The bad blood between Cisco Systems Inc. and organizers of the Black Hat conference appears to be a thing of the past. One year after suing the hacker conference for allowing security researcher Michael Lynn to disclose a security vulnerability, Cisco is returning to Black Hat -- this time as one of the show's top sponsors. Black Hat USA will be July 29 to Aug. 3 in Las Vegas. . "Despite what happened last year we wanted to show our commitment and show our openness to working with the security research community," said John Noh, a Cisco spokesman. Cisco has sponsored Black Hat in the past, but this is the first time it has shelled out for the show's most expensive "platinum" sponsor status, Noh said. The link for this article located at Infoworld is no longer available. . Cisco's recent partnership with Black Hat showcases its dedication to enhancing the security research landscape, addressing previous disagreements head-on.. Cisco Systems, Black Hat, Cybersecurity Sponsorship, Security Research. . Brittany Day
If it had the political nerve, the Transportation Security Administration could guarantee air safety by collecting passenger information from public and private databases, industry executives said at a recent Washington forum sponsored by the Council for Excellence in Government. . .. If it had the political nerve, the Transportation Security Administration could guarantee air safety by collecting passenger information from public and private databases, industry executives said at a recent Washington forum sponsored by the Council for Excellence in Government . "It"s not a technology problem, it"s a problem of political will ... what we are willing to give up" in exchange for greater security, said Steve Perkins, senior vice president for public-sector business at Oracle Corp. Oracle formed the Liberty Alliance with Electronic Data Systems Corp., PricewaterhouseCoopers Inc. of New York and Sun Microsystems Inc. to sell the database-mining idea to the government. Their emphasis is on hardware and software integration, not privacy or data security. "Our goal is to push the bounds of the technology," Perkins said. "I don't see a role for the alliance on the policy side." Government officials, however, said privacy and security policies require industry participation. The link for this article located at GCN is no longer available. . If it had the political nerve, the Transportation Security Administration could guarantee air safety. political, nerve, transportation, security, administration, guarantee, safety. . LinuxSecurity.com Team
The IT community has developed checklists of must-have technologies and accepted best practices for solid protection, but even the most vigilant enterprise IT professionals have been forced into reactionary postures by ceaseless new vulnerabilities, increasingly sophisticated hacker tools and heightened threats of cyber-terrorism. Security in depth is critical to business continuity and customer trust, but challenges to that level of security can seem insurmountable.. . .. The IT community has developed checklists of must-have technologies and accepted best practices for solid protection, but even the most vigilant enterprise IT professionals have been forced into reactionary postures by ceaseless new vulnerabilities, increasingly sophisticated hacker tools and heightened threats of cyber-terrorism. Security in depth is critical to business continuity and customer trust, but challenges to that level of security can seem insurmountable. The goal of this eWEEK Special Report is to provide a leg up. We gathered security experts from the research and vendor communities--The SANS Institute, Microsoft Corp., Oracle Corp., Sun Microsystems Inc. and Symantec Corp.--for a roundtable discussion that examined the relative securability of Web-based computing and the role of the vendor community and enterprise IT in creating or magnifying risks. Oracle put "unbreakable" in perspective and advocated working with and not against hackers, while Microsoft addressed the "Is it a feature or a bug?" question. Symantec and Sun focused on end-user responsibility, while SANS addressed the practical problems of system configuration. The complete transcript of the roundtable will be available soon at www.eweek.com, as will audio highlights of the conversation. The link for this article located at eWeek is no longer available. . The IT community has developed checklists of must-have technologies and accepted best practices for . community, developed, checklists, must-have, technologies, accepted, practices. . LinuxSecurity.com Team
This is a pretty article that discusses why IPSec is slow going, and how now vendors are starting to work together to make sure their products interoperate when building a VPN. "As the number of VPN gateways increases, so does the . . . . This is a pretty article that discusses why IPSec is slow going, and how now vendors are starting to work together to make sure their products interoperate when building a VPN. "As the number of VPN gateways increases, so does the need for smart, robust, centralized management, because you don't want to increase your workload proportionally. There is some help on the way. As the VPN becomes more critical to your operations, many vendors are adding support for integration and high-availability features that let the gateway leverage existing services for authentication, configuration and logging. Leveraging existing services should reduce much of the management overhead. In addition to the management hurdles, configuring a VPN using equipment from multiple vendors is gnarly. At this point, support for IPsec (IP Security) interoperability isn't making much difference. The IPsec protocol suite has been in RFC status in the IETF since 1998, and the IPsec vendors-through bake-offs and the ICSA ()-have shown interoperability among shipping products. Since that time, the number of vendors offering IPsec VPNs has dramatically increased, especially in software-only implementations. Hardware-based IPsec VPN providers have consolidated. This has left two long-standing vendors-RedCreek Communications and VPNet Technologies-contending with large companies like Alcatel, Cisco Systems, Intel Corp. and Lucent Technologies. The next big obstacle for these vendors to overcome is interoperable IPsec with the use of digital certificates. Maybe next year. " The link for this article located at Planet IT is no longer available. . The evolution of IPSec VPNs showcases both challenges and progress, as vendors collaborate to improve interoperability and simplifymanagement for secure access.. IPSec VPN, Protocol Interoperability, Network Management. . LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.