The InfoSec Blog

System Integrity: Without Integrity you don’t have Security

July 15th, 2008

Motive isn’t necessary to convict

http://government.zdnet.com/?p=3874

There’s an old joke about a man brought before the court for breaking and entering, not because he was caught in the commission of a crime but because he was found in possession of housebreaking tools - crowbars, glass-cutter and so forth.

When found guilty by the judge he said “well you better convict me for rape as well since I have the tool for that“.

Professor Alan Dershowitz of Harvard Law School. This case is neither new nor precedent setting as Alan Dershowitz pointed out … back in 1988 in this book “Taking Liberties“. Some of his orther books at Amazon are listed here.

Zemanta Pixie
July 15th, 2008

On Spies and inside knowledge

My friend and mentor, Donn Parker, observes:

Build your security assuming that the enemy knows as much about
your security and what you are doing as you do.

The lesson of history, InfoSec, industry, literature, warfare and politics tells us this is so.

Chapter 13 of Sun Tzu’s great work, “On the use of Spies“, advises:

What enables the enlightened rulers and good generals to conquer
the enemy at every move and achieve extraordinary success is
foreknowledge.

Foreknowledge cannot be elicited from ghosts and spirits; it
cannot be inferred from comparison of previous events, or from
the calculations of the heavens, but must be obtained from
people who have knowledge of the enemy’s situation.

Therefore there are five kinds of spies used:

Local spies, internal spies, double spies, dead spies, and
living spies.

He goes on to say

Only the wisest ruler can use spies; only the most benevolent
and upright general can use spies, and only the most alert and
observant person can get the truth using spies.

Which is of course pandering. And then:

It is subtle, subtle!

Which is pandering still, but none the less true.

There is nowhere that spies cannot be used.

Which is also true. Hence http://privateeyespyshop.com/

Generally, if you want to attack an army, besiege a walled city,
assassinate individuals, you must know the identities of the
defending generals, assistants, associates, gate guards, and
officers. You must have spies seek and learn them.

However these days, many companies and countries publish all this information on the web. The identity theft in “Day of The Jackal” (which has been copied by many other authors since) can now be performed from the comfort of you local hot-spot equipped cafĂ© or in some locals commuter train.

Zemanta Pixie
|