Are sw bugs taxing your resilience ..?

There would be a solution when we’d find a way to tax software makers for their product faults.

Because caveat emptor can work only if unlike in softwareland, one can duly (!) examine the product before purchase otherwise-and-anyway culpability for hidden flaws remains with the seller/licensor.

Which is impossible with shrink-wrapped stuff — and the ‘license’ claim is ridiculous, moreover the EULA is inconsistent hence null and void: Either the product is used under license hence the product quaility liability remains with the producer/licensor or the licensee is liable for damages the use of the product might cause but then invariably ownership is with the purchaser.

The software maker can’t have their cake and eat it; that would run against basic legal principles. And claiming that one’s always allowed to not use the product and choose another one or not, the Hobson’s Choice that brings about so many legal ramifications that even $AAPL’s pockets would never suffice, would invariably lead to oligopoly/cartel charges …!

Or, as this may easily be solved when taken as a societal problem just like environmental stuff like CO2 pollution (we all need electricity): Why not tax the software makers for their ‘pollution’ of the IS environment with bugs ..? (And prohibit the use of greenhouse gases like SQL injection weaknesses?)
Like, after post-write but before release, this (Dutch) news that casual carelessness is a headache for government(s)… A bit like driving rules with no enforcement, maybe ..?

I’m not one for fighting the real windmills… hence:
dsc_0099
[The outards of the inn(ard)s of courts; Bridget’s London obviously]

Simply, stats

Just putting it down there.

With some discussion, OK, OK…:

  • Fubbuck still the largest, “of course”, but by less of a margin than previous (?);
  • Because FB ‘messenger’ oh horrendous thing, is listed separately. Prob with reason. At least, because reasons;
  • QQ and QZone still biggies, to grow ..!?
  • Tumblr’s big this time. Let’s dig for demographics, et al., to see whether some specific user group is biasing stats. The age-old subject that the Internet was invented and invaded for, may be a big one in this;
  • LinkedIn larger than Pinterest. A #first ..? And not by much. Cause? Sturdy growth, hanging in there, holding out and succeeding by others falling back; or has some take(n)-over played a role here …?
  • Insta quite big but maybe not living up to the hype (or what’s its growth), Snapchat rather flat. Is Millennialhyping a thing from the past already ..?

statistic_id272014_most-famous-social-network-sites-2016-by-active-users

Contra Bruce, for once

For once, Bruce is not at the right end. Maybe not opposite of it, but.
As per this here blog post of his — a repeat of one of his, and others’, thread.

The argument: We make things, like, security, too difficult for users and hence (?) we shouldn’t try to change them into secure behaviour.
The contra: ‘Guns kill people’, or was it that the men (mostly) firing guns, kill people? And the many toddlers shooting their next of kin since, being at the approximate maturity of the Original gun pwner, they have no clue.

The Contra, too, and much more to the point when it comes to ‘information’ ‘security’: We should make cars run at maximum 5Mph … Since ‘users’ are waaaay too stupid to drive carefully.
Just don’t mention that ‘security’ is a quality not an absolute pass-or-fail thing, and that ‘information’ could not be more vague. [Except ‘cyber’, that’s so vacated of any meaning that it’s a black hole.] And don’t mentoin we still seem to let cars be used by any other moron that once, possibly literally decades ago before ‘chips’ were invented, passed some formal test — the American idea of the test coming very, dangerously, close to … was (sic) it the Belgian? system where one could pick up one’s driver’s license at the post office. Able, allowed, to buy cars that drive not just 5 but 250Mph, on busy roads, without protection against using socmed mid-traffic… One thing could be to introduce Finnish-style booking for unsafe behaviour (if caught, not when as per next paragraph [think that through…]), and/or huge fines for the producers of bad equipment (hw/sw) comparable to fines on car makers, or outright laws to build airbags in, etc.

And then, if we’d design ‘secure’ systems, e.g., the Apple way, we’d end up with even worse Shallows sheeple that have so much less clue than before… And all in the hands of … even in ultra-liberal countries one would suggest either Big Corp, or Big Gov’t, both options being Big Brother literally in such an atrocious Dystopia of humanity.

So, you want safe systems? You get the loss of humanity before actual safety.

[Yes I get the Humans Are The Cause Of Much Infosec Failure thing (including Human Flexibility Can (still!) Solve More Than Machines Can, Against System (!) Malfunction), but also I am completely in favour of both the Humans Must Through Tech Be Completely Shielded From Being Able To Do Anything Wrong and Humans Should Retain All Freedom To Act Responsibly solutions.]

Pick your stand. And:

[Use G Translate if you have to, from Dutch. Typifying the driver, probably, if only for picking the brand/car…; London]

You sporting against all

When sports are considered to be character-forming for later (mostly assumed to be business-)life, either by having been trained to be competitive or have learned (really?) to cooperate in teams (really?), let’s see which versions there are:
business
In which the You Against Natural science (No counter-actors other than nature, only personal performance counts, possibly measured against others but still, bad luck gets you), You Against One opponent (where one’s in a knock-out tournament or variant; running into the later champion in the first round doesn’t do much for your chances for second place), and Team Against Team (if you’re a champ in a bad team, fuggeddaboudit; the other way around too, like Leicester City…), are all too well known, with the ‘character formation’ mostly being: Either you win or are a loser, and Suck It Up The Other Guy(‘)s Much Better.

But in business … Be careful not to think that it’s a team-to-team competition. Yes, you may assemble, or join, a team, but you’re playing against … the Market. Not another team … Unless the very unusual situation of a duopoly, which should be breakable, legally.
Rather, you’re up against ‘everything out there’; can count only on one’s own errors, not count on the luck of anything out there working your way though they sometimes do. And the character building/application is … well, mostly about you not being Hercules.

Well, if you think you are the big Heracles himself, note that your Impostor Syndrome is no illusion. The Wonder CEO that thinks he’s in the bottom right corner, is deluded to not see that it’s not all the underlings (certainly the sycophants) in a Team against him (seldomly her), in an internal struggle much larger than any competitive fight out there. But that all those one’s up against, are the Team in the top left corner, though possibly having ousted him for displaying anti-team play morals…

Talking of big business: What sport would have massive teams of hundreds, thousands, hundred thousands of players on either side ..!? With all specialised in their own little square foot of the playing field ..? At best, one has such armies with the classical mercenaries — and even they were, are, organised much more effectively. The military discipline of the multinational überbureaucracies will fail in the murk out there, certainly when one’s not against one specific opponent, as above.
‘Normal’ teams in sports are, ballpark, smaller than 20 players, all maybe having designated tasks but always all (of the winning teams) have the flexibility to step out of their role and position, with team mates catching the blind spots. As if that ever happens in business-outside-the-startup-scene. The closest to actual normal business, would be athletics teams, all with their specialties, contributing to the total, the satisfaction of having succeeded as a team winning out over the satisfaction of personal performance over team gains.

So, what was that about through (‘high school’/university age) (team) sports, would one breed character for the real world ..? If one does sports, obviously it should‘nt be for that reason but for the joy of it. ‘Character building’ as an argument shows one has no clue.

Plusquote: Beaton

Be daring, be different, be impractical, be anything that will assert integrity of purpose and imaginative vision against the play-it-safers, the creatures of the commonplace, the slaves of the ordinary.

Thus wrote sir Cecil Beaton.

And right he was. And is, and will be, more than before. Since times are a’changing ever faster, too. Which means the risk, nay certain penalty of not venturing out into the future by one’s own action, increases by the day, as well. Live, or not — the characterisation of those of the ordinary is apt.

With thoughtful salutations, I thee present:
dsc_0043
[One feels invited to have to wait here, only; Royal waiting room entrance, Amsterdam CS]

You're Exposed…

You haven’t studied this here overview hard enough. Because you’re not even on it so shows your lack of will to enormously improve the seriousness of your (clients’) information security which would get you onto the list, just. Your security being too much of a joke to even achieve this level of honest attempt at seriousness.

ig_nobel_stinker_serif_icon_400x400

Teh business, does it exist ..?

On purpose, teh. Plus a spoiler: No.

Though this is a tell-tale sign your infosec program, of whatever kind, will #fail, wholesale.
’cause If you can’t specify all stakeholders, at their various levels of detail required, beyond swiping them up under the ‘the business’ nomen, Then you might as well call it ‘teh’ business, as you are vague to the point of irrelevance, as you will be regarded by ‘the business’ and since that’s where 99.9% of your security sits (including budget holders…), fugeddabout effectiveness.
Endif. No Else.

So, stop using ‘the business’ as a stopgap designation for your lack of understanding of the infosec problems that you claimed you could tackle hence you demonstrate to know no thing about the swamp of root causes to the problems that you said to go solve.
You n00b.

Oh well…:
dscn1150
[Some specific business; Madrid]

Data Classinocation

I was studying this ‘old’ idea of mine of drafting some form of impact-based criteria for data sensitivity when, along with a couple of fundamental logical errors in some of the most formally adopted (incl legal) standards and laws, I suddenly realised:

In these times of easily provable easy de-anonymisation of even the most protective homomorphic encryption multiplied with the ease of de-anonymisation throught data correlation of even the most innocent data points, all even the most innocent data points/elements must (not should) be classified at the highest sensitivity levels so why classifiy data ..!?

This may not be a popular point, but that doesn’t make it less true.
In similar vein, in European context where one is only to process data in the first place if (big if) there is no alternative and one can process for the Original intent and purpose only,

To prevent data from unauthorised disclosure internally or externally, without tight need-to-know/need-to-use IAM implementation, one already does too little; with, enough.

That’s right; ‘internal use only’ is waaay too sloppy hence illegal — it breaks the legal requirement for due (sic) protection, and if the use of data is, ‘by negligence’ not changing a thing here, let possible, the European privacy directive (and its currently active precursors) do not allow you to even have the data. This may be a stretch but is still understandable and valid once you take the effort to think it through a bit.
Maybe also not too popular.

Needless to say that both points will not be understood the least by all the ‘privacy officer’ types that have rote learned the laws and regulations, but have no experience/clue how to actually use those in practice and just wave legal ‘arguments’ (quod non) around as if that their (song and) dance is the end purpose of the organisation but cannot answer even the most simple questions re allowablity of some data/processing with anything that logically or linguistically approaches clarity. [Note the ‘or’ is a logical one, not the sometimes interpreted xor that the too-simpletons (incl ‘privacy officers’) interpret but don’t know exists.]

OK. So far, no good. Plus:
dscn0990
[Not a fortress, nor a real maze once you see the structure; Valencia]

Waves of cyberfud

Not just because #ditchcyber is real. But because only now, the first of the absolute leggards (i.e., gov’t officials) begin to make waves about access to private data, through apparent (sic) complete lack of understanding about the fundamentals of free society. The issue of blanket access to any communications, for whatever purpose, has been settled so shut up for eternity or however much longer it takes ‘you’ to get it or die — whichever comes first, my guess is the latter.

Politics being the only field of work where no education is required; all the cyber-blah being the second, then, apparently ..? And:

dscn1128
[He would have annihilated the little people that clamour for ‘backdoors’, etc., et al.; DC]

World Animal Day: a disruptive Whale

Because today is World Animal Day, let’s think of the Whale.
hqdefault
Because this is the kind of disruption your brain needs. Today, and any day.
Yes the clip is ‘Old’ — but still fresh; how’s that you Under-30-or-younger hunting faux headhunters that still, en masse (over 99,5% at least) hunt for dummies (car crashing kind) to fill dummy slots in Bureaucratia.

That’s all. And do check the vid at least until 2:42 Because Reasons.

Maverisk / Étoiles du Nord