Friday, 16 September 2016

Structure News: Email security is broken, but you should still open this one

Your weekly tech news roundup, with a little bit of Structure.

STRUCTURE EVENTS Newsletter
Where Our Fantasy Football Team Is Awesome, Thanks For Asking
September 16th, 2016 / by Tom Krazit
This week, we'll talk about why email is at the heart of so many security issues, the push for security thinking as the new design thinking, and why Facebook deliberately shuts off some of its data centers from time to time.
BIG PICTURE
It's increasingly clear that information security is a broken promise, and it's probably email's fault.

Despite decades of attempts to kill it, email is still one of the most-used applications on our personal computers. That means some of our most valuable information is stored in a place tied to your computer that anyone in the world with your address can contact, potentially gaining control of your system if you're careless, unlucky, or both. And if you host your own email server, you're probably more at risk.

The World Anti-Doping Agency confirmed this weekthat Russian hackers, possibly the ones behind other prominent hacks this election year, used an email spear-phishing attack to steal the personal information of an unknown number of athletes. That personal medical information was used to make a clumsy attempt at denting the reputations of U.S. gymnast Simone Biles and tennis players Venus and Serena Williams. Several emails written by former U.S. Secretary of State Colin Powell were also leaked this week, revealing private conversations containing frank assessments of public figures that Powell would have never published in an op-ed.

And then security expert Bruce Schneier warned of a new threat: hackers who might forge a document or two alongside a dump of legitimate documents or correspondence, spreading disinformation while inviting the target to confirm the legitimacy of other damaging information in order to deny the forged information. How hard would it be to fake a damaging email thread?

Sure, you can encrypt your email, set up two-factor authentication, or use encrypted messaging apps instead of email. Most people aren't going to do that. It's long past time for the technology and security worlds to work together to make secure communications products that are as easy to use as email. The power of the default setting is well understood in technology, and email is a default setting for digital communication that spans age, gender, race, and nationality.
STRUCTURE NEWS
RE-THINKING SECURITY FUNDAMENTALS: HOW TO MOVE BEYOND THE FUD
Our good friends at ZDNet, an official media partner of Structure Security, were kind enough to let me riff on a topic I've been thinking about all year while planning this conference: why the tech world needs to embrace security thinking the same way design thinking became a central facet of product development a decade ago. It took products like the iPhone and services like Airbnb to make design thinking trendy, and 'Im almost afraid to imagine what it will take for software companies to take security thinking as seriously as their font choices.

We're less than two weeks away from Structure Security, which is going to happen September 27th and 28th at the Golden Gate Club in San Francisco (pictured here). I've talked at length about our great speaker list, which you can find here. And if you haven't yet purchased tickets, now is the time and here is the place.
INDUSTRY NEWS
HOW NVIDIA LET INTEL GET AN EDGE IN AI CHIP MARKET
Nvidia and Intel have tussled over the years, and seem destined for more conflict as the market for artificial intelligence chips heats up. The Information (subscription required) takes a look at Intel's acquisition of Nervana Systems and what might have been a missed opportunity for Nvidia.

U.S. CYBER COMMAND'S WEAPONS WILL BE CREATED BY CONTRACTORS, SENIOR OFFICIAL SAYS

This should be interesting: the federal government will employ both contractors and in-house employees in creating "loud" cyber weapons, or exploits that leave a calling card for the U.S. government, according to FedScoop. The idea is that such easily-identifiable exploits might deter countries or organizations from escalating their own activities, but Oliver Stone might be thinking about a sequel to Snowden.

A LOUD SOUND JUST SHUT DOWN A BANK'S DATA CENTER FOR 10 HOURS

This was a new one for me. ING Bank revealed this week that its primary data center in Romania was brought to its knees by a fire drill in which a gas-extinguisher system made such a loud noise as to ruin its hard drives. Motherboard reports that vibration from the noise, which was compared to standing next to an airplane engine, was responsible for destroying the drives.

GOOGLE'S DIANE GREENE TALKS AWS AND MACHINE LEARNING AT TECHCRUNCH DISRUPT

Google's "We're Serious About The Cloud World Tour 2016" continued this week with an appearance at Techcrunch Disrupt. The site shared a video that Google had convinced Evernote to shed its datacenters and move its workloads to over to Google.

WHY CLOUD VENDORS AREN'T TALKING SO MUCH ABOUT PRICE CUTS ANYMORE

In the cloud evangelism era, deep and frequent price cuts were a popular tool used by Amazon Web Services and its competitors to reward existing users and court new ones. But that tactic is starting to fall by the wayside in favor of adding new features and finding more value for customers in existing products, Fortune reports.

WHAT FACEBOOK HAS LEARNED FROM REGULARLY SHUTTING DOWN ENTIRE DATA CENTERS

This item is a little old by the regular standards of this newsletter, but I wanted to highlight a talk given by Structure veteran (and 2016 participant) Jay Parikh of Facebook on how the company measures the resiliency of its network by taking out an entire data center. Data Center Knowledge wrote up his talk, which goes into some detail about how Facebook has learned to prepare for failures it can't control by introducing a few it can control.
QUOTE OF THE WEEK
It's one thing to have all of your dirty laundry aired in public for everyone to see. It's another thing entirely for someone to throw in a few choice items that aren't real."
STRUCTURE

Click here to unsubscribe from this list.

Our mailing address is:
405 El Camino Real, #215 Menlo Park, CA 94025

Copyright (C) 2016 StructureSeries All rights reserved.

Monday, 12 September 2016

Why CISOs should take a page from the Secret Service when securing their networks

Meet pioneers in machine-learning advances at Structure Security.

twitter facebook linkedin
REGISTER NOW
A human being with relatively modest athletic ability can scale the fence that surrounds the White House in Washington, D.C. Once inside, though, good luck getting more than twenty feet from the perimeter before being tackled by a Secret Service agent who played linebacker in high school.

Nathaniel Gleicher, who saw firsthand the obsession with the physical security that surrounds the White House while developing information security policies for the Obama Administration, doesn't understand why more of us aren't taking the same approach to cybersecurity.

At Structure Security, Nathaniel and other leading security experts will share how they are getting their companies to move past perimeter defense and focus on more layered approaches to securing their data.

For 2 days only, we're discounting prices by $200. If you haven't gotten your ticket yet, now is the time.
SPEAKERS
Oren Falkowitz
Area 1 Security
Nathaniel Gleicher
Illumio
Stuart McClure
Cylance
Carson Sweet
CloudPassage
Mark Terenzoni
Sqrrl
Stacy Stubblefield
TeleSign
SPONSORS
HEADLINE
PRIMETIME
SHOWTIME
HEADLINE MEDIA PARTNER
PARTNERS
STRUCTURE CONNECT
SEPTEMBER 27-28, 2016
SAN FRANCISCO, CA
REGISTER NOW

Click here to unsubscribe from this list.

Our mailing address is:
405 El Camino Real, #215 Menlo Park, CA 94025

Copyright (C) 2016 StructureSeries All rights reserved.

Friday, 9 September 2016

Structure News: Can Michael Dell pull off one last miracle?

Your weekly tech news roundup, with a little bit of Structure.

STRUCTURE EVENTS Newsletter
Where The Headphone Jack Lives Forever
September 9th, 2016 / by Tom Krazit
This week, we'll talk about some of the big gambles that aging enterprise tech companies are making, why you should protect your information like the Secret Service protects the White House, and how ransomware appears to be getting worse.
BIG PICTURE
There was a time -- one that must baffle those still on the happy side of their first boom-bust tech cycle -- when Dell, Hewlett-Packard, and Intel ruled the tech world. While they're all still alive and kicking, they're not setting the pace, and the moves they make over the next year or two are critical.

All three companies have good reason to be proud of the contributions they've made to technology. But they have made some questionable decisions trying to extend their run at the top of the tech food chain, and Intel and HPE decided this week to cut some of those losses. Intel sold a controlling stake in Intel Security, offloading the unitformerly known as McAfeefor $4.2 billion after acquiring it for $7.6 billion in 2011. HP sold $8.8 billion worth of software assets, with CEO Meg Whitman telling The New York Times "there are elements of our world that are shrinking."

That might be an understatement. But Intel and HP's gambles on security and software pale in comparison to what Michael Dell is going to try and pull off, now that the historic $67 billion acquisition/merger of EMC and its associated companies is complete. It's really hard to see how this merger can end any other way but badly, which makes it all the more fascinating. (The Next Platform has a good overview of how Dell will try and pull this off.)

Intel is in the best position to have an outsized impact in this new world, having shed decades of orthodoxy about chip design and manufacturing to embrace a more flexible business model that listens to its customers. HPE lacks a compelling story outside of its mysterious "Machine" project; I've been cracking up for weeks at the overly dramatic and unintentionally hilarious ads for its security services shown before Season 1 of Mr. Robot on Amazon Prime, and it just sold that division. And the new Dell Technologies, well, we're going to have to wait a bit to see how that goes.

There are only a handful of companies that have navigated multiple transitions in computing across decades, and fewer still that have thrived amid those changes. As the pace of change gets faster and faster, that's not likely to change.
STRUCTURE NEWS
WHY CISOS SHOULD TAKE A PAGE FROM THE SECRET SERVICE WHEN SECURING THEIR NETWORKS
There's no bigger target in the world than the President of the United States. Nathaniel Gleicher of Illumio (pictured), worked inside the White House for several years advising the Obama administration on information security matters, and thinks the Secret Service has some lessons to teach the information security community on how to protect high-value targets. Gleicher will expand on this idea in a talk at Structure Security, and this week he shared a bit of a preview of his upcoming remarks.

Structure Security will take place September 27th and 28th at the Golden Gate Club in San Francisco. Gleicher is one of several speakers from some of the most innovative startups in the security world scheduled to appear at the conference, including Todd McKinnon of Okta, Stuart McClure of Cylance, and several others. More information on our speakers is here.
INDUSTRY NEWS
INTRODUCING DEEP LEARNING: BOOSTING SECURITY WITH AN ARTIFICIAL BRAIN
Information Week's Dark Reading site has a nice overview of how deep learning techniques can be used to improve security, which well discuss in detail at Structure Security. Automating malware detection could allow us to find far more threats and find those threats faster than human oversight would allow.

MICROSOFT WORKING ON SKYPE TEAMS, ITS OWN SLACK COMPETITOR.

I had sort of thought that Microsoft's bet on workplace collaboration tools would come out of Yammer, but apparently the company is developing such a tool under the hood of another service it acquired: Skype. MSPoweruser reports that Microsoft's would-be Slack killer supports threaded conversations, which has to be one of the top feature requests thrown at Slack.

EXASCALE MIGHT PROVE TO BE MORE THAN A GRAND CHALLENGE

Looks like Fujitsu's huge exascale supercomputer project has hit a snag, as The Next Platform reports that the project has been delayed by at least a year. Avoiding delays on a project of that size is probably impossible, but those looking for ARM server processors operating at scale will have to wait even longer.

THIS LEAKED CATALOG OFFERS WEAPONIZED INFORMATION THAT CAN FLOOD THE WEB

The underground market for software exploits is full of interesting and shady characters, and Motherboard looks at one company that once advertised hacking services to basically anyone with money. It's not clear whether Aglaya's products or services did any damage (one person described them as "crap"), but there appears to be pretty strong demand for hacking tools.

GOOGLE JUST BLEW UP ITS ALL-IN STRATEGY FOR PRODUCTIVITY SOFTWARE

Google and Box cut a deal this week at BoxWorks to allow Google Apps users to work on documents stored in Box through Google's popular tools, according to IDG News Service. It's a user-friendly approach that acknowledges that some customers don't want to put all their eggs in one basket, and a nice coup for Box.

HOW RANSOMWARE BECAME A BILLION-DOLLAR NIGHTMARE FOR BUSINESSES

We've talked about the ransomware problem several times this year, and believe it or not, the situation does not appear to be improving. The Atlantic takes a look at the state of the ransomware market and how people and businesses can fight back against this scourge.
QUOTE OF THE WEEK
This is a change or die business and we absolutely know that and, you know, are prepared to change."
STRUCTURE

Click here to unsubscribe from this list.

Our mailing address is:
405 El Camino Real, #215 Menlo Park, CA 94025

Copyright (C) 2016 StructureSeries All rights reserved.