg?10000</pp:image>
                <pp:imageOriginal>https://content.presspage.com/clients/150_2054.jpeg?10000</pp:imageOriginal><pp:imageTitle><![CDATA[logo]]></pp:imageTitle></item><item>
                        <title>Spies In Disguise: NSA Pretends To Be Google</title>
                        <link>https://www.siliconvalleywatcher.com/spies-in-disguise-nsa-pretends-to-be-google/</link>
                        <guid>https://www.siliconvalleywatcher.com/spies-in-disguise-nsa-pretends-to-be-google/</guid><pp:caseid>239478</pp:caseid><description><![CDATA[<p class="photocaption"><img style="display: block; margin-left: auto; margin-right: auto;" title="2013-09-12_16-46-51.jpg" src="https://s3-eu-west-1.amazonaws.com/presspage-production-content/uploads/2054/2013-09-12_16-46-51.jpg" alt="2013 09 12 16 46 51" width="672" height="332" border="0" /></p><p class="photocaption">Above from Mother Jones.</p><p>The NSA Edward Snowden revelations are getting worse and worse for the reputation of leading Silicon Valley companies as the latest information shows that the US spy agency has masqueraded as Google to collect information on users.</p><p> Josh Harkinson reports in Mother Jones: <a href="http://www.motherjones.com/politics/2013/09/flying-pig-nsa-impersonates-google">Report: NSA Mimics Google to Monitor "Target" Web Users | Mother Jones</a></p><blockquote><br /><p>The NSA has impersonated Google and possibly other major internet sites in order to intercept, store, and read supposedly secure online communications. The spy agency accomplishes this using what's known as a "man-in-the-middle (MITM) attack," a fairly well-known exploit used by elite hackers. </p></blockquote><br /><p>This can't be good for business. </p><p>Google's Chrome browser offers some protection from MITM attacks.</p><blockquote><br /><p>Google Chrome maintains its own list of the public keys for Google webpages; the browser sends an alarm to Google headquarters if it detects any attempts to forge those sites.</p></blockquote><br /><p>However, it's not known if the NSA has demanded Google's keys so it can perform such surveillance without triggering any alarms. If this is the case, Google will face a hailstorm of criticism.</p><p>If the NSA is doing this for Google, it could disguise itself as other popular sites such as Facebook, and Twitter.</p><p>The leaked documents also show that the NSA has used MITM methods to spy on Brazilian oil company Petrobas indicating that it is harvesting information that might better be classified as industrial espionage, than terrorist tracking.</p><p>This could significantly harm business prospects for US cloud companies in foreign markets if they can't protect their systems from industrial espionage.</p><p>It could also set back by years the transition of IT systems to cloud-based hosts just as the cloud infrastructure is becoming better understood among businesses. </p>]]></description><category><![CDATA[A Top Story,Security]]></category>
            <pubDate>Thu, 12 Sep 2013 08:17:17 -0700</pubDate>
            <enclosure url="https://content.presspage.com/clients/150_2054.jpeg?10000" length="0" type="image/jpeg" />
                <pp:image>https://content.presspage.com/clients/150_2054.jpeg?10000</pp:image>
                <pp:imageOriginal>https://content.presspage.com/clients/150_2054.jpeg?10000</pp:imageOriginal><pp:imageTitle><![CDATA[logo]]></pp:imageTitle></item><item>
                        <title>How To Disable Facebook&#039;s Creepy Face Recognition Software</title>
                        <link>https://www.siliconvalleywatcher.com/how-to-disable-facebooks-creepy-face-recognition-software/</link>
                        <guid>https://www.siliconvalleywatcher.com/how-to-disable-facebooks-creepy-face-recognition-software/</guid><pp:caseid>239344</pp:caseid><description><![CDATA[<p>Here's some good advice in the form of an infographic from Checkpoint's <a href="http://www.zonealarm.com/">Zone Alarm</a> about the new Facebook security changes. Your face has become very important to Facebook with a new facial recognition system that encourages others to tag your face in photos.</p><p>Find out what it is and how to disable it:</p><p>David Michaelis at A New Domain explains what Facebook has done and how it plans top profit from tagging your face:</p><p><a href="http://anewdomain.net/2013/09/02/protect-face-face-book-new-rules-inside-facebook-social-engineering-infographics/?fb_source=pubv1">Protect Your Face-Face Book New Rules- Inside Facebook and Social Engineering</a></p><p>Last week, Facebook updated its privacy policy again. It reads in part: “We are able to suggest that your friend tag you in a picture by scanning and comparing your friend’s pictures to information we’ve put together from your profile pictures and the other photos in which you’ve been tagged.”</p><p><img style="display: block; margin-left: auto; margin-right: auto;" title="ZoneAlarm-FacebookFace-C5-.jpg" src="https://s3-eu-west-1.amazonaws.com/presspage-production-content/uploads/2054/ZoneAlarm-FacebookFace-C5-.jpg" alt="ZoneAlarm FacebookFace C5" width="918" height="3570" border="0" /></p>]]></description><category><![CDATA[Security]]></category>
            <pubDate>Wed, 04 Sep 2013 13:16:21 -0700</pubDate>
            <enclosure url="https://content.presspage.com/clients/150_2054.jpeg?10000" length="0" type="image/jpeg" />
                <pp:image>https://content.presspage.com/clients/150_2054.jpeg?10000</pp:image>
                <pp:imageOriginal>https://content.presspage.com/clients/150_2054.jpeg?10000</pp:imageOriginal><pp:imageTitle><![CDATA[logo]]></pp:imageTitle></item><item>
                        <title>JFK&#039;s Most Amazing And Incredibly Important Speech On Secrecy And Newspapers</title>
                        <link>https://www.siliconvalleywatcher.com/jfks-most-amazing-and-incredibly-important-speech-on-secrecy-and-newspapers/</link>
                        <guid>https://www.siliconvalleywatcher.com/jfks-most-amazing-and-incredibly-important-speech-on-secrecy-and-newspapers/</guid><pp:caseid>239000</pp:caseid><description><![CDATA[<p><iframe src="//www.youtube.com/embed/Em8cuv_a0gU" width="600" height="450" frameborder="0"></iframe></p><p>"The very word "secrecy" is repugnant in a free and open society;</p><p>and we are as a people inherently and historically opposed to secret societies,</p><p>to secret oaths and secret proceedings..."</p><p>- - -</p><p>"…there is very grave danger that an announced need for increased security will be seized upon those anxious to expand its meaning to the very limits of official censorship and concealment.</p><p>That I do not intend to permit to the extent that it is in my control."</p><p>- - -</p><p>"…that is why our press was protected by the First Amendment-- the only business in America specifically protected by the Constitution</p><p>-- not primarily to amuse and entertain,</p><p>not to emphasize the trivial and sentimental,</p><p>not to simply "give the public what it wants"</p><p>--but to inform, to arouse, to reflect,</p><p>to state our dangers and our opportunities,</p><p>to indicate our crises and our choices, to lead, mold educate</p><p>and sometimes even anger public opinion."</p><p><a href="http://www.youtube.com/watch?v=Em8cuv_a0gU">http://www.youtube.com/watch?v=Em8cuv_a0gU</a></p><p>(Thanks to <a href="http://www.youtube.com/user/seowweb?feature=watch">Donovan Seow</a>.)</p><p>Please listen to President John F. Kennedy's speech on secrecy and a free and democratic society. It's short and incredibly relevant.</p><p>Here is the transcript: </p><p>"The very word "secrecy" is repugnant in a free and open society; and we are as a people inherently and historically opposed to secret societies, to secret oaths and secret proceedings.</p><p>We decided long ago that the dangers of excessive and unwarranted concealment of pertinent facts far outweighed the dangers which are cited to justify it. Even today, there is little value in opposing the threat of a closed society by imitating its arbitrary restrictions.</p><p>Even today, there is little value in insuring the survival of our nation if our traditions do not survive with it. And there is very grave danger that an announced need for increased security will be seized upon those anxious to expand its meaning to the very limits of official censorship and concealment.</p><p>That I do not intend to permit to the extent that it is in my control.</p><p>And no official of my Administration, whether his rank is high or low, civilian or military, should interpret my words here tonight as an excuse to censor the news, to stifle dissent, to cover up our mistakes or to withhold from the press and the public the facts they deserve to know."</p><p>For we are opposed around the world by a monolithic and ruthless conspiracy that relies on covert means for expanding its sphere of influence--on infiltration instead of invasion, on subversion instead of elections, on intimidation instead of free choice, on guerrillas by night instead of armies by day.</p><p>It is a system which has conscripted vast human and material resources into the building of a tightly knit, highly efficient machine that combines military, diplomatic, intelligence, economic, scientific and political operations.</p><p>Its preparations are concealed, not published. Its mistakes are buried not headlined. Its dissenters are silenced, not praised. No expenditure is questioned, no rumor is printed, no secret is revealed."</p><p>"No President should fear public scrutiny of his program. For from that scrutiny comes understanding; and from that understanding comes support or opposition. And both are necessary.</p><p>I am not asking your newspapers to support the Administration, but I am asking your help in the tremendous task of informing and alerting the American people. For I have complete confidence in the response and dedication of our citizens whenever they are fully informed.</p><p>I not only could not stifle controversy among your readers-- I welcome it.</p><p>This Administration intends to be candid about its errors; for as a wise man once said: "An error does not become a mistake until you refuse to correct it." We intend to accept full responsibility for our errors; and we expect you to point them out when we miss them.</p><p>Without debate, without criticism, no Administration and no country can succeed-- and no republic can survive.</p><p>That is why the Athenian lawmaker Solon decreed it a crime for any citizen to shrink from controversy.</p><p>And that is why our press was protected by the First (emphasized) Amendment-- the only business in America specifically protected by the Constitution-- not primarily to amuse and entertain, not to emphasize the trivial and sentimental, not to simply "give the public what it wants"--but to inform, to arouse, to reflect, to state our dangers and our opportunities, to indicate our crises and our choices, to lead, mold educate and sometimes even anger public opinion.</p><p>This means greater coverage and analysis of international news-- for it is no longer far away and foreign but close at hand and local. It means greater attention to improved understanding of the news as well as improved transmission. And it means, finally, that government at all levels, must meet its obligation to provide you with the fullest possible information outside the narrowest limits of national security...</p><p>And so it is to the printing press--to the recorder of mans deeds, the keeper of his conscience, the courier of his news-- that we look for strength and assistance, confident that with your help man will<br />be what he was born to be: free and independent."</p>]]></description><category><![CDATA[A Top Story,Saturday Post,Security]]></category>
            <pubDate>Sat, 13 Jul 2013 14:01:48 -0700</pubDate>
            <enclosure url="https://content.presspage.com/clients/150_2054.jpeg?10000" length="0" type="image/jpeg" />
                <pp:image>https://content.presspage.com/clients/150_2054.jpeg?10000</pp:image>
                <pp:imageOriginal>https://content.presspage.com/clients/150_2054.jpeg?10000</pp:imageOriginal><pp:imageTitle><![CDATA[logo]]></pp:imageTitle></item><item>
                        <title>US Spy And Law Enforcement Agencies Should Buy &#039;Big Data&#039; Like Everyone Else</title>
                        <link>https://www.siliconvalleywatcher.com/us-spy-and-law-enforcement-agencies-should-buy-big-data-like-everyone-else/</link>
                        <guid>https://www.siliconvalleywatcher.com/us-spy-and-law-enforcement-agencies-should-buy-big-data-like-everyone-else/</guid><pp:caseid>239047</pp:caseid><description><![CDATA[<p><img style="display: block; margin-left: auto; margin-right: auto;" title="RestoreTheFourth (7 of 18).jpg" src="https://s3-eu-west-1.amazonaws.com/presspage-production-content/uploads/2054/RestoreTheFourth (7 of 18).jpg" alt="RestoreTheFourth  7 of 18" width="600" height="902" border="0" /></p><p class="photocaption">("Restore the Fourth" rally in San Francisco protesting NSA surveillance of US citizens.)</p><p>Declan McCullagh, the Washington correspondent for CNET, reports that the NSA and other agencies can force tech firms to comply with demands for real-time data on their users because the Foreign Intelligence Surveillance Act provides them with legal rights to install their own gear inside their data centers.</p><p><a href="http://news.cnet.com/8301-13578_3-57593538-38/how-the-u.s-is-forcing-internet-firms-hands-on-surveillance/">How the U.S. is forcing Internet firms' hands on surveillance | Politics and Law - CNET News</a></p><blockquote><br /><p>Those devices, the companies fear, could disrupt operations, introduce security vulnerabilities, or intercept more than is legally permitted.</p><p>"Nobody wants it on-premises," said a representative of a large Internet company who has negotiated surveillance requests with government officials. "Nobody wants a box in their network... [Companies often] find ways to give tools to minimize disclosures, to protect users, to keep the government off the premises, and to come to some reasonable compromise on the capabilities."</p></blockquote><br /><p>It's tough to fight such demands because there are several legal precedents, such as when ISP Earthlink lost a legal battle to stop the FBI from installing its "Carnivore" surveillance system within its networks. </p><p><strong>Foremski's Take: </strong></p><p>US tech giants have been surveilling their users for years. That's what they mean by "Big Data" and it feeds a huge industry where that data is sold and used in real-time. That's how ad networks know what ads to serve to you in the milliseconds it takes to load a page.</p><p>It's commonly known as "contextual advertising."  But the "context" isn't the content of a page, the context is "who."</p><p>I'm sure you've noticed those sticky ads, the ones that follow you around the Internet. For example, I was seeing adverts for Tai Chi DVDs and books on numerous web sites for weeks because I had visited a Tai Chi site and clicked around for a bit. </p><p>Advertising networks detect when and where you are online and your physical location.  In the instant it takes to load a page they analyze all the data they have about you and serve up an appropriate ad. They log the event and update their personalized dossier with any additional information they collect. </p><p>In that regard, spy agencies and advertisers are essentially the same. They are both interested in real-time data about a specific person. It doesn't matter that one is trying to sell you a watch, while the other one just wants to watch -- the process is the same. </p><p>Imagine if the NSA built an advertising network as a cover and bought access to the same real-time data that advertising networks use. It would be able to collect a lot of valuable data without needing to argue its case in secret courts.</p><p>It would have real-time login and other information, it could also drop a super-cookie or key-logger onto a target's computer.</p><p>It could even serve up contextual adverts: where to find hard-to-get combustible materials; or difficult to source equipment such as high-speed centrifuges. It would be perfect for sting operations.</p><p>But the government agencies should buy the data instead of demanding the right to take it. It's not that expensive and the suppliers will sort it and package it – saving them from having to filter and process the firehose of data from their own equipment installed on-site. </p>]]></description><category><![CDATA[A Top Story,Bright Ideas,Security]]></category>
            <pubDate>Fri, 12 Jul 2013 06:18:28 -0700</pubDate>
            <enclosure url="https://content.presspage.com/clients/150_2054.jpeg?10000" length="0" type="image/jpeg" />
                <pp:image>https://content.presspage.com/clients/150_2054.jpeg?10000</pp:image>
                <pp:imageOriginal>https://content.presspage.com/clients/150_2054.jpeg?10000</pp:imageOriginal><pp:imageTitle><![CDATA[logo]]></pp:imageTitle></item><item>
                        <title>Reimagining The NSA As A Hybrid Public/Private Platform For New Jobs And Businesses</title>
                        <link>https://www.siliconvalleywatcher.com/reimagining-the-nsa-as-a-hybrid-publicprivate-platform-for-new-jobs-and-businesses/</link>
                        <guid>https://www.siliconvalleywatcher.com/reimagining-the-nsa-as-a-hybrid-publicprivate-platform-for-new-jobs-and-businesses/</guid><pp:caseid>239459</pp:caseid><description><![CDATA[<p>The National Security Agency could be rejigged as a self-funded entity fulfilling its missions while saving taxpayers billions of dollars and also providing them with a host of useful services. </p><p>Its substantial computing platform and its superior security knowledge could jumpstart new jobs and businesses if the agency had a commercial arm.</p><p> </p><p>The NSA is interested in the tiniest fraction of the data it collects, the bits about finding terrorists. The rest of the data is useless to it but it keeps it anyway. It's a highly valuable resource to others. </p><p>Here are some business ideas:</p><p>- A Web Services Suite for consumers that includes, virus protection, data backup services of all client computers and devices and online data lockers; unlimited dropbox-like data storage in the cloud; free banking software; unlimited email accounts; unlimited VOIP calls; and a personalized VPN protecting users from snoopers, would be a killer package. The NSA Security suite could get away with charging a premium monthly fee for the service because of its stellar pedigree. </p><p>There are other services it could offer:</p><p>- Host IT services. It clearly has all the APIs needed to link up with hundreds of thousands of businesses and financial institutions and is able process mountains of Internet data in real-time. There is no business in existence today that can do that.</p><p>- It could sell incredibly detailed analytics reports on the planet's commerce, what the billions are buying and thinking. And economic data to help governments keep their countries healthy.</p><p>- There might be legal protection for NSA customers from private lawsuits and police investigations. Since NSA cannot secretly collect information on US citizens therefore any court orders to search through its databases and collect information on citizens would require breaking the law and impossible to fulfill.</p><p>The NSA wouldn't need to spy on its own consumer or business clients since anyone with something to hide would never buy or use any NSA services, even if they were free or saved them a bunch of money. The agency could focus its resources on other people and thus help fulfill its mission faster.</p><p>- Also, the NSA archives are undoubtably the single largest collection of archeological data that anyone has ever collected. It documents in raw form our collision with the Internet Age, a media age extraordinaire.</p><p>The data  would offer a tremendous insight into our collective nature, an aggregation of how people behave, and how they change, across an enormous scale.  It must be incredible treasure trove of data, and it would allow sociologists and anthropologists to draw a far more accurate picture of humanity than we have today.</p><p>That mass of data hides a map of our social genome, those long double-twisted chains of memes and stories that shape each of us as distinctly as our DNA gives us form.</p><p>It might even reveal a key code that governs our nature and can help unlock new abilities. Yet the NSA just sifts for a very narrow range of human behaviors – all negative.</p><p>Here are some marketing slogans for the NSA, which could be used sell services or perk up its image:</p><p>"We've got your back."</p><p>"You're welcome."</p><p>"We're always watching out for you."</p><p>"We know what you did last summer."</p><p>"Speak freely -- it's your right."</p><p>"Free speech is nothing if no one listens."</p><p>"$19 a year for unlimited data storage, emails, and phone calls."</p>]]></description><category><![CDATA[A Top Story,Security]]></category>
            <pubDate>Mon, 01 Jul 2013 13:39:13 -0700</pubDate>
            <enclosure url="https://content.presspage.com/clients/150_2054.jpeg?10000" length="0" type="image/jpeg" />
                <pp:image>https://content.presspage.com/clients/150_2054.jpeg?10000</pp:image>
                <pp:imageOriginal>https://content.presspage.com/clients/150_2054.jpeg?10000</pp:imageOriginal><pp:imageTitle><![CDATA[logo]]></pp:imageTitle></item><item>
                        <title>The Winklevoss Risk Factor In The Winklevoss Bitcoin Venture</title>
                        <link>https://www.siliconvalleywatcher.com/the-winklevoss-risk-factor-in-the-winklevoss-bitcoin-venture/</link>
                        <guid>https://www.siliconvalleywatcher.com/the-winklevoss-risk-factor-in-the-winklevoss-bitcoin-venture/</guid><pp:caseid>239498</pp:caseid><description><![CDATA[<p>Simone Foxman at Quartz reports that Cameron and Tyler Winklevoss, the millionaire twins from the Facebook founders' saga, have filed SEC papers for <a href="http://qz.com/99632/winklevoss-bitcoin-etf-risk-factors/">a public offering of shares in Winkelvoss Bitcoin Trust</a>. </p><p>The venture will allow retail investors to invest in Bitcoins by trading shares in the Trust. This is similar to a gold fund and lets investors own fractions of "Digital Math Based Assets such as Bitcoins." This will likely increase volatility in the value of Bitcoins because speculators can play the market without needing to buy and sell them directly.</p><p>The Winklevoss twins have accumulated a large number of Bitcoins so this could allow them to earn money on a substantial amount of locked-up capital via the Trust's monthly fees and  transaction services.</p><p>The risk factors in <a href="http://www.sec.gov/Archives/edgar/data/1579346/000119312513279830/d562329ds1.htm">the SEC filing</a> includes warnings that a malicious botnet on the Bitcoin Network could stop the Trust operating; or the Trust could lose its encryption keys.</p><p>There's an astounding 18 pages of risk factors. However, I did not see listed the most obvious risk factor of them all:  the Winklevoss name.  The twins are rich, good-looking, and Facebook famous, which attracts a lot of mean-spirited trolls. Hacker groups will relish an opportunity to school these Harvard grads. </p><p>Bitcoin exchanges have been attacked by hackers and the largest knocked offline and out of business.</p><p>Clearly, the Trust must be highly-confident that it has rock-solid security to use the Winklevoss name so prominently, and not include it as a risk factor. </p>]]></description><category><![CDATA[Security]]></category>
            <pubDate>Mon, 01 Jul 2013 10:52:52 -0700</pubDate>
            <enclosure url="https://content.presspage.com/clients/150_2054.jpeg?10000" length="0" type="image/jpeg" />
                <pp:image>https://content.presspage.com/clients/150_2054.jpeg?10000</pp:image>
                <pp:imageOriginal>https://content.presspage.com/clients/150_2054.jpeg?10000</pp:imageOriginal><pp:imageTitle><![CDATA[logo]]></pp:imageTitle></item><item>
                        <title>How Secure Are The NSA Spy Lines?</title>
                        <link>https://www.siliconvalleywatcher.com/how-secure-are-the-nsa-spy-lines/</link>
                        <guid>https://www.siliconvalleywatcher.com/how-secure-are-the-nsa-spy-lines/</guid><pp:caseid>238987</pp:caseid><description><![CDATA[<p><img style="display: block; margin-left: auto; margin-right: auto;" title="Corp-Vac.jpg" src="https://s3-eu-west-1.amazonaws.com/presspage-production-content/uploads/2054/Corp-Vac.jpg" alt="Corp Vac" width="620" height="451" border="0" /></p><p>Many are concerned about the National Security Agency (NSA) collection of data on US companies and individuals and the very real possibility that it has a way of directly accessing the servers of the world's largest computing platforms: Google, Facebook, Microsoft, etc.</p><p>It's certainly a situation that deserves attention and concern. But what's missing in this discussion is this: how secure is the NSA's spying system? </p><p>If a foreign entity wanted to spy on US companies or individuals, would it try to tackle the problem directly by targeting the specific company or individual in its electronic spying attempts? It might, but that's a lot of work for an uncertain payoff.</p><p>A much more efficient approach would be to hack into a surveillance system that already has access to the information. Far better to hack into the NSA spying system at Google, or at Facebook, or at Microsoft (if such an NSA system exists, of course).</p><p>In early 2010 Google discovered that Chinese hackers had gotten into its systems. Who did it call to help deal with this problem? The NSA. [<a href="http://www.washingtonpost.com/wp-dyn/content/article/2010/02/03/AR2010020304057.html">Google to enlist NSA to help it ward off cyberattacks</a>.]</p><p>This puzzled me tremendously, why would Google, with its enormous brain trust of the world's top computer experts call on the NSA? Why didn't Google have the means, the expertise, to deal with this problem directly and solely?</p><p>It makes sense if it was the NSA's spying system that got hacked within Google.</p><p>The search giant knows its own systems and how they can be protected but it does't know the NSA's computer systems and how they protect themselves. It makes perfect sense to call in the NSA to help plug this hole because it's a hole created for the NSA which the NSA might have left vulnerable in some way.</p><p>The NSA also employs the world's top computer experts but it's not infallible. Everyone knows that there's no such thing as a completely secure system. The greater danger in the NSA's spying activities is not from the NSA itself, but from the many nefarious foreign national, and international criminal enterprises, that find a way to exploit the existing spy systems so thoroughly crafted, and so thoroughly extensive, that have been built by the NSA.</p><p>The danger from allowing the NSA to have deep access into the data systems of US companies is that that very system creates an enormous vulnerability that would not have existed. Hack into part of the NSA spy network and you have access to a mass of private data that would be near impossible to collect in any other way.</p><p>It's ironic that the NSA's activities to improve the security of the US have created the nation's largest security risk of them all. </p><p>- - -</p><p>Please see: </p><p><a href="http://www.zdnet.com/blog/foremski/googles-internal-spy-system-was-chinese-hacker-target/1047">Google's internal spy system was Chinese hacker target</a></p><p><a href="http://www.zdnet.com/blog/foremski/goog-v-china-highlights-security-risks-in-wiretapping-systems/1049">GOOG v China highlights security risks in wiretapping systems</a></p>]]></description><category><![CDATA[A Top Story,Security]]></category>
            <pubDate>Wed, 12 Jun 2013 01:12:55 -0700</pubDate>
            <enclosure url="https://content.presspage.com/clients/150_2054.jpeg?10000" length="0" type="image/jpeg" />
                <pp:image>https://content.presspage.com/clients/150_2054.jpeg?10000</pp:image>
                <pp:imageOriginal>https://content.presspage.com/clients/150_2054.jpeg?10000</pp:imageOriginal><pp:imageTitle><![CDATA[logo]]></pp:imageTitle></item><item>
                        <title>Tufin: Rethinking The Enterprise Security Model</title>
                        <link>https://www.siliconvalleywatcher.com/tufin-rethinking-the-enterprise-security-model/</link>
                        <guid>https://www.siliconvalleywatcher.com/tufin-rethinking-the-enterprise-security-model/</guid><pp:caseid>239146</pp:caseid><description><![CDATA[<p style="clear: both">I recently spoke with Ruvi Kitow, CEO and co-founder of <a href="https://www.tufin.com/">Tufin Technologies</a>, which provides firewall policy management tools for very large companies. </p><p style="clear: both">Tufin is interesting because it is rethinking the way firewalls should be managed. It's because of rise in the number of applications being produced by enterprises.</p><p style="clear: both">Firewall administrators are spending more of their time dealing with application related change requests. Yet the app developers know little about firewalls and potential conflicts, or security holes. Earlier this year, Tufin launched SecureApp, a suite of admin tools to help manage this important security relationship between apps and firewalls.</p><p style="clear: both">This application centric approach to enterprise security is a different way of thinking about security. <strong>Here are some notes from our conversation:</strong></p><p style="clear: both"><br />- Our <a href="https://www.tufin.com/about-us/news-and-media/press-releases/2012/october-23%2c2012/">latest survey</a> shows that nearly half of all firewall changes are related to application connectivity. And most companies report that they don't have confidence in their IT staff being able to fully address the compliance and security risks that arise when managing application connectivity.<br /><br />- We realized that the best approach is to address security through the app layer first, to document the resources an app needs and how it behaves, and then to communicate what's needed in the firewalls. Our new product helps to automate this process. And it's integrated with our two other firewall products, <a href="https://www.tufin.com/products-solutions/products/products-securetrack-securechange-overview/">SecureTrack and SecureChange</a>. <br /><br />- It's a paradigm shift and it might take some time for this to be understood but you have to tackle security first through the app layer not the network.<br /><br />- Here's why: Large enterprises have a high degree of complexity because of multiple locations, multiple IT systems and hundreds of firewalls to manage with multitudes of rules. Developing new applications is tough because they must work across all of a corporations firewalls.<br /><br />- The situation becomes more complex when changes are made to an application and those changes have to be communicated to hundreds of firewalls. <br /><br />- If firewalls aren't configured right, apps will fail. But the apps developers have to be better at communication, and documenting, how their apps behave, so that the right changes can be made by the network security teams.<br /><br />- Anytime you change the configuration of firewalls, other things can break. A key feature of SecureApp is that you can simulate the entire network and test changes safely. </p><p style="clear: both">- CIOs want to deploy apps faster but this can compromise security if there is little communication between the app developers and the security teams.<br /><br />- There's often a cultural problem within large corporations in that the apps developers don't understand the security issues and the security people don't understand the apps. </p><p style="clear: both">-There is often little or no documentation, and when people leave a company, a lot of knowledge about an app leaves too. SecureApp makes sure that there is documentation and that knowledge isn't lost when people leave.<br /><br /></p><p style="clear: both"><strong>Foremski's Take:</strong> Tufin's application centric approach to improving enterprise security makes sense and it won't take corporations long to realize its the right approach.</p><p style="clear: both">What will take longer is the internal shift in culture, in the app developer teams, which traditionally have not been very security minded.</p><p style="clear: both">It's a leadership move by Tufin and one that's well timed. The explosion of apps in the consumer web is driving a tremendous amount of app development in the enterprise. Firewalls can quickly become brick walls or leave security holes open because of badly designed apps.</p><p style="clear: both">Managing hundreds of firewalls while trying to support a deluge of apps will quickly turn into a nightmare unless the whole process of application development can be mapped against an organization's firewalls. The app and the firewall have to be in sync and that requires new sets of tools. </p><p style="clear: both"><br /><p style="clear: both">Tools such as Tufin's not only provide an easy interface for managing security policies and compliance but they can also be used as an agent of cultural change within organizations because they offer a common ground for the apps and security teams. It helps them communicate with each other, which should lead to better apps.</p></p><p style="clear: both"></p><br class='final-break' style='clear: both' />]]></description><category><![CDATA[A Top Story,Enterprise IT,Interview,Security]]></category>
            <pubDate>Wed, 19 Dec 2012 07:06:35 -0800</pubDate>
            <enclosure url="https://content.presspage.com/clients/150_2054.jpeg?10000" length="0" type="image/jpeg" />
                <pp:image>https://content.presspage.com/clients/150_2054.jpeg?10000</pp:image>
                <pp:imageOriginal>https://content.presspage.com/clients/150_2054.jpeg?10000</pp:imageOriginal><pp:imageTitle><![CDATA[logo]]></pp:imageTitle></item></channel>
                    </rss>