SecurityBullshit.com


Cartoon 007 – Dr. Norbert Trumpton (from securityimprovization.com)
January 31, 2007, 3:54 pm
Filed under: Speeches

I am not a fan of personal baiting on blogs (there is just no need for it) so I’ll let you figure out the true identity of Dr. Norbert Trumpton on your own. Anyone who has seen him speak and present the same dull presentation for the last 3 years will have no trouble.  Rudy and I had the unfortunate experience of hearing him speak a year or so ago.  He first starts off by telling you how smart he is and then drops in a subtle phrase about how he did his PhD in Basyesian Maths every five minutes. I honestly counted 16 times in 45 minutes (and won a $10 bet). Hes a great presenter I’ll give him that. He does the gun with the hand movement as he tells stories about how he and his life long buddies were hanging out in the University finding zero days like shooting into a barrel of fish. The presentations are like a magic show; but not Penn and Teller, more like Magic Marvin. Having pumped you and almost got you to believe the hype he pulls out a bag of demos from the 90’s. The one that finally made me get up and leave was a disappearing menu in an unpatched Excel 2003.

securitybullshit-cartoon007.png

Editors note: Pulling rabbits out of hats is neither big nor clever. Self-proclamation of word-wide expert status (with a PhD in Bayesian Maths) and making Excel menus disappear isn’t either.


Digg!

Click for the full size cartoon. As always original files available on request.

Especially for you Mikey Boy !



Cartoon 006 – Creating a Security Lifecycle
January 30, 2007, 5:44 pm
Filed under: Sales

We have all seen these things in various places. Andrew Jaquith has a brilliant post at Security Metrics called Escaping the Hamster Wheel of Pain.

Ever wondered how companies create them? Now you know……

securitybullshit-cartoon006.png


Digg!

Click for the full size cartoon. As always original files available on request.



Cartoon 005 – Security Sales Graphs
January 29, 2007, 8:48 am
Filed under: Sales

There’s lies, damn lies and statistics…and then there are security sales graphs. These are often based on the informal science of making things look and sound better (or worse) without any evidence to support the case. There was an amusing case a few years back of a web application firewall company that was formed in 2002. They released a “survey” showing how may holes were not fixed after pen tests (I think the number was 95%) with the intent of making a case that people should be buying web application firewalls. Magically their data went back to 1999, 3 years before they were formed! If you see pretty graphs or impressive numbers, ask where they came from. If its unproven, call it like it is; bullshit!

 securitybullshit-cartoon005.png


Digg!

Click for the full size cartoon. As always original files available on request.



Cartoon 004 – The Big Four (Pt 2)
January 22, 2007, 4:26 pm
Filed under: Consulting

This is the last Big Four one for a while I promise ……..and I am truly deeply sorry (NOT).

securitybullshit-cartoon004.png


Digg!

Click for the full size cartoon. As always original files available on request.



Cartoon 003 – The Big Four (Pt 1)
January 15, 2007, 4:24 pm
Filed under: Consulting

I am so sorry to all my friends who work (or have worked) for the accounting firms. I just couldn’t resist!

securitybullshit-cartoon003.png


Digg!

Click for the full size cartoon. As always original files available on request.



Cartoon 002 – Appliances
January 8, 2007, 4:13 pm
Filed under: Hardware

Just who do these people think they are kidding? This one needs little commentary. Don’t be fooled by headless boxes that go whirr in the night.

securitybullshit-cartoon002.png


Digg!

Click for the full size cartoon. As always original files available on request.



Cartoon 001 – Antivirus Wars
January 1, 2007, 10:30 am
Filed under: Anti Virus

When the AV firms finally woke up to Microsoft entering the desktop security market what did they do?

A. Innovate their way out of the impending onslaught

B. Diversify their risk

C. Start crying

The correct answer is of course “C”. Among the temper tantrums and stamping of the feet they all lobbied the powers that be to open up Patchguard, a technology that was aimed to protect the Windows kernel from malicious attacks. The result; MSFT was forced to create an API so people could get access; very handy if you are a malware developer I suspect?

securitybullshit-cartoon001.png


Digg!

Click for the full size cartoon. As always original files available on request.