Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Vista
Interview with Marcus Ranum
Federico Biancuzzi, 2005-06-21

Comments Mode:
Good! 2005-06-21
Anonymous
Interview with Marcus Ranum 2005-06-21
Steve Lodin
Interview with Marcus Ranum 2005-06-22
Anonymous (1 replies)
Re: Interview with Marcus Ranum 2005-06-22
Marcus Ranum
If the CTOs of 10 FORTUNE 500 firms .... 2005-06-22
Andrew Yeomans
Interview with Marcus Ranum 2005-06-22
some guy in Central PA (1 replies)
Re: Interview with Marcus Ranum 2005-06-22
Marcus Ranum (1 replies)
Interview with Marcus Ranum 2005-06-22
Anonymous
Interview with Marcus Ranum 2005-06-22
Anonymous (1 replies)
Re: Interview with Marcus Ranum 2005-06-22
Marcus Ranum (2 replies)
Re: Re: Interview with Marcus Ranum 2005-06-22
Anonymous (1 replies)
Re: Re: Re: Interview with Marcus Ranum 2005-06-23
Marcus Ranum (1 replies)
Blame 2005-06-22
Anonymous (1 replies)
Re: Blame 2005-06-22
Marcus Ranum
That's a really good point and I didn't consider it. :( In fact, I wish you'd been a reviewer on the early draft of the interview because I'd have loved to address that issue. :(

Blame does not mean you have the power to fix things. :(

In other contexts I've pointed out that CTOs have (for the last 10 years or so) ignored their responsibilities to build secure robust networks. What about that is NOT under the purview of a competent CTO? CTOs need to be held accountable by senior management (CEO/board of directors) and terminated if they aren't competent. In my opinion a CTO that fields a wireless deployment because they read a bunch of press releases about how keeewl it is and never looked at security - is incompetent. A lot of IT managers in the federal sector are (again, myo opinion) professionally negligent in how they have ignored security. All of these clowns need to be given pink slips.

Vendors need to be held accountable to standards of excellence but it's the customer who can do the most to change the current situation. They control the money. Don't buy crap - defer your payments until the vendors give you satisfactory answers. The free market will help correct the situation that way.

Vendors also need to be held liable if they make inaccurate claims. There are already legal constructs in place for doing so but they are not being employed. For example, I think it's ludicrous that Microsoft has flash-screens during the Windows XP install that claim "now you can access the internet fast and securely..." What? The FTC should fine them for making such a ridiculous claim. Again, this is an area where the customers hold (but aren't exercising) the power. Customers could make a huge difference very quickly if they stopped buying products that had EULAs that absolve the vendor of all responsibility for poor quality.

So - if the hackers are the least likely to fix the problem, then the people who are the most likely to be able to fix it are the customers. They have the money, after all, and the vendors are fundamentally answerable to their wishes. That's the only place where a revolution could start that might make an improvement - but I've seen zero trace of clue emerging in the customer community - they're still busy sucking down the marketing and buying based on hype.

mjr.

[ reply ]

Link to this comment: http://www.securityfocus.com/comments/columns/334/32034#32034
Interview with Marcus Ranum 2005-06-22
Anonymous
What a genius! 2005-06-22
Pete (4 replies)
Re: What a genius! 2005-06-22
Anonymous (1 replies)
Re: Re: What a genius! 2005-06-27
Anonymous
Re: What a genius! 2005-06-22
Marcus Ranum
Re: What a genius! 2005-06-23
Anonymous
Re: What a genius! 2005-06-23
Anonymous
Interview with Marcus Ranum 2005-06-22
B Maurice
Interview with Marcus Ranum 2005-06-22
Anonymous (1 replies)
Re: Interview with Marcus Ranum 2005-06-22
Marcus Ranum
Interview with Marcus Ranum 2005-06-22
Anonymous
Interview with Marcus Ranum 2005-06-22
Anonymous
Interview with Marcus Ranum 2005-06-22
Anonymous
Interview with Marcus Ranum 2005-06-22
Tails (2 replies)
Re: Interview with Marcus Ranum 2005-06-22
Anonymous
Re: Interview with Marcus Ranum 2005-06-22
Marcus Ranum (7 replies)
Re: Re: Interview with Marcus Ranum 2005-06-23
Anonymous (1 replies)
Re: Re: Interview with Marcus Ranum 2005-06-25
rabidpacketmonkey
Re: Re: Interview with Marcus Ranum 2005-06-28
Norman Yarvin
Interview with Marcus Ranum 2005-06-22
trip (1 replies)
Re: Interview with Marcus Ranum 2005-06-23
Marcus Ranum
Good Article 2005-06-22
JC
What A Total Jackass 2005-06-22
Anonymous (1 replies)
Re: What A Total Jackass 2005-06-23
Marcus Ranum (1 replies)
Re: Re: What A Total Jackass 2005-06-29
Anonymous
Marcus Ranum blaming hackers???? 2005-06-22
pw (2 replies)
Re: Marcus Ranum blaming hackers???? 2005-06-23
Marcus Ranum
no, blame the victims 2005-06-24
Anonymous
SE/Linux 2005-06-22
Luke Kenneth Casson Leighton (1 replies)
Re: SE/Linux 2005-06-29
Anonymous
Interview with Marcus Ranum 2005-06-23
Rastor5
Interview with Marcus Ranum 2005-06-23
Anonymous
distribution of responsability is well put 2005-06-23
Martin-Éric Racine
Interview with Marcus Ranum 2005-06-23
Anonymous
Blame the Hackers? 2005-06-23
Bob (1 replies)
Re: Blame the Hackers? 2005-06-29
Marcus Ranum
Interview with Marcus Ranum 2005-06-24
Phil Agcaoili
his comments about the RFC process 2005-06-24
Reinier Post
Interview with Marcus Ranum 2005-06-24
Anonymous (2 replies)
Re: Interview with Marcus Ranum 2005-06-27
M. Andrew Molitor
Re: Interview with Marcus Ranum 2005-06-28
Anonymous (1 replies)
Interview with Marcus Ranum 2005-06-27
Anonymous (1 replies)
Re: Interview with Marcus Ranum 2005-07-11
Anonymous
80% spyware & 15% keyloggers? 2005-06-28
Anonymous
Interview with Marcus Ranum 2005-06-28
Anonymous (1 replies)
Re: Interview with Marcus Ranum 2005-06-29
Marcus Ranum
Interview with Marcus Ranum 2005-06-29
David
Agressive network configuration 2005-07-05
Stephen T
Interview with Marcus Ranum 2005-07-06
Anonymous
Think about it... 2005-07-16
Johann van Duyn
Interview with Marcus Ranum 2007-07-11
John Cowan
Interview with Marcus Ranum 2007-11-27
Anonymous







 

Privacy Statement
Copyright 2008, SecurityFocus