Showing posts with label RSA Conference 2010. Show all posts
Showing posts with label RSA Conference 2010. Show all posts

Friday, March 5, 2010

RSA 2010: Lost in the Cloud, & Shrouded in the Fog of War, How Far Into the Cyber Future Can You Peer? Can You See Even Beyond Your Next Step?


The Rosetta Stone Photo Credit: Hans Hillewaert CC-SA-BY-3.0 (Theme of RSA 2010)

RSA 2010: Lost in the Cloud, & Shrouded in the Fog of War, How Far Into the Cyber Future Can You Peer? Can You See Even Beyond Your Next Step?

By Richard Power


Some final observations on RSA Conference 2010:

The presentations I wanted to get to, but couldn't, because of time constraints: "Local is the New Organic - A Bottom-Up Model for Information Sharing," in which Michael Hamilton of the City of Seattle introduced a model for the automated collection of security event data from public and private entities across a metropolitan area, and "Crowd Sourcing Fraud and Abuse Detection," in which Lee Holloway of Project Honey Pot presented early success in breaking down barriers and facilitating the free flow of abuse information between organizations. I hope that even today we live in a world that still allows for the possibility that such ideas can be propagated and exploited for the good of the many as well as the few.

The more and more I hear about the Cloud, from the C-level ("C" for Cloud as well as "Chief") keynoters, the more and more I wonder just where it is we will find ourselves as we migrate lock, stock and barrel into the Cloud (and make no mistake about it, that is where we are all going, or at least that is where most of our IT infrastructure is going).

What are the implications, beyond the obvious security issues? (Indeed, for some enterprises, security in the Cloud will be better than what they have on their own? For example, will all of us find ourselves enveloped in a billowing Cloud so thick it will trump Net Neutrality?

And what about the security and privacy established inside that billowing Cloud, and guaranteed by a cluster of major corporations and massive law enforcement agencies? Will it protect you and I from everyone and everything except (perish the thought) ethically challenged corporations and misdirected law enforcement agencies? Don't get me wrong. We are all going into the Cloud, like it or not.

I just hope you keep one eye on the exits, and remember where everything is (or was) outside that Cloud.

I have covered the RSA Conference annually since the early 1990s. I remember when it consisted of couple of meeting rooms, at the Sofitel Hotel, crammed with cryptographers and a few developers. Then it became an e-commerce conference disguised as a security conference. Then it became the defining event of the year for the IT security sector. And now, it has become even something even bigger; it has become a cross-roads for whole industries, and for government and business, and a window on cultures (corporate, institutional and popular). Swirling in the din that rises up from this Barnum & Bailey production, you can detect intermingled strains of music that are both disturbing and inspiring.

After four CyBlog posts (one for every day of the conference), and over 60 tweets, I will close with a few brief excerpts from a presentation on "Wired for War: The Robotics Revolution and 21st Century Conflict," delivered by Dr. Peter Warren Singer, a Senior fellow and director of the 21st Century Defense Initiative at the Brookings Institution.

Dr. Peter Warren Singer, Brookings Institution: There is something big going on in war today, and maybe even in the overall history of humanity itself. The US military force that went into Iraq in 2003 had a handful of drones ... we now have over 7,000 in the U.S. military inventory. The invasion force on the ground utilizied zero unmanned ground vehicles, we now have over 12,000 ... This year, the U.S. Air Force will train more unmanned systems operators than it will train manned bomber and manned fighter plane pilots combined ... These Predators, [etc.], are the first generation, they are a lot like the Model-T Ford or the Wright Brothers Flyer ... very soon it is not going to be thousands of robots as we use in our war today, it is going to be tens of thousands ...One of the things that you are familiar with, of course is Moore's Law: the idea that we have been able to pack far more computing power into our micro-chips, such so that they just about double in their power capacity just under every two years. Moore's Law, in action, is the reason that if you have ever gotten one of those Hallmark Greeting Cards that opened up and played a little song, you held in your hand more computing power than the entire U.S. Air Force had in 1960 ... Now if Moore's Law holds true, over the next twenty-five years, our systems, our computers and our robots will be over a billion times more powerful than today ... literally ... What if Moore's Law doesn't hold true? Yeah, it's hold true over the last forty years, but there is no guarantee that it is going to hold true over the next twenty-five. What if it only goes one one-hundreth as fast? Well, that would mean that our computers and our robotics mere million times more powerful than today ... The kind of things we only use to talk about at Science Fiction conventions, like Comic-Con, need to be talked about by people like us here, and at the Pentagon. We are living through a robots revolution.

Recent history offers some compelling evidence for the reliability of Moore' Law. Unfortunately, spanning the entire history of human consciousness, there is scant evidence that our collective common sense or our collective conscience will increase in sufficient depth to keep up with the demands that have already long since overwhelmed their existing capacities.

So, lost in the Clouds, shrouded in the Fog of War, how far ahead of your next step are you able to peer?

Here is a summary of CyBlog posts from RSA Conference 2010, in chronological order:

RSA 2010: Lifestyle Hacking -- Notes on "Social Networks & Gen Y Meet Security & Privacy"

RSA 2010: Hacking the Smart Grid -- Myths, Nightmares & Professionalism

RSA 2010: Merging Mind & Machine - Hacking the Neural Net

RSA 2010: Lost in the Cloud, & Shrounded in the Fog of War, How Far Beyond Your Next Step Are You Able to Peer into the Cyber Future?

See also RSA Conference 2009: Summary of Posts

Wednesday, March 3, 2010

RSA 2010: Merging Mind & Machine - Hacking the Neural Net


The Rosetta Stone Photo Credit: Hans Hillewaert CC-SA-BY-3.0 (Theme of RSA 2010)

We are developing encyclopedia of the brain, neuron by neuron ... Dr. John P. Donoghue, Brown University

RSA 2010: Merging Mind & Machine - Hacking the Neural Net

By Richard Power


On Monday, at the I.S.S.A. CISO Executive Forum, I delivered the current iteration of my Executive Intelligence Briefing. I update it quarterly, and have delivered it in forty countries, over the last 15 years. The 2009-2010 theme is "Starting Over After A Lost Decade: In Search of A Bold New Vision of Security." The CISO Executive Forum presentation was the fifth time I have delivered this version.

In the current iteration, I continue to track the evolution of the five areas of concern that I started with: i.e., E-Commerce Crime, Information Age Espionage, Infrastructure Attacks, Personal Cyber Insecurity. But, in addition, I articulate five new areas of concern: IT supply chain insecurity, virtualization and the Cloud, Corporate Governance, Climate Change, Sustainability and Cyber Security, and Being and Consciousness in Cyberspace.

The last of these, "Being and Consciousness in Cyberspace" is an exploration of some philosophical issues from what "the Wisdom of Insecurity" and the theory of the "Biocentric Universe" can offer us in terms of perspective, to the existential implications and security consequences of the merging of human and cyber, a radical transformation which is happening at a far more accelerated pace than most of us realize.

At the ISSA CISO Executive Forum, as elsewhere, the responses registered in attendees range from bewilderment to a deep grokking.

So I smiled when I saw that at the last keynote session, at the end of the day on the second day of the RSA, featured Dr. John P. Donoghue, Director of Brown Institute for Brain Science, Brown University and his work on "connecting the internet to the brain," i.e., "hacking the neural net."

Why would we want a sensing neural interface system? Well, the principle answer (at this point in time) is to transform the lives of people paralyzed by disease or injury.

Five paralyzed people were implanted with BrainGate in a pilot project.

In his powerful presentation, Dr. Donoghue answered these questions:

Can motor intention activate neurons after long-standing paralysis? Yes.

What area of the brain? "Primary Motor Cortex/Arm."

What signals are there to read? "FP and Spikes."

How are these signals decoded? "Neural patterns in the Spikes become control signals."

Donoghue showed how researchers could listen to one brain cell of a patient, as the patient imagined opening a hand (active) and then closing a hand (silent).

What technologies are involved (and evolved) in this research?

Donoghue showed a video of a paralysis patient using the brain to move a computer cursor to open e-mail, & then draw a circle. He also showed a video of a paralysis patient controlling robotic "assistants."

The Brown Institute team is working on a version of BrainGate with wireless, fully implanted sensors.

Such neural output, it is projected, will be used not only to assist paralysis patients, but to replace the limbs, and even to restore movement in limbs.

Referencing TV Sci-Fi, Donoghue illustrated how BrainGate was now somewhere between technology imaged in Star Trek and technology imagined in Star Wars.

"Neurotechnology," Donoghue remarked, "is already here." He cited some examples: electronic stimulation used to "turn off" Parkinson's Disease, as well as bionic ears to restore hearing, and bionic eye to transmit some imagery to the brain.

BTW, I was inspired when Donoghue showed a slide juxtaposing an image of the human brain and with a mapping image of the internet, because my briefing starts with a slide juxtaposing images of the earth from space with a mapping image of the internet. Yes, I will soon be juxtaposing all three images in the next iteration of my briefing.

Now, we are getting somewhere ...

After Donoghue's dazzling presentation, he sat with Ari Juels of RSA Laboratories to answer some compelling questions.

Here is just a brief excerpt:

Ari Juels: BrainGate restores lost capabilities to patients who are suffering from a dysfunction, but as you have shown it is possible to control more than just artificial limbs, you showed, for instance, the ability to control a cursor. Can you envision a day when healthy patients have implants of this sort, to supplement their functionality in the world, implants that help people stick to their diets, or control devices for a third arm, or something along those lines?

Dr. John Donoghue: There are many people who think about these things, and who want to be able to extend their capabilities. This is a medical device. We are trying to develop something for individuals who have disabilities, to make their lives better. The biggest barrier is that this does require brain surgery. We don't take that lightly. It is something that always raises a concern. Where we go with this, and how we use it will require serious debate and discussion. But, as I said, I think the barrier will always be the surgical one. We will not in any cavalier way, implant able-bodied people to have frivolous functions. On the other hand, we have many things already available to us that are aids, we have smart phones that we carry around with us that are substitutes for our memories, we have many, many devices; so it would have to be clear that at some point we would outstrip all of the available external technology before we begin to think about enhancing ourselves by implanting something in the brain.

Juels: Have you in fact been approached by industries, or companies, or government agencies that are hoping to exploit BrainGate for purposes other than the strictly medical ones?

Donoghue: I would say "exploit." I mentioned this EEG-like signal that is available from outside your head. There are a lot of people interested in how much control can you get from that. It is, in fact, a very noisy and hard to manage signal. And it is not very reliable. There are a lot of people who are interested in seeing that signal be as good as the one that you can from inside your head ... One place where there is a lot of interest is in the toy industry ...

Well, I am going to leave it there.

There are profound implications for security and privacy.

First, the network perimeter vanished, as the internet popped up inside the enterprise, and vice-versa; and now, both the network and the internet are vanishing into the Cloud. What's next? Will Being and Consciousness vanish into the Cloud, or will the Cloud vanish into Being and Consciousness? The answer to that either/or question is, of course, a very Zen "Yes."

Stay tuned ...

RSA 2010: Hacking the Smart Grid -- Myths, Nightmares & Professionalism


The Rosetta Stone Photo Credit: Hans Hillewaert CC-SA-BY-3.0 (Theme of RSA 2010)

NOTE: What do we mean by smart grid? Speaking on "Investing in Our Energy Future" at a Gridweek event on 9-21-09, Secretary of Energy (and Nobel prize winning physicist) Steven Chu offered a worthy definition: “Dynamic optimization of grid operations and resources. Incorporation of demand response and consumer participation.” (For your convenience, I have embedded Secretary Chu's full presentation at the end of this post.) Ah, but what about it's security?

RSA 2010: Hacking the Smart Grid -- Myths, Nightmares & Professionalism

By Richard Power


The implementation of Smart Grid is in the vital national interest of the U.S., and all other industrial (and post-industrial) nations; it is vital both in terms of energy security and climate security, which, of course, means Smart Grid is also vital to economic security.

Any nation that wants to compete in the 21st Century needs Smart Grid. Indeed, any nation that wants to survive in the 21st Century needs Smart Grid.

In framing the issue for this RSA 2010 session on "Hacking the Smart Grid," Gib Sorebo of SAIC (one of CyLab corporate partner, BTW), cited several Smart Grid drivers, most notably, resiliency and reliability and reduction in carbon emissions, as well as several Smart Grid challenges, including the integration and distribution of renewables, the complexity of transmission networks, how to eventually provide infrastructure for electric vehicles (hopefully much sooner than later), and yes, what to do in regard to cyber security.

A smart grid, after all, is not necessarily a secure grid.

Smart grid is full of innovation, and it is being designed and implemented swiftly (or certainly should be), and innovation and urgency only tend to exacerbate security issues.

Furthermore, the issues swirling around the cyber security of power grids, whether legacy, smart or in transition, have shifted from the theoretical to the down and dirty. A decade or so ago, talking about attacks on the power grid were mostly speculative, but a decade ago, well, that was a century ago.

Some incidents have even ended up in the headlines:

In a rare public warning to the power and utility industry, a CIA analyst this week said cyber attackers have hacked into the computer systems of utility companies outside the United States and made demands, in at least one case causing a power outage that affected multiple cities. Washington Post, 1-19-08

A power failure has blacked out Brazil's two largest cities and other parts of Latin America's biggest country for more than two hours, leaving millions of people in the dark after a huge hydroelectric dam suddenly went offline. All of neighbouring Paraguay also lost power, but for only about 20 minutes ... The blackouts came three days after the CBS's 60 Minutes news programme in the US reported that several past Brazilian power outages were caused by hackers. Guardian, 11-11-09

So what is really happening in the space of Smart Grid cyber security?

The RSA 2010 panel Sorebo moderated consisted of Matthew Franz, Principle Security Consultant, SAIC, Matthew Carpenter, Senior Security Analyst, InGardians and Seth Bromberger, Information Systems Security Manager, PG&E.

For those of us who have firsthand knowledge of the decade-long struggle to promote critical infrastructure protection for existing systems, this few brief excerpt from their discussion offer a tantalizing, but humbling glimpse into this profoundly promising, yet clearly perilous undertaking glibly dubbed Smart Grid:

Seth Bromberger, PG&E: The research is being done on security in these components is not necessarily new. We are talking about encryption, key management, strong authentication. These are not new concepts. The devil is in the implementation. Where you have vendors, manufacturers and product developers taking short-cuts, or implementing poorly, that's where we are finding these vulnerabilities ...

Matthew Carpenter: We need pen-testing out of everybody. That doesn't mean everyone in the audience should go disassemble our firmware and look for buffer overflows. But there are so many different layers in this very complex system, and sometimes we just need critical thinking done about how we implement x, or whether this is a great feature to have. For instance, some utilities are thinking about having [an automated process by which] a person's credit report could impact whether or not that person can actually have power. This may not be the smartest choice to have automated throughout the system, without checks and balances in place. But it is actually something that has been pushed forward as a To-Do. So I can break into meters using this technology, but what about the guys who can influence credit reports? Or how about getting in between the communication of these credit reports? How can I manipulate the system? So we need everyone in the entire implementation of Smart Grid to be thinking critically about this could be abused. If I turn on this security protection, how could it be abused to cause more damage? How do I turn on anti-tampering technology in this device? OK, now what? So if I have anything higher than a 1.0 on some scale, I just shut down my entire neck of the woods? OK, maybe not the best bet. We need critical thinking done by everyone who has purview into the system, and good communication of "Well, maybe this isn't such a good idea." We need to open up that flow of communication.

Gib Sorebo, SAIC: For a long time, the [utility] industry has had a reputation of being tight-lipped about incidents, even about vulnerabilities that have been discovered (and, of course, it is not the only one). There have been a lot of bad feelings, recently, about some disclosures related to meters, people were branded not as terrorists, but it was almost that kind of thinking; in other words, "You guys are destroying the industry by revealing information about these vulnerabilities." And then we have the issue of everyone complaining that incidents are never reported to the regulators, or to the industry, or to whatever. Is there a middle ground? Obviously, we do not want to disclose vulnerabilities right away for an infrastructure that takes a long time to change, but where can we go with that?

Matthew Franz, SAIC: I am still kind of traumatized by my involvement with the disclosure of some SCADA vulnerabilities. Speaking of [being called] terrorists, I remember a utility software vendor that ... I gave a case study back in 2006 about some ... protocol vulnerabilities that I worked through the CERT process ... To paraphrase, what I was told was that by telling US CERT, i.e., giving them the details, and how to reproduce it, etc., and having US CERT release an advisory, we were arming the terrorists ... Just as a bell-weather of where we are I went to four or five of the leading meter AMI vendors this morning, and I looked for their /security site. The kind of site that Microsoft and Cisco and others have, in terms of how you go about reporting vulnerabilities, and only one of these meter vendors had the contact information, the GPG keys, etc., and that is the first step if that researcher wants to do the right thing, to get a hold of these vendors, and there is no way to do that ... The level of transparency you have is far less than Cisco or Microsoft ...

Matthew Carpenter, InGaurdians: We have to be more cautious than a Microsoft vulnerability disclosure. If you know me, you have probably heard me talk about responsible disclosure being a communication mechanism for vulnerabilities, but also a way to keep vendors in line. For IT, I think that makes a lot more sense. We have to be more cautious because of the impact in this arena. But we need to have fluid motion for our vulnerability research, we need to have a way to disclose to a vendor that there is an issue. We need to be able to have discourse throughout the utility space, so that effected customers have an early warning, "Hey, something's up, we've got a fix that's in the works, but just to give you some warning, when this comes out, you need to put it into test immediately, and in a certain amount of time, roll it out ... I remember hearing a vendor say, "Think about thirty days." I said, "That seems a little long, but if get a vulnerability notification, and within thirty days you have a fix out, well, you're better than Microsoft." But no, thirty days was actually the number to push out the patch from the time they clicked the button. "Whoa," I said, "we have some problems in our viewpoint into vulnerability handling." Disclosure needs mechanisms ...

Seth Bromberger, PG&E: You talked about making sure that the affected customers are made aware of the vulnerability. I am all for knowing ... The challenge that we have is that the lines dividing customers and non-customers are very blurry when it comes to things like critical infrastructure. I could see an argument that anyone who consumes power is a customer of the vendor whose control systems help deliver that power. From a utility perspective, I would say that the utilities are probably the customer base that the vendor would be beholden to. So when we talk about disclosing vulnerabilities ... to what end is the researcher disclosing, is it to feed ego? If so, that is probably not the most responsible way of doing it. Sending out on one of the public lists, information on a zero-day in a control system handling power or manufacturing is probably not the best way to people who are going to be impacted by it. And someone could argue that everyone is impacted by it, but I would challenge [by saying] that the average power consumer doesn't have any ability to effect the change and necessary remediation in those systems. So there are mechanisms the word to the right people, and again, I would say from my perspective, knowing about it is better than not knowing, so if the only way to get it out there is full disclosure, well, if it is actionable, I can take action, if I don't know about it, I can't do anything, and we can't pressure the vendors to fix it. But ultimately the utilities are in the position here of being the consumers of the product, and not necessarily the manufacturers of the product, and so the leverage we have is as a paying customer ... But it also puts us at a little bit of a disadvantage in that we need to be able to have the influence with our vendors to actually affect this change. We can't do it by ourselves.

Tuesday, March 2, 2010

RSA 2010: Lifestyle Hacking -- Notes on "Social Networks & Gen Y Meet Security & Privacy"


The Rosetta Stone Photo Credit: Hans Hillewaert CC-SA-BY-3.0 (Theme of RSA 2010)

When e-mail was just starting to be introduced in the workplace, I was a summer intern at IBM, before I went to graduate school, and you couldn't send anything outside of IBM, and there was a lot of struggle about whether or not to allow it. Now we are just seeing the exact same thing is repeating. -- Avi Rubin

People have been looking at social networks and crowds and how they reinforce productivity ... People who are on social networks are more productive, make better decisions, and have many advantages over those who are not. -- Kimberly De Vries

RSA 2010: Lifestyle Hacking -- Social Networks & Gen Y Meet Security & Privacy
By Richard Power


After a long morning of heavy hype and lofty notions at the RSA 2010 keynote sessions (see www.twitter.com/cylab for my 33 tweets from inside), I went looking for something to sink my teeth into. And therefore, not surprisingly, I drifted toward "Social Networks & Gen Y Meet Security & Privacy," a panel organized by the worthy IEEE Security and Privacy.

The panel was moderated by Gary McGraw, CTO, Cigital, and included Kimberly De Vries, Assistant Professor, CSU Stanislau, Avi Ruben, Professor, John Hopkins University, James Routh, Consultant, Archer Technologies and Gillian Hayes, UC Irvine.

Whatever Gary has his hand in is going to be refreshing, yet relevant, timely and yet ahead of the curve. This session was no exception.

He led off by having his panelists role-play in two little skits, both entitled "Pursuit of Productivity."

The first skit depicted a meeting between an H.R. Director, a CISO and a Chief Operating Office.

The COO remarked that there seemed to be some sort of generational gap, but that there was no way the enterprise could allow employees to fritter away time on social networking, declaring, "we need to focus on productivity."

The CISO showed the COO an analysis of recent security incidents, showing that they had increased dramatically, and that most were from the inside, because employees were seeking to by-pass the enterprise's controls to use social networking sites.

The COO responded, "Well, just tell me their names and we will fire them."

The HR Director then showed the COO results of studies that showed loosing up policy might make people more productivity, as well as the results of focus groups that showed in order to attract and hold on to the best candidates we have to update our current policy.

The COO remarked, "I never thought I would see the day when the security geek would propose loosening up policy, I will have to think about this ..."

In the second skit, the HR Director was depicted in a meeting with two employees who were both really outspoken about the need to access social networking, one from Sales and one from Technology.

The Sales person said, "I have over 600 contacts on LinkedIn."

The Technology person said, "On the product development team, if you don't keep up forget it, social networking is how I keep in touch with my peers and gurus."

The Sales person said, "I cannot be productive unless I clear my head with tunes on You Tube."

The H.R. Director asked for a percent of how much social networking was business as opposed to purely social.

The Sales person said, "It is very hard to compartmentalize between social and business."

The H.R. Director insisted, "I will need a percent for the form."

The Technology person answered, "LnkedIn: 100% business, 30% social."

The Sales person said, "Here's a percent, if LinkedIn and Facebook are banned, it is 100% certain I am going to quit; well, let's say 90%, yes, I have 600 contacts, and there's a 90% that one of them will hire me."

These two little skits really do capture the essence of a great upheaval going on inside the enterprise, in regard to how best to tap into the power of social media, without it turning into a well of woe.

Here are some of the insightful commentary from the panel discussion that followed.

Gary McGraw: Do controls encourage breaking rules? Is hacking around controls a gateway drug?

James Routh: It is not a gateway drug; it is more of a manifestation of a convenience factor. The generation that is coming out of school, and into corporate America, there are certain expectations coming to work, so to them, hacking around policy is trivial, it is not like crossing the line in their minds.

Gary McGraw: How do you define productivity? How do you balance maximum productivity against tools that do genuinely cause productivity loss?

Gillian Hayes: I am doing a lot of work with public schools, and what we see is this emphasis on 21st Century skills; what that means is solving problems creatively, and often that involves using technology, and it involves a sort of mash-up culture that kids have, i.e., grabbing bits and pieces of information, grabbing different services, bringing this all together, using your social network, etc. This is explicitly how we are teaching kids to solve problems when they are in school. It is probably a really good way to teach kids to solve problems, but we then put them into a very different environment. We take all those tools away, and say work inside this little sandbox. This is not a generation of people that is prepared for that. At the same time, what we are teaching them about information is "keep all your data private all the time." This is the abstinence-only model of teaching kids about security and privacy. So we have a real tension in which we are not teaching kids to make these decisions intelligently. Kids are taught very early: "Hide all the crazy things you're doing, but do them so that you can solve the problem."

Gary McGraw: Is there a parallel to the history of phones in the workplace?

Kimberly De Vries:Actually, there is a parallel to almost every new technology. Even if you go back and look at the introduction of writing, it was felt that if people learned to write, their memories would suffer, they wouldn't be able to focus. Plato complained about. People use to memorize everything, they use to be able to listen, people could remember; but if you can write things down and have that crutch, your brain is going to turn to oatmeal.

Avi Rubin: I have three elementary aged school children. I look at social networking and all the cool things you can do on-line, and say, "How cool is that, I can google this, and my GPS can tell me where I am ..." But my kids know no other world. If we go somewhere my son will tell me to pause the TV because he has to go to the bathroom. And I have to tell him, "we can't pause this TV, it's not one of those TVs." They use this stuff all the time. They live it, they breathe it. My son was using some video game that they play on-line, he knows how to get there, I don't ... He's seven years old. he created a user account. I overheard the conversation between my eleven year old and my seven year old. "Well, I need a user account and a password." And my daughter says, "Wel, don't use the same password that you use for other things, like your e-mail." "Well, how am I going to remember it?" "Here's what I do, have a good password, and then find something from that site and then combine it together, and if you go to another site, do the same thing with something from that site ..." I can't believe I a hearing my kids talk like this, they live in a completely different world.

Yes, I have been doing a lot of thinking, writing and speaking about the state of security and privacy, and where we are going in the future. And I have come to the conviction that the very nature of security and privacy must change radically to prevail, and that our best hope for this is the next generation, and the generation just beyond them. It was good to hear a similar sentiment echoed in the remarks of the panelists, particularly Hayes and Rubin.