This page is repository for ideas for development in the book.
We've used Hunt Engineering ( for datacenter mechanical
and electrical engineering. I haven't personally worked with them, but
the results and feedback from coworkers were very good.
Members mailing list
Tom. Controlling Software Projects: Management,
Measurement and Estimation.
Englewood Cliffs, NJ: Prentice-Hall, 1982.
Dorset House, New York,
1995. ISBN 0-932633-34-X.
--State of Information Security 2005 Report Finds Security-Related
Events on the Rise
(12 December 2005)
The State of Information Security 2005 report from CIO Magazine and
PricewaterhouseCoopers found that security-related events have increased
22.4 percent since last year. Just 37 percent of the companies
responding to the survey have established a security plan; twenty-four
percent plan to implement one in the next year. The number of
organizations with a CISO or CIO rose from 31 percent last year to 40
percent this year. Among organizations with a chief information
security officer (CISO) or Chief Security Officer (CSO), 62 percent have
security plans in place. The study surveyed more than 8,200 IT security
executives in 63 countries around the world.
[Editor's Note (Schultz): The fact that only 37 percent of the companies
that responded to this survey have a security plan is not a very good
sign. I fear that Donn Parker may have been right when he asserted that
the practice of information security is more like "folk art" than
anything else. ]
--Engineer Indicted for Alleged Theft of Trade Secrets
(23 December 2005)
An engineer has been indicted for alleged theft of trade secrets.
Suibin Zhang allegedly downloaded proprietary files from Marvell
Semiconductors, Inc, after accepting a position with Broadcom, a Marvell
competitor. Zhang had access to the Marvell data because his former
employer, Netgear Inc., was a Marvell customer. Zhang then allegedly
loaded the files onto a Broadcom-issued laptop and emailed some trade
secrets to other Broadcom employees. Zhang entered a not guilty plea
and was released on a US$500,000 bond. If convicted on all counts,
Zhang faces a maximum jail sentence of 75 years and a fine of in excess
of US$2 million.
[Editor's Note (Honan) Most companies access policy disables user
accounts for employees who have left the company. This is an example
of how that policy should be extended to include external users from
partner companies or suppliers with employees who have access to
sensitive data.]
[root@angel root]# for i in `fgrep -h finao /var/log/httpd/access_log* | awk '{print $1}' | sort | uniq`; do
> host $i
> done
Host not found: 3(NXDOMAIN) domain name pointer domain name pointer
Host not found: 3(NXDOMAIN) domain name pointer domain name pointer domain name pointer domain name pointer domain name pointer
[root@angel root]#
--Versions of Windows Server 2003, Windows XP Receive Common Criteria
Certification at EAL 4+
(14 December 2005)
Six versions of Microsoft Windows Server 2003 and two versions of
Microsoft Windows XP have earned Evaluation Assurance Level (EAL) 4+ of
the Common Criteria. Meeting the standards set by the Common Criteria
is necessary to win federal contracts that involve dealing with
classified information.
[Editors' Note (Schultz): Achieving EAL 4+ certification is no small
feat. Microsoft has truly made a lot of progress when it comes to
security in its operating systems.
(Guest Editor (Donald Smith): Microsoft windows evaluation was against
the CAPP. From:
"The CAPP provides for a level of protection which is appropriate for
an assumed non-hostile and well managed user community requiring
protection against threats of inadvertent or casual attempts to breach
the system security. The profile is not intended to be applicable to
circumstances in which protection is required against determined
attempts by hostile and well funded attackers to breach system
(Multiple): When a government agency says a product meets a high
security standard, and that is a product in which dangerous flaws are
continuously discovered and for which the vendor chooses not to release
an existing patch while exploits for the flaw are circulating on the
Internet, perhaps the standard (Common Criteria) is part of the problem,
and should be reconsidered.]
Microsoft |
Ventilation and Vacuum (home of Failure is Not
an Option) |
Real Networks
Running linux and apache |
Running Linux and coyote |
California Institute of Technology |
Hewlett-Packard |
National Cash Register (NCR) |
Running Linux and AOLserver/3.3.1+ad13 |
Running HP-UX and Apache
(impressive) |
NCR (underwhelming) | |
MacWorld Expo
My server world |
Windows Server/2003 and IIS |
Windows server 2003 and IIS |
Windows server 2003 and IIS |
Customer service is considered A
Good Thing |
You never know what clowns
facilities is going to let into your data closets |
Cable Management |
How well do your systems work
when failures occur? |
Lights Out Computing |
The Medieval model of computing
security |
Nobody worries about Backups
until you need them |
Good morning, your network is
about to go down. |
$Log: ideas.html,v $Revision 2006/10/01 23:36:20 cvsuserInitial checkin to CVSRevision 1.2 2006/09/20 21:22:45 jeffsAdded the all_files link to a PHP script which generates a list of all files in this directoryfor search engines
Revision 1.1 2006/01/05 06:02:19 jeffs
Initial revision