Monday, April 27, 2009
PCI Whitepaper
I wrote a paper on PCI compliance titled "The 5 claims of PCI DSS snake oil salesmen", which is now being run by ThreatPost. Enjoy!
Friday, March 27, 2009
NYTimes calls Tripwire a fall hazard
The venerable NY Times is reporting that the Tripwire used at home can be a fall hazard. However, Tripwire at home offers many advantages (health and emotional benefits) unlike the product used in the Enterprise which has often delivered severe emotional shocks to many customers.
Solidcore has ample evidence that Tripwire Enterprise customers have suffered from different types of shocks including, but not limited to, sticker-shock, pci-coverage-shock and bloatware-shock. Sticker shock hits the customers when they are presented the first quote after the initial demo. Tripwire has recently managed to alleviate the pain caused by this shock through deep discounting of prices.
PCI coverage shock is a recent phenomenon and affects customers who are looking for PCI compliance solutions. At the outset, this shock makes everyone think they were stupid to deploy anti-virus and run vulnerability scans and penetration testing as mandated in PCI DSS sections 5, 11.2 and 11.3. After all, they could have achieved the same using Tripwire had they thought about it at first. However, this shock dampens once the QSAs and other vendors point out that Tripwire's PCI coverage whitepaper is not worth the paper it is printed on.
Bloatware shock is experienced only by customers who have used Tripwire in the past. After-effects of this shock include incredulity and deep anger that Tripwire has not introduced any significant changes to their UI or feature set in the last 10+ years in business. The few features that were added, including Configuration Assessment capability, have made the product more complicated and difficult to use than ever before. Tripwire's marketing department claims that only a minority of customers will suffer from this shock as there are more people who have not used Tripwire than those who have.
These reports have been confirmed by analysts from top-tier firms like Gorretner and the 911 group. Tim Ikestotalk from Gorretner says "It is unrealistic for customers to expect that a product named Tripwire will not deliver shocks. The name itself was chosen to signify how administrators will be shocked whenever they perform tasks that are anything but the most standard and mundane ones". The 911 group adds "Tripwire has been extremely successful in pulling the wool over customers eyes when it comes to PCI coverage. We have been receiving many calls from customers who feel cheated by Tripwire, but we can understand Tripwire's behavior. In these hard economic times, it is indeed very difficult to sell a product that offers so little to so few for such a high cost". Clearly, as the NYTimes puts it "no one had looked at this. It was all anecdotal." Until now, that is.
Names of all characters in this article have been changed to protect them from receiving shocks
Friday, February 13, 2009
Cloud Computing
Having worked for a Grid computing startup has made me a big skeptic about whatever new marketing umbrella the idea gets resurrected under. As you probably guessed, its latest incarnation is called cloud computing.
Here's a witty video that tries to make the concept of cloud computing less cloudy. Hope you enjoy it.
Here's a witty video that tries to make the concept of cloud computing less cloudy. Hope you enjoy it.
Monday, November 10, 2008
Product Development Process
I chanced upon this document by Laurie in which she describes a typical product development process. We follow a very similar process, except that the MRD is seldom a formal document. Based on the analysis of market requirements from various sources as described here, we write the PRD. The UI mockups are done by our UI designer who works closely with the Product Managers to understand the workflows.
When there is a need to change the layout or the UI elements, our designer provides a static mockup. For workflows, we use Axure Pro, a wonderful wire-framing/prototyping product. Axure allows us to place UI elements, create links to other pages and design a prototype that is easy for our developers to play with and understand. There are two main advantages in using such a prototyping tool -
When there is a need to change the layout or the UI elements, our designer provides a static mockup. For workflows, we use Axure Pro, a wonderful wire-framing/prototyping product. Axure allows us to place UI elements, create links to other pages and design a prototype that is easy for our developers to play with and understand. There are two main advantages in using such a prototyping tool -
- It forces us, the Product Managers, to think through the design a lot more. When only static mockups are provided, the development team has to many assumptions about various corner cases. Given the distance and timezone differences, it is not always possible to validate these assumptions. However, PMs have to address many of the corner cases when designing dynamic mockups and this reduces the gap between what PMs want and what development thinks PMs want. See here for details.
- These mockups can be used to demo upcoming features to prospects and customers. Axure prototypes look very similar to the real software and helps us get advance feedback about workflows and features that we are planning for future releases.
Monday, October 13, 2008
100% protection against viruses and malware?
My wife's laptop recently got infected with malware, despite running an up to date version of a leading anti-virus and a spyware detector. Coincidentally, both these vendors have offices in the same street in which my wife works. Wish she could take the laptop over and tell them how badly their products suck. However, reality meant that I had to troubleshoot and fix the problem. After trying out a few other free anti-viruses and malware, none of which seemed to detect/fix the issue, I found Spyware doctor. A fantastic tool that found and fixed the problem - I ended up purchasing a 5-pack license for all our computers at home.
While on that topic, Solidcore's product was tested against nearly 16,000 viruses and malware by NSS labs. The results are available from our website here. We prevented 100% of these viruses, worms and malware. Needless to say, we were thrilled when we heard this and had celebrated in a big way. We are seeing a tremendous uptick in the demand for this product and there has never been as much excitement at Solidcore before.
Just in case you were wondering why I did not put our product on my wife's computer - I'd have done so had it not been her company issued laptop :)
Update on 10/14 - Shortly after I posted this entry, Secunia, an independent testing firm had released the results of their security tests. Symantec won, but Secunia claims in their blog entry that "Even the "high" score from Symantec was disappointing. Symantec detected a mere 64 out of 300 exploits, or less than one-fourth, leaving 236 exploits undetected!" and the report concludes alarmingly thus - "These results clearly show that the major security vendors do not focus on vulnerabilities. Instead, they have a much more traditional approach, which leaves their customers exposed to new malware exploiting vulnerabilities."
While on that topic, Solidcore's product was tested against nearly 16,000 viruses and malware by NSS labs. The results are available from our website here. We prevented 100% of these viruses, worms and malware. Needless to say, we were thrilled when we heard this and had celebrated in a big way. We are seeing a tremendous uptick in the demand for this product and there has never been as much excitement at Solidcore before.
Just in case you were wondering why I did not put our product on my wife's computer - I'd have done so had it not been her company issued laptop :)
Update on 10/14 - Shortly after I posted this entry, Secunia, an independent testing firm had released the results of their security tests. Symantec won, but Secunia claims in their blog entry that "Even the "high" score from Symantec was disappointing. Symantec detected a mere 64 out of 300 exploits, or less than one-fourth, leaving 236 exploits undetected!" and the report concludes alarmingly thus - "These results clearly show that the major security vendors do not focus on vulnerabilities. Instead, they have a much more traditional approach, which leaves their customers exposed to new malware exploiting vulnerabilities."
Tuesday, September 9, 2008
Saturday, July 5, 2008
My First Webinar
Last week, Solidcore held a joint webinar with Trustwave (in which I presented). We had a very good attendance and the recording is available from -
http://w.on24.com/r.htm?e=112634&s=1&k=7F324EFE23D977C21A8DA677D816463D&partnerref=SCWEB
http://w.on24.com/r.htm?e=112634&s=1&k=7F324EFE23D977C21A8DA677D816463D&partnerref=SCWEB
Subscribe to:
Posts (Atom)
