<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Software Associates. &#187; Physical security</title>
	<atom:link href="http://www.software.co.il/category/physical-security/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.software.co.il</link>
	<description>Security and compliance specialists for medical device and healthcare companies</description>
	<lastBuildDate>Wed, 08 Feb 2012 06:36:35 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
		<item>
		<title>Treat passwords like cash</title>
		<link>http://www.software.co.il/2012/02/treat-passwords-like-cash/</link>
		<comments>http://www.software.co.il/2012/02/treat-passwords-like-cash/#comments</comments>
		<pubDate>Sun, 05 Feb 2012 16:45:33 +0000</pubDate>
		<dc:creator>Danny Lieberman</dc:creator>
				<category><![CDATA[Physical security]]></category>
		<category><![CDATA[Risk Assessment]]></category>
		<category><![CDATA[Risk management]]></category>
		<category><![CDATA[Default passwords]]></category>
		<category><![CDATA[Weak passwords]]></category>

		<guid isPermaLink="false">http://www.software.co.il/?p=4346</guid>
		<description><![CDATA[How much personal technology do you carry around when you travel?  Do you use one of those carry-on bags with your notebook computer on top of the carry-on? A friend who is a commercial pilot had his bag swiped literally behind his back while waiting on line to check-in to a 4 star Paris hotel. ...]]></description>
			<content:encoded><![CDATA[<p>How much personal technology do you carry around when you travel?  Do you use one of those carry-on bags with your notebook computer on top of the carry-on?</p>
<p>A friend who is a commercial pilot had his bag swiped literally behind his back while waiting on line to check-in to a 4 star Paris hotel. The hotel security cameras show the thief moving quickly behind his back, quietly taking the bag and calmly walking off.</p>
<p>Is your user password 123456?</p>
<p>The Wharton School at UPenn recently posted an article &#8211; <a title="Is your password 123456" href="http://knowledgetoday.wharton.upenn.edu/2012/01/is-your-password-123456/" target="_blank">is your password 123456</a>?</p>
<p>As the article notes &#8211; &#8220;<em>Hack attacks have recently hit government agencies, news sites and retailers ranging from the U.S. Justice Department and Gawker to Sony and Lockheed Martin, as hackers become more sophisticated in their ability to steal customers’ identities and personal information.&#8221;</em></p>
<p>But, you don&#8217;t need sophisticated hack attacks to know that many people use simple minded passwords like 123456 and thieves use simple techniques like grab and run.</p>
<p>So &#8211; why don&#8217;t we all use strong passwords?</p>
<p>Every Web site and business application you use has a  different algorithm and password policy.  For users, who need to maintain strong passwords using 25 different policies on 25 different systems and web sites, it&#8217;s impossible to maintain a strong password policy without making some compromises.</p>
<p>The biggest vulnerability is using your corporate password on an online porn site.  Since adult sites are routinely subject to attack and cheesier, more marginal adult sites &#8211; (mind you we&#8217;re not talking Penthouse.com or Playboy.com perish the thought) are frequently unwitting malware distribution platforms.</p>
<p>Here are 5 rules for safe password management :</p>
<ol>
<li><strong>Use technical aids</strong> to manage your passwords.  Consider using <a title="f KeePass, the free, open source, light-weight and easy-to-use password manager." href="http://keepass.info/" target="_blank">Keepass password management</a></li>
<li><strong>Match password  strength to asset value</strong>. In other words &#8211; use a complex combination of letters and numbers for online banking and a simple easy to remember password for Superball news.</li>
<li><strong>Don&#8217;t reuse</strong>.   Don&#8217; use the same strong password on more than one sites.</li>
<li><strong>Make passwords easy to remember but hard to guess</strong>.  Adopt mnemonics &#8211; like 4Tshun KukZ that you can remember</li>
<li><strong>Maintain physical security of your passwords</strong>.  Treat your passwords like you treat the cash in your wallet.  If you have to write passwords down, put them on a piece of paper in your wallet and treat that piece of paper like a $100 bill,  make sure you don&#8217;t lose that wallet.</li>
</ol>
<p>&nbsp;</p>
]]></content:encoded>
			<wfw:commentRss>http://www.software.co.il/2012/02/treat-passwords-like-cash/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Ehud Barak, information leaks and political activism</title>
		<link>http://www.software.co.il/2011/12/ehud-barak-information-leaks-and-political-activism/</link>
		<comments>http://www.software.co.il/2011/12/ehud-barak-information-leaks-and-political-activism/#comments</comments>
		<pubDate>Mon, 05 Dec 2011 15:05:12 +0000</pubDate>
		<dc:creator>Danny Lieberman</dc:creator>
				<category><![CDATA[Physical security]]></category>
		<category><![CDATA[Barak]]></category>
		<category><![CDATA[Bibi]]></category>
		<category><![CDATA[ethics]]></category>
		<category><![CDATA[Islamic Terror]]></category>
		<category><![CDATA[Israeli elections]]></category>
		<category><![CDATA[Meir Dagan]]></category>
		<category><![CDATA[Obama]]></category>

		<guid isPermaLink="false">http://www.software.co.il/?p=4154</guid>
		<description><![CDATA[What do Anat Kamm, Ehud Barak and Meir Dagan have in common? Ehud Barak is current Israeli Minister of Defense, former IDF Chief of Staff and former Prime Minister  that led the disastrous withdrawal from Lebanon that fomented Intifada II and then Lebanese War II.  Barak is famous for quotes like &#8220;If I was a Palestinian, I ...]]></description>
			<content:encoded><![CDATA[<h4>What do <a title="Anat Kam" href="http://en.wikipedia.org/wiki/Anat_Kamm-Uri_Blau_affair" target="_blank">Anat Kamm</a>, Ehud Barak and Meir Dagan have in common?</h4>
<p><strong><a href="http://www.software.co.il/wp-content/uploads/2011/12/barak.jpg"><img class="alignleft size-full wp-image-4167" title="barak" src="http://www.software.co.il/wp-content/uploads/2011/12/barak.jpg" alt="" width="264" height="191" /></a>Ehud Barak</strong> is current Israeli Minister of Defense, former IDF Chief of Staff and former Prime Minister  that led the disastrous withdrawal from Lebanon that fomented Intifada II and then Lebanese War II.  Barak is famous for quotes like &#8220;<em>If I was a Palestinian, I would also be a suicide bomber</em>&#8221; or &#8220;<em>If I was an Iranian, I would also build nuclear weapons</em>&#8220;.</p>
<p>During her military service as an assistant in the <a title="Central Command (Israel)" href="http://en.wikipedia.org/wiki/Central_Command_(Israel)">Central Command</a> bureau<a href="http://www.software.co.il/wp-content/uploads/2011/12/kamm.jpg"><img class="alignright size-full wp-image-4168" title="Anat kamm" src="http://www.software.co.il/wp-content/uploads/2011/12/kamm.jpg" alt="" width="274" height="184" /></a> <strong>Anat Kamm</strong> secretly copied over 2,000 classified documents, copied the documents to a CD and leaked it to the Israeli <em><a title="Haaretz" href="http://en.wikipedia.org/wiki/Haaretz">Haaretz</a></em> journalist <a title="Uri Blau" href="http://en.wikipedia.org/wiki/Uri_Blau">Uri Blau</a>. Kamm  was recently convicted of espionage and leaking confidential information without authorization and sentenced to 4.5 years in prison after a plea bargain.</p>
<p><a href="http://www.software.co.il/wp-content/uploads/2011/12/dagan.jpg"><img class="alignright size-full wp-image-4169" title="meir dagan" src="http://www.software.co.il/wp-content/uploads/2011/12/dagan.jpg" alt="" width="238" height="212" /></a>Former Mossad chief<strong> Meir Dagan</strong> has recently voiced unrestrained criticism of the current administration&#8217;s defense policy in the service of his political activism; criticism which is supposedly based on his inside knowledge from the Mossad.</p>
<p>Meir Dagan, together with Gen. Gabi Ashkenazi (former chief of staff), Gen. Amos Yadlin (former head of military intelligence), and Yuval Diskin (former head of Shin Bet), <em><strong>opposed</strong></em> an attack on Iran. While in office (they all retired between November 2010 and May 2011), the Gang of Four successfully blocked attempts by Netanyahu and Barak to move forward on the military option.</p>
<p>Of the four, only Dagan has spoken openly, after leaving office, about what he considers to be the folly of an attack on Iran —  and openly criticized Netanyahu and Barak for irresponsibly pushing Israel to an unnecessary war, relying on his former position of responsibility as chief of intelligence as as implying that what he said must be true.</p>
<p>It was unclear why Dagan would speak of plans best left undisclosed. Unclear, at least until last week, when Dagan announced his plans for a movement to change the method of Israeli government, leaving his options to enter politics in the future open.</p>
<p>I wish Dagan luck.  I&#8217;m not happy with his way of publicizing his political activism at the risk of treading the thin line of information leak. It places him on the same slippery slope as Anat Kam who lamely attempted to justify her actions as an act of political protest.</p>
<p>In comparison with Dagan, Barak is circumspect (despite his unfortunate quotes and bad decisions).</p>
<p>Barak was asked about the possibility of making a decision on attacking Iran in the Israeli daily Ha&#8217;aretz.</p>
<div>“<em>In my various posts I’ve already seen all the possible permutations, as long as one thing remains constant: the role of the military is to prepare the plans. It is important that the political echelon listen very carefully to what the operational and intelligence echelons have to say, but at the end it is the political echelon that has the responsibility for the decision.</em>”</div>
<div>More <a title="Israeli defense minister Ehud Barak on Iran, U.S., and war" href="http://www.homelandsecuritynewswire.com/israeli-defense-minister-ehud-barak-iran-us-and-war?page=0,1" target="_blank">here</a> on Israeli defense minister Ehud Barak on Iran, U.S., and war</div>
]]></content:encoded>
			<wfw:commentRss>http://www.software.co.il/2011/12/ehud-barak-information-leaks-and-political-activism/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Rising the level of trust associated with identity in online transactions</title>
		<link>http://www.software.co.il/2011/07/rising-the-level-of-trust-associated-with-identity-in-online-transactions/</link>
		<comments>http://www.software.co.il/2011/07/rising-the-level-of-trust-associated-with-identity-in-online-transactions/#comments</comments>
		<pubDate>Fri, 01 Jul 2011 13:57:08 +0000</pubDate>
		<dc:creator>Danny Lieberman</dc:creator>
				<category><![CDATA[Physical security]]></category>
		<category><![CDATA[Privacy]]></category>
		<category><![CDATA[Risk Assessment]]></category>
		<category><![CDATA[identity]]></category>
		<category><![CDATA[Identity theft]]></category>

		<guid isPermaLink="false">http://www.software.co.il/wordpress/?p=3641</guid>
		<description><![CDATA[Obama&#8217;s National Strategy for Trusted Identities in Cyberspace In April President Obama signed the National Strategy for Trusted Identities in Cyberspace (NSTIC) which charts a course for the public and private sectors to collaborate on raising the level of trust associated with identity in online transactions. NSTIC focuses on upgrading outdated password-based authentication systems and ...]]></description>
			<content:encoded><![CDATA[<p><strong>Obama&#8217;s National Strategy for Trusted Identities in Cyberspace</strong></p>
<p>In April President Obama signed the National Strategy for Trusted Identities in Cyberspace (NSTIC) which charts a course for the public and private sectors to collaborate on raising the level of trust associated with identity in online transactions.</p>
<p>NSTIC focuses on upgrading outdated password-based authentication systems and reducing the barriers associated with identity proofing and deployment of strong credentials, while also enabling end-users to have more control over when and what information they disclose in a range of transactions.</p>
<p>Could someone please translate this for me?</p>
<p>How is giving an end-user more control over information disclosure is going to mitigate the risk of data breaches when over 300 million credit cards have <em><strong>already been breached</strong></em>?</p>
<p>What about online merchants vulnerabilities and better data security countermeasures for online Web services?</p>
<p>Will PCI DSS discover Data loss prevention technology anytime in the next decade?</p>
<p>Where  I come from, that&#8217;s called shutting the barn-door after the horses have flown.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.software.co.il/2011/07/rising-the-level-of-trust-associated-with-identity-in-online-transactions/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Why Microsoft Windows is a bad idea for medical devices</title>
		<link>http://www.software.co.il/2011/06/why-microsoft-windows-is-a-bad-idea-for-medical-devices/</link>
		<comments>http://www.software.co.il/2011/06/why-microsoft-windows-is-a-bad-idea-for-medical-devices/#comments</comments>
		<pubDate>Wed, 22 Jun 2011 11:20:10 +0000</pubDate>
		<dc:creator>Danny Lieberman</dc:creator>
				<category><![CDATA[Physical security]]></category>
		<category><![CDATA[Application security]]></category>
		<category><![CDATA[data security]]></category>
		<category><![CDATA[embedded]]></category>
		<category><![CDATA[FDA]]></category>
		<category><![CDATA[HIPAA]]></category>
		<category><![CDATA[medical devices]]></category>
		<category><![CDATA[Security engineering]]></category>

		<guid isPermaLink="false">http://www.software.co.il/wordpress/?p=3597</guid>
		<description><![CDATA[I&#8217;m getting some push back on LinkedIn on my articles on banning Microsoft Windows from medical devices that are installed in hospitals &#8211; read more about why Windows is a bad idea for medical devices here and here. Scott Caldwell tells us that the FDA doesn’t rule “out” or “in” any particular technology, including Windows ...]]></description>
			<content:encoded><![CDATA[<p>I&#8217;m getting some push back on LinkedIn on my articles on banning Microsoft Windows from medical devices that are installed in hospitals &#8211; read more about why Windows is a bad idea for medical devices <a title="Why outlawing windows from medical devices is a good idea" href="http://www.software.co.il/wordpress/2011/06/why-outlawing-windows-from-embedded-medical-devices-is-a-good-idea/" target="_blank">here</a> and <a title="Why the Microsoft monoculture is a threat to national security" href="http://www.software.co.il/wordpress/2011/06/the-microsoft-monoculture-as-a-threat-to-national-security/" target="_blank">here</a>.</p>
<p><a title="See this member's activity" href="http://www.linkedin.com/groups?viewMemberFeed=&amp;gid=3287843&amp;memberID=611820">Scott Caldwell</a> tells us that the FDA doesn’t rule “out” or “in” any particular technology, including Windows Embedded.</p>
<p>Having said that, Microsoft has very clear language in their EULA regarding the use of Windows Embedded products:</p>
<blockquote><p>“The Products are not fault-tolerant and are not designed, manufactured or intended for any use requiring fail-safe performance in which the failure of a Product could lead to death, serious personal injury, severe physical or environmental damage (“High Risk Activities”).”</p></blockquote>
<p>Medical device vendors  that  use Windows operating systems for less critical devices, or for the user interface are actually increasing the threat surface for a hospital, since any Windows host can be a carrier of malware that can take down the entire hospital network, regardless of it&#8217;s primary mission function, be it user-friend UI at a nursing station or intensive care monitor at the bedside.</p>
<p>Medical device vendors that use Microsoft IT systems management &#8220;best-practices&#8221; often  take the approach of &#8220;bolting-on&#8221; third party solutions for anti-virus and software distribution instead of developing robust, secure software, &#8220;from the ground up&#8221; with a secure design, threat analysis, software security assessment and secure software implementation.</p>
<p>Installing third-party security solutions that need to be updated in the field, may be inapplicable to an embedded medical device as the MDA (Medical Device Amendments of 1976) clearly states:</p>
<blockquote><p>These devices may enter the market only if the FDA reviews their design, labeling, and manufacturing specifications and determines that those specifications provide a reasonable assurance of safety and effectiveness. <em>Manufacturers may not make changes to such devices that would affect safety or effectiveness unless they first seek and obtain permission from the FDA</em>.</p></blockquote>
<p>It&#8217;s common knowledge that medical device technicians use USB flash drives and notebook computers to update medical devices in the hospital. Given that USB devices and Windows computers are notoriously vulnerable to viruses and malware, there is a reasonable threat that a field update may infect the Windows-based medical device. If the medical device is isolated from the rest of hospital network, then the damage is  localized, but if the medical device is networked to an entire segment, then all other Windows based computers on that segment may be infected as well &#8211; propagating to the rest of the hospital in a cascade attack.</p>
<blockquote><p>It&#8217;s better to get the software security right than to try and bolt in security after the implementation.Imagine that you had to buy the brakes for a new car and install them yourself after you got that bright new Lexus.</p></blockquote>
<p>It is not unusual for medical device vendors to fall victim to the same Microsoft marketing messages used with enterprise IT customers &#8211; &#8220;lower development costs, and faster time to market&#8221; when in fact, Windows is so complex and vulnerable that the smallest issue may take a vendor months to solve. For example &#8211; try and get Windows XP to load the wireless driver without the shell.   Things that may take months to research and resolve in Windows are often easily solved in Linux with some expertise and a few days work. That&#8217;s why you have professional medical device  software security specialists like <a title="Software security specialists for medical device vendors" href="http://www.software.co.il" target="_blank">Software Associates</a>.</p>
<p>With Windows, you get an application up and running quickly, but it is never as reliable and secure as you need.</p>
<p>With Linux, you need expertise to get up and running, and once it works, it will be as reliable and secure as you want.</p>
<p><a title="See this member's activity" href="http://www.linkedin.com/groups?viewMemberFeed=&amp;gid=3287843&amp;memberID=37404955">Yves Rutschle</a> says that <em>outlawing Microsoft Windows from medical devices in hospitatls  sounds too vendor-dependant to be healthy</em> (sic) <em>(</em>Seems to me that this would make the medical device industry LESS vendor-dependent, not more vendor-dependent, considering the number of embedded Linux options out there.)</p>
<p>Yves suggests that instead, the FDA should create a &#8220;<em>proper medical device certification cycle. If you lack of inspiration, ask the FAA how they do it, and maybe make the manufacturers financially responsible for any software failure impact, including death of a patient</em>&#8220;. (The FDA does not certify medical devices, they grant pre-market approval).</p>
<p>I like a free market approach but consider this:</p>
<ul>
<li>Bruce Schneier proposed adopting Federal legislation to make companies pay for security breaches &#8211; the proposal never got traction. Today, the Obama administration might adopt the idea as being in the same spirit of <a title="http://montanafirealliance.org/treasury-to-temporarily-penalize-mortgage-companies-making-good-on-old-threat/" href="http://montanafirealliance.org/treasury-to-temporarily-penalize-mortgage-companies-making-good-on-old-threat/" target="_blank">penalizing financial service providers for non-compliance</a>.</li>
<li>If the FDA has premarket approved a medical device, <a title="Common Law" href="http://en.wikipedia.org/wiki/Common_law" target="_blank">common-law claims</a> for negligence are not an option for consumers. See the <a title="Riegel vs Medtronic" href="http://www.law.cornell.edu/supct/html/06-179.ZS.html" target="_blank">Supreme Court ruling “Riegel v. Medtronic “, 2008</a> -</li>
</ul>
<blockquote><p>(<em>Held</em>)The MDA’s pre-emption clause bars common-law claims challenging the safety or effectiveness of a medical device marketed in a form that received premarket approval from the FDA. Pp. 8–17.</p></blockquote>
<p>Maybe the FDA <strong><em>should </em></strong>learn from the FAA but in the meantime, it seems to me if the FDA pre-market validation process had an item requiring a suitable operating system EULA, that would pretty much solve the problem.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.software.co.il/2011/06/why-microsoft-windows-is-a-bad-idea-for-medical-devices/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Night walking on the freeway</title>
		<link>http://www.software.co.il/2009/11/night-walking-on-the-freeway/</link>
		<comments>http://www.software.co.il/2009/11/night-walking-on-the-freeway/#comments</comments>
		<pubDate>Mon, 23 Nov 2009 10:28:53 +0000</pubDate>
		<dc:creator>Danny Lieberman</dc:creator>
				<category><![CDATA[Physical security]]></category>
		<category><![CDATA[Risk mitigation]]></category>

		<guid isPermaLink="false">http://www.software.co.il/wordpress/?p=2162</guid>
		<description><![CDATA[Ian Fleming once remarked how American road signs were so sexy &#8211; &#8220;winding curves&#8221; and &#8220;soft shoulders&#8221;. I was thinking of Ian Fleming  taking an unexpected 5K walk at night on the shoulders of a 6 line freeway. Last night I was driving my daughter&#8217;s car on Route 6.   There was a leak in the ...]]></description>
			<content:encoded><![CDATA[<p>Ian Fleming once remarked how American road signs were so sexy &#8211; &#8220;winding curves&#8221; and &#8220;soft shoulders&#8221;.</p>
<p>I was thinking of Ian Fleming  taking an unexpected 5K walk at night on the shoulders of a 6 line freeway.</p>
<p>Last night I was driving my daughter&#8217;s car on Route 6.   There was a leak in the water pump, engine overheated and I stopped by the side of road and called a tow.</p>
<p>Visualize.  Route 6 South, 2km before the Kfar Daniel interchange. 7pm at night</p>
<p>The tow company (Derachim) told me &#8211; up to 3 hours + 60 sheqel surcharge for service on Route 6 &#8211; they asked me how I would like to pay and I said &#8211; &#8220;cash&#8221;.  After 1 1/2 hours &#8211; the tow shows up, takes the car and instead of taking the car (and me) to our garage in Shilat &#8211; he left me by the road side and drove off &#8220;to pick up another car in Rishon&#8221;.    I started walking, after a brisk 5 km hike &#8211; I got a ride from a woman who stopped by the side to change her shoes&#8230;. I got my wife on the horn and we rendezvou&#8217;d at the gas station at Latrun.</p>
<p>The icing on the cake was a series of phone messages on my cell from the tow company at 1130 pm &#8211; saying that they understood I was supposed to pay the Route 6 surchage by credit card&#8230;.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.software.co.il/2009/11/night-walking-on-the-freeway/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Jennifer Lopez Joins the Fight Against Pertussis</title>
		<link>http://www.software.co.il/2009/10/jennifer-lopez-joins-the-fight-against-pertussis/</link>
		<comments>http://www.software.co.il/2009/10/jennifer-lopez-joins-the-fight-against-pertussis/#comments</comments>
		<pubDate>Wed, 14 Oct 2009 07:47:29 +0000</pubDate>
		<dc:creator>Danny Lieberman</dc:creator>
				<category><![CDATA[Information security]]></category>
		<category><![CDATA[Physical security]]></category>
		<category><![CDATA[Jennifer Lopez]]></category>
		<category><![CDATA[Sanofi-Pasteur]]></category>

		<guid isPermaLink="false">http://www.software.co.il/wordpress/?p=2010</guid>
		<description><![CDATA[Help protect your baby by protecting yourself. Our daughter and son-in-law stayed with us over the weekend recently &#8211; listening to one of the babies cough, I realized that there is a lot more to life than enterprise information protection and cost-effective data loss prevention.]]></description>
			<content:encoded><![CDATA[<p>Help protect your baby by protecting yourself. Our daughter and son-in-law stayed with us over the weekend recently &#8211; listening to one of the babies cough, I realized that there is a lot more to life than enterprise information protection and cost-effective data loss prevention.<br />
<object classid="clsid:d27cdb6e-ae6d-11cf-96b8-444553540000" width="425" height="344" codebase="http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab#version=6,0,40,0"><param name="allowFullScreen" value="true" /><param name="allowscriptaccess" value="always" /><param name="src" value="http://www.youtube.com/v/T6VQt_kpn2M&amp;hl=en&amp;fs=1&amp;" /><param name="allowfullscreen" value="true" /><embed type="application/x-shockwave-flash" width="425" height="344" src="http://www.youtube.com/v/T6VQt_kpn2M&amp;hl=en&amp;fs=1&amp;" allowscriptaccess="always" allowfullscreen="true"></embed></object></p>
]]></content:encoded>
			<wfw:commentRss>http://www.software.co.il/2009/10/jennifer-lopez-joins-the-fight-against-pertussis/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Clear and present danger &#8211; on a bike.</title>
		<link>http://www.software.co.il/2009/08/clear-and-present-danger-on-a-bike/</link>
		<comments>http://www.software.co.il/2009/08/clear-and-present-danger-on-a-bike/#comments</comments>
		<pubDate>Wed, 05 Aug 2009 15:20:51 +0000</pubDate>
		<dc:creator>Danny Lieberman</dc:creator>
				<category><![CDATA[Mountain biking]]></category>
		<category><![CDATA[Physical security]]></category>
		<category><![CDATA[bike]]></category>
		<category><![CDATA[bike helmet]]></category>

		<guid isPermaLink="false">http://www.software.co.il/wordpress/?p=1739</guid>
		<description><![CDATA[Walking down the street this afternoon &#8211; I could not believe my eyes. I see this  bike streak by down the main street. A father riding a bike (with a helmet) and baby in back seat (with helmet) &#8211; talking on a cell phone. Now That&#8217;s Foolish and Dangerous.]]></description>
			<content:encoded><![CDATA[<p>Walking down the street this afternoon &#8211; I could not believe my eyes.</p>
<p>I see this  bike streak by down the main street.</p>
<p>A father riding a bike (with a helmet) and baby in back seat (with helmet) &#8211; talking on a cell phone.</p>
<p>Now That&#8217;s Foolish and Dangerous.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.software.co.il/2009/08/clear-and-present-danger-on-a-bike/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Swine flu and social networking</title>
		<link>http://www.software.co.il/2009/07/swine-flu-and-social-networking/</link>
		<comments>http://www.software.co.il/2009/07/swine-flu-and-social-networking/#comments</comments>
		<pubDate>Wed, 29 Jul 2009 11:38:25 +0000</pubDate>
		<dc:creator>Danny Lieberman</dc:creator>
				<category><![CDATA[Physical security]]></category>
		<category><![CDATA[Pharmaceutical]]></category>

		<guid isPermaLink="false">http://www.software.co.il/wordpress/?p=1720</guid>
		<description><![CDATA[It just occurred to me &#8211; as our partner in Poland was getting ready to drive from Warsaw to Łęczyca for a sales call &#8211; that novel H1N1 (swine flu) and seasonal influenza is a great reason to use social media and Web conferencing for customer contacts, sales and support and reduce physical contact and ...]]></description>
			<content:encoded><![CDATA[<p>It just occurred to me &#8211; as our partner in Poland was getting ready to drive from Warsaw to Łęczyca for a sales call &#8211; that novel H1N1 (swine flu) and seasonal influenza is a great reason to use social media and Web conferencing for customer contacts, sales and support and reduce physical contact and risk of exposure.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.software.co.il/2009/07/swine-flu-and-social-networking/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>The threat behind the House Tri-Committee Bill on Health Care</title>
		<link>http://www.software.co.il/2009/07/the-threat-behind-the-house-tri-committee-bill-on-health-care/</link>
		<comments>http://www.software.co.il/2009/07/the-threat-behind-the-house-tri-committee-bill-on-health-care/#comments</comments>
		<pubDate>Fri, 24 Jul 2009 12:25:29 +0000</pubDate>
		<dc:creator>Danny Lieberman</dc:creator>
				<category><![CDATA[Physical security]]></category>
		<category><![CDATA[business threat modeling]]></category>
		<category><![CDATA[data loss prevention]]></category>
		<category><![CDATA[DLP]]></category>
		<category><![CDATA[Pharmaceutical]]></category>
		<category><![CDATA[Risk and strategy]]></category>
		<category><![CDATA[Risk management]]></category>
		<category><![CDATA[Social Networking]]></category>

		<guid isPermaLink="false">http://www.software.co.il/wordpress/?p=1668</guid>
		<description><![CDATA[Don&#8217;t ask me why, but I was invited (and joined) the Pakistan Networkers group on LinkedIn.  I see all kinds of cool job opportunities in the Emirates which I can&#8217;t really take but the traffic is interesting. I saw this picture in a post today from the Pakistan Networkers group. It graphically describes the complexity ...]]></description>
			<content:encoded><![CDATA[<p><img class="alignright size-medium wp-image-1669" title="Obama Healthcare" src="http://v20/wp-content/uploads/2009/07/healthcarechart-266x300.jpg" alt="Federal Healthcare Chart" width="266" height="300" /></p>
<p>Don&#8217;t ask me why, but I was invited (and joined) the Pakistan Networkers group on LinkedIn.  I see all kinds of cool job opportunities in the Emirates which I can&#8217;t really take but the traffic is interesting.</p>
<p>I saw this picture in a post today from the Pakistan Networkers group. It graphically describes the complexity of ObamaCare:  the Obama health care reform bill.   I then sat down and started to learn more about this proposed solution to the US health care system that will cost over a trillion dollars in the next 10 years.</p>
<p>The Obama Health plan and the problems the administration is currently facing getting it through Congress is second page news here in Israel (front pages this weekend in Israeli papers are how Obama and Rahm are throwing their weight around and dictating to the Jews where they can live and not live&#8230;.)</p>
<p>I started reading about the <a title="ObamaHealth" href="http://angrybear.blogspot.com/2009/07/house-tri-committee-health-care-bill.html" target="_blank">House Tri-committee Health Care bill</a> and my eyes started popping at the cost and complexity of the proposal. I then read the response of the Mayo Clinic &#8211; <a title="Mayo Clinic response to Obama Health" href="http://healthpolicyblog.mayoclinic.org/2009/07/16/mayo-clinic%E2%80%99s-reaction-to-house-tri-committee-bill/" target="_blank">Mayo Clinic’s reaction to House Tri-Committee bill</a> and I finally realized that just like in Cyber Security and data loss prevention &#8211; the Obama administration is <strong>more interested in compliance and big government than customers and health, safety and security.<br />
</strong></p>
<p>I&#8217;ve been arguing for basing data security product purchasing decisions on value at risk and cost-effectiveness of the DLP product in reducing the value at risk of a data breach. Therefore, it is  obvious to me that the notion of a value-based decision is an important cornerstone in <a title="Redefining health care" href="http://www.hbs.edu/rhc/" target="_blank">redefining health care</a> &#8211; see a discussion on pay for value in health care in the <a title="Pay for Value" href="http://healthpolicyblog.mayoclinic.org/2009/07/22/open-letter-to-congress/" target="_blank">open letter to congress</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.software.co.il/2009/07/the-threat-behind-the-house-tri-committee-bill-on-health-care/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Reducing risk of major data loss events</title>
		<link>http://www.software.co.il/2009/06/soaring-cryptography-and-nuclear-weapons/</link>
		<comments>http://www.software.co.il/2009/06/soaring-cryptography-and-nuclear-weapons/#comments</comments>
		<pubDate>Thu, 18 Jun 2009 18:58:08 +0000</pubDate>
		<dc:creator>Danny Lieberman</dc:creator>
				<category><![CDATA[Physical security]]></category>
		<category><![CDATA[Risk Assessment]]></category>
		<category><![CDATA[Risk management]]></category>
		<category><![CDATA[Risk mitigation]]></category>
		<category><![CDATA[Data retention]]></category>
		<category><![CDATA[Homeland Security]]></category>
		<category><![CDATA[Islamic Terror]]></category>
		<category><![CDATA[nuc]]></category>
		<category><![CDATA[Obama]]></category>
		<category><![CDATA[Palestinian violence]]></category>

		<guid isPermaLink="false">http://www.software.co.il/wordpress/?p=1542</guid>
		<description><![CDATA[Martin Hellman (of Diffie Hellman) fame maintains the Nuclear Risk web site and has written a very insightful piece on risk analysis of nuclear war entitled Soaring, cryptography and nuclear weapons Hellman proposes that we need a  third state scenario (instead current state &#8211; &#62; nuclear war) where the risk of nuclear holocaust has been ...]]></description>
			<content:encoded><![CDATA[<p>Martin Hellman (of Diffie Hellman) fame maintains the Nuclear Risk web site and has written a very insightful piece on risk analysis of nuclear war entitled <a title="Soaring" href="http://nuclearrisk.org/soaring_article.php" target="_blank">Soaring, cryptography and nuclear weapons</a></p>
<p>Hellman proposes that we need a  third state scenario (instead current state &#8211; &gt; nuclear war) where the risk of nuclear holocaust has been reduced by several orders of magnitude from today to an acceptable level.</p>
<p>This makes sense and it&#8217;s an intriguing idea as an exercise in risk analysis of information security and data protection to see if there is a third state of reduced risk that where the risk of data breach and major data loss events is reduced to acceptable levels.</p>
<p>That&#8217;s one thing that got me thinking.</p>
<p>The second thing is the quote from Fyodr Burlatsky, one of Khrushchev&#8217;s speechwriters and close advisors, as well as a man who was in the forefront of the Soviet reform movement:</p>
<blockquote><p>In Krushchev&#8217;s eyes [America insisting on getting its way on certain issues] was not only an example of Americans&#8217; traditional strong arm policy, but also an underestimation of Soviet might. &#8230; Khrushchev was infuriated by the Americans&#8217; &#8230; continuing to behave as if the Soviet Union was still trailing far behind.</p></blockquote>
<p>So here we are &#8211; 2009 and President Obama is insisting on getting his way <em>on certain issues</em> with the  Iranians, who pose a serious nuclear threat to the world.  But no only Ahmadenijad &#8211; the Russians and the North Koreans are also  infuriated by the Americans&#8217; &#8230; continuing to behave as if they are still trailing far behind.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.software.co.il/2009/06/soaring-cryptography-and-nuclear-weapons/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

