Wednesday, March 2, 2011

Beschreibung Pet Containment System Rf

No: ANSSI is not "French" Cyber Command!

PC Inpact week published an interview last interesting Pailloux Patrick, CEO of ANSSI. Interesting because it allows, in my view, to illustrate how one can perceive the role of cybersecurity in developed nations, particularly France and Europe but also in the U.S. who are iron lance. To illustrate but also to try to understand the workings visible, less visible or invisible, to come and connect to inform, transmit and sometimes debate.

Since its inception, this blog tries to put a modest issues that are dear to my heart as well as the right questions (you can always dream, right?). All this so surely imperfect, fragmented but enthusiastic (if not passionate). What makes me react strangely, without any fatigue (almost:), is noted in some media (institutions but also on the blogosphere) processing part (and sometimes biased) about the new responsibilities assigned to ANSSI ( the decree of February 11, 2011 ). In the light of a previous post , I could have called it " ANSSI: 1 - Media: 0 " but it is feared qu'ANSSI Stuxnet and can be replaced indefinitely. This is no longer the game but the systematism with a certain arrogance which I try to keep my ego (or disproportionate, or degraded).

That said in a playful tone, become again serious moments: some media proclaim and declaim in recent weeks that would become the ANSSI Cyber Command ( should be ambitious but not worth crossing that one is interested), a sort of agency to shock the French in the fight against cyber-threats.

Yet I think that it is (very) long way to go and Patrick Pailloux I do not say anything when he says:
- this decree allows above all provide a legal basis therefore saving time (2-3 hours) in terms of legal authority identified with respect to any "orders" of disconnection that ISP may receive from the French authorities in case of cyber attack majeure;
- ANSSI have a role in crisis management , neither more nor less, and I love the metaphor about the fire management was, at best it will coordinate the few available means and attempt to limit a possible attack;
- for the rest, we must not forget that the agency first an advisory role and support towards the government (or companies) and devotes a significant portion of its business through certification of products and security solutions .

must therefore right to keep and consider that the allocation state of cybersecurity to ANSSI could be a temporary solution until:
- Either the field of cyberspace becomes an axis Medium-term strategic (hence the policy underlying foresight and anticipation ... I have a dream ) and the agency could be allocated adequate resources accordingly, the role of "Nation's leading Cybersecurity "in the European Union could be one of the consequences - a reasonable and interesting
- Let it retains its "small" powers and participate in a complementary or integrated into a future Nato or European authority (ENISA? Faced with NATO, the "game" seems a foregone conclusion. ..);
- Finally, the third way: a new agency is created , dedicated to cybersecurity and integrating, why not, the CERT with strong interfaces to the military (the DRM thus has a role to play) but also to large enterprises.

In fact the latter course looks furiously to that taken by the United States, relatively speaking: a central authority with the means to monitor the threat in cyberspace (with its Common Operational Picture , I'll come back another time) in permanent contact with all state entities employed by the cyber security and all the security department of the largest companies.

Monday, February 28, 2011

Beef Heifers Cows For Sale

Cybersecurity in France and Europe: downgrading or opportunity (ies)?

While on the Old Continent we try as best they can position themselves in the fight against cyber-threats, the United States and more particularly the "DoD (Department of Defense / Department of Defense), communicate to another level but also advancing rapidly. I will return in a future post.

A first bracket: you can even think that the evolution of the "Holy Trinity" (doctrine / resources / capabilities) ahead of the communication also great communicators because they are, the technological advance and / or capability and confidentiality remain as one of their strengths.

A second bracket for accuracy, linked to one of my previous posts abruptly (but in fact, I maintain my position!) Entitled " Noddy and cyber threats . I laughed politely of the European Agency for Safety Network and Information ( ENISA) and his French counterpart, the ANSSI . These two entities, missions rather different but complementary suffer from major handicaps: for ENISA is to be a European integrated agency with what it leads in terms of strategy (s) and decision (s). Since its inception, the initial goal was quickly confronted with the reality: the legitimacy of national agencies and CERT , modest budgets, goals quickly revised downwards. Like other agencies in their time, it will in future find its place among the national systems, on pain of being a new "gadget .

For ANSSI is more complicated late DCSSI has a legitimacy on the national stage and beyond, recognized expertise, but the major drawback of not having a size critical. Budgets are certainly increasing and the number of open positions has increased significantly recent years but that does not spearhead that France, " fifth largest economy", is entitled wait. Especially in Europe, is an actor but also a target for threats ranging from terrorism to economic and industrial intelligence. And that networks and information systems are at the heart of these issues.

Has provided the die is cast? We can fear it, unfortunately. Especially when we know that NATO at its last summit , placed cybersecurity as one of the important areas that the Alliance will have to address.

So on one hand, we can let go and say that keeping a small agency at the national level, integrated in a system with NATO staff resources and greater resources, is common sense. Especially at a time when economies across announced.

On the other hand, some makers (and their advisers) have adequately measured the interest that France (and some of its European neighbors) Will (are) to engage in the process of the fight against cyber threats ? Behind what may seem abstruse, highly virtual, high-tech jobs and new tools (concepts, methodologies, technologies) are to integrate and create. And know-how could be partly exported (ie sold) thereafter.

To believe the adage that "security is a cost, not an investment "remain inscribed in stone a long time!

Thursday, February 24, 2011

Watch Family Guy In Iphone

USAF, social media and false identities

A surprising spin-off of the shock wave Wikileaks through one of the many emails illegally recovered ; by Anonymous in the security company HB Gary has learned that the U.S. Air Force launched in early summer 2010, a tender for a software create and manage false identities on social networks (Facebook, Twitter, MySpace). Among these emails, one of the leaders of HB Gary surprised that this solicitation be "open", ie public, especially since it seems that Federal HB Gary, entity that provides security services, which could be retained to provide the desired software.
The feature of the tool are as follows: 50 licenses to manage each 10 personae (virtual users) with functions of IP Spoofing to disguise the true origin persona of . The aim of the operation is twofold: to lure friends who connect to these profiles and obtain information on individuals targeted through these friends. That's what we learned article from Information Week .
Information still shows from more important social networks as a vector informational but also how the U.S. government entities are firing on all cylinders in the field of technology information.

A further illustration of the emergence of cyber security as a key area and critical (and possibly controllable!) as well as the four dimensions (land, sea, air and space) including the United States has control or superiority.