<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>SecMusings &#187; We can&#8217;t make this stuff up</title>
	<atom:link href="http://shermansolutionsllc.com/secmusings/topics/we-cant-make-this-stuff-up/feed" rel="self" type="application/rss+xml" />
	<link>http://shermansolutionsllc.com/secmusings</link>
	<description>Andy's Reflections on Technology and Security</description>
	<lastBuildDate>Wed, 14 Apr 2010 00:34:46 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.2</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>No Free Lunch</title>
		<link>http://shermansolutionsllc.com/secmusings/archives/57</link>
		<comments>http://shermansolutionsllc.com/secmusings/archives/57#comments</comments>
		<pubDate>Fri, 24 Jul 2009 13:58:39 +0000</pubDate>
		<dc:creator>andy</dc:creator>
				<category><![CDATA[General Technology]]></category>
		<category><![CDATA[We can't make this stuff up]]></category>

		<guid isPermaLink="false">http://shermansolutionsllc.com/secmusings/?p=57</guid>
		<description><![CDATA[A hat tip to Spaf for this one.  Hillary Clinton held a town hall for State Department employees recently, where a recent transfer from one of the intelligence agencies asked why they couldn&#8217;t have Firefox, which was approved by NSA for use in the intel community.  Secretary Clinton turned to one of her aides, [...]]]></description>
			<content:encoded><![CDATA[<p>A hat tip to <a href="http://blog.spaf.us">Spaf</a> for this one.  Hillary Clinton held a town hall for State Department employees recently, where a recent transfer from one of the intelligence agencies asked why they couldn&#8217;t have Firefox, which was approved by NSA for use in the intel community.  Secretary Clinton turned to one of her aides, Patrick Kennedy, who replied that they had to look into the budgetary issues.  This drew cries of &#8220;but it&#8217;s free&#8221; from the crowd, which then got the &#8220;nothing is really free&#8221; explanation.</p>
<p>This explanation drew snarky hoots of derision from <a href="http://www.theregister.co.uk/2009/07/13/firefox_and_us_state_department/">The Register</a> and <a href="http://gizmodo.com/5315634/us-state-department-rejects-firefox-which-is-entirely-free-due-to-expense-questions">Gizmodo</a>, both of whom ridicule the notion that a piece of free software could cost anything to manage.</p>
<p>Clearly, you don&#8217;t have to actually know anything about managing IT to write about it for these publications.  <em>There is no such thing a &#8220;free&#8221; software, if by that you mean that the total cost of ownership is zero. </em>Here&#8217;s what it takes to deploy Firefox to tens of thousands of desktops:</p>
<ul>
<li>Decide what lockdowns you need in your environment and build a local build of Firefox that implements.</li>
<li>If you care about plugins, include in the lockdowns a restriction that plugins come from a local repository of approved ones.</li>
<li>Package it.</li>
<li>Distribute it.</li>
<li>Support it.</li>
<li>Rinse and repeat for each patch release.</li>
</ul>
<p>What you can&#8217;t do in an environment where the user desktop is a managed resource is have users download and self-maintain a complex security-sensitive piece of software.  I&#8217;ve worked in organizations that decided that the costs of doing the above was worth spending.  But there was no illusion that supporting Firefox was free.  Even a &#8220;best effort&#8221; support model requires people to execute it.</p>
<p>One encouraging note was that lots of IT professionals gave these articles the comments they deserved.</p>

<div class="sociable">
<div class="sociable_tagline">
<strong>Share and Enjoy:</strong>
</div>
<ul>
	<li class="sociablefirst"><a rel="nofollow"  target="_blank" href="http://www.feedburner.com/fb/a/emailFlare?itemTitle=No%20Free%20Lunch&amp;uri=http%3A%2F%2Fshermansolutionsllc.com%2Fsecmusings%2Farchives%2F57" title="email"><img src="http://shermansolutionsllc.com/secmusings/wp-content/plugins/sociable/images/email_link.png" title="email" alt="email" class="sociable-hovers" /></a></li>
	<li><a rel="nofollow"  target="_blank" href="http://www.printfriendly.com/print?url=http%3A%2F%2Fshermansolutionsllc.com%2Fsecmusings%2Farchives%2F57&amp;partner=sociable" title="Print"><img src="http://shermansolutionsllc.com/secmusings/wp-content/plugins/sociable/images/printfriendly.png" title="Print" alt="Print" class="sociable-hovers" /></a></li>
	<li><a rel="nofollow"  target="_blank" href="http://www.facebook.com/share.php?u=http%3A%2F%2Fshermansolutionsllc.com%2Fsecmusings%2Farchives%2F57&amp;t=No%20Free%20Lunch" title="Facebook"><img src="http://shermansolutionsllc.com/secmusings/wp-content/plugins/sociable/images/facebook.png" title="Facebook" alt="Facebook" class="sociable-hovers" /></a></li>
	<li><a rel="nofollow"  target="_blank" href="http://twitter.com/home?status=No%20Free%20Lunch%20-%20http%3A%2F%2Fshermansolutionsllc.com%2Fsecmusings%2Farchives%2F57" title="Twitter"><img src="http://shermansolutionsllc.com/secmusings/wp-content/plugins/sociable/images/twitter.png" title="Twitter" alt="Twitter" class="sociable-hovers" /></a></li>
	<li><a rel="nofollow"  target="_blank" href="http://www.linkedin.com/shareArticle?mini=true&amp;url=http%3A%2F%2Fshermansolutionsllc.com%2Fsecmusings%2Farchives%2F57&amp;title=No%20Free%20Lunch&amp;source=SecMusings+Andy%27s+Reflections+on+Technology+and+Security&amp;summary=A%20hat%20tip%20to%20Spaf%20for%20this%20one.%20%20Hillary%20Clinton%20held%20a%20town%20hall%20for%20State%20Department%20employees%20recently%2C%20where%20a%20recent%20transfer%20from%20one%20of%20the%20intelligence%20agencies%20asked%20why%20they%20couldn%27t%20have%20Firefox%2C%20which%20was%20approved%20by%20NSA%20for%20use%20in%20the%20in" title="LinkedIn"><img src="http://shermansolutionsllc.com/secmusings/wp-content/plugins/sociable/images/linkedin.png" title="LinkedIn" alt="LinkedIn" class="sociable-hovers" /></a></li>
	<li><a rel="nofollow"  target="_blank" href="http://digg.com/submit?phase=2&amp;url=http%3A%2F%2Fshermansolutionsllc.com%2Fsecmusings%2Farchives%2F57&amp;title=No%20Free%20Lunch&amp;bodytext=A%20hat%20tip%20to%20Spaf%20for%20this%20one.%20%20Hillary%20Clinton%20held%20a%20town%20hall%20for%20State%20Department%20employees%20recently%2C%20where%20a%20recent%20transfer%20from%20one%20of%20the%20intelligence%20agencies%20asked%20why%20they%20couldn%27t%20have%20Firefox%2C%20which%20was%20approved%20by%20NSA%20for%20use%20in%20the%20in" title="Digg"><img src="http://shermansolutionsllc.com/secmusings/wp-content/plugins/sociable/images/digg.png" title="Digg" alt="Digg" class="sociable-hovers" /></a></li>
	<li><a rel="nofollow"  target="_blank" href="http://delicious.com/post?url=http%3A%2F%2Fshermansolutionsllc.com%2Fsecmusings%2Farchives%2F57&amp;title=No%20Free%20Lunch&amp;notes=A%20hat%20tip%20to%20Spaf%20for%20this%20one.%20%20Hillary%20Clinton%20held%20a%20town%20hall%20for%20State%20Department%20employees%20recently%2C%20where%20a%20recent%20transfer%20from%20one%20of%20the%20intelligence%20agencies%20asked%20why%20they%20couldn%27t%20have%20Firefox%2C%20which%20was%20approved%20by%20NSA%20for%20use%20in%20the%20in" title="del.icio.us"><img src="http://shermansolutionsllc.com/secmusings/wp-content/plugins/sociable/images/delicious.png" title="del.icio.us" alt="del.icio.us" class="sociable-hovers" /></a></li>
	<li><a rel="nofollow"  target="_blank" href="http://technorati.com/faves?add=http%3A%2F%2Fshermansolutionsllc.com%2Fsecmusings%2Farchives%2F57" title="Technorati"><img src="http://shermansolutionsllc.com/secmusings/wp-content/plugins/sociable/images/technorati.png" title="Technorati" alt="Technorati" class="sociable-hovers" /></a></li>
	<li><a rel="nofollow"  target="_blank" href="http://www.google.com/bookmarks/mark?op=edit&amp;bkmk=http%3A%2F%2Fshermansolutionsllc.com%2Fsecmusings%2Farchives%2F57&amp;title=No%20Free%20Lunch&amp;annotation=A%20hat%20tip%20to%20Spaf%20for%20this%20one.%20%20Hillary%20Clinton%20held%20a%20town%20hall%20for%20State%20Department%20employees%20recently%2C%20where%20a%20recent%20transfer%20from%20one%20of%20the%20intelligence%20agencies%20asked%20why%20they%20couldn%27t%20have%20Firefox%2C%20which%20was%20approved%20by%20NSA%20for%20use%20in%20the%20in" title="Google Bookmarks"><img src="http://shermansolutionsllc.com/secmusings/wp-content/plugins/sociable/images/googlebookmark.png" title="Google Bookmarks" alt="Google Bookmarks" class="sociable-hovers" /></a></li>
	<li><a rel="nofollow"  target="_blank" href="https://favorites.live.com/quickadd.aspx?marklet=1&amp;url=http%3A%2F%2Fshermansolutionsllc.com%2Fsecmusings%2Farchives%2F57&amp;title=No%20Free%20Lunch" title="Live"><img src="http://shermansolutionsllc.com/secmusings/wp-content/plugins/sociable/images/live.png" title="Live" alt="Live" class="sociable-hovers" /></a></li>
	<li><a rel="nofollow"  target="_blank" href="http://www.stumbleupon.com/submit?url=http%3A%2F%2Fshermansolutionsllc.com%2Fsecmusings%2Farchives%2F57&amp;title=No%20Free%20Lunch" title="StumbleUpon"><img src="http://shermansolutionsllc.com/secmusings/wp-content/plugins/sociable/images/stumbleupon.png" title="StumbleUpon" alt="StumbleUpon" class="sociable-hovers" /></a></li>
	<li><a rel="nofollow"  target="_blank" href="http://slashdot.org/bookmark.pl?title=No%20Free%20Lunch&amp;url=http%3A%2F%2Fshermansolutionsllc.com%2Fsecmusings%2Farchives%2F57" title="Slashdot"><img src="http://shermansolutionsllc.com/secmusings/wp-content/plugins/sociable/images/slashdot.png" title="Slashdot" alt="Slashdot" class="sociable-hovers" /></a></li>
	<li><a rel="nofollow"  target="_blank" href="http://www.blogospherenews.com/submit.php?url=http%3A%2F%2Fshermansolutionsllc.com%2Fsecmusings%2Farchives%2F57&amp;title=No%20Free%20Lunch" title="Blogosphere News"><img src="http://shermansolutionsllc.com/secmusings/wp-content/plugins/sociable/images/blogospherenews.png" title="Blogosphere News" alt="Blogosphere News" class="sociable-hovers" /></a></li>
	<li class="sociablelast"><a rel="nofollow"  target="_blank" href="http://buzz.yahoo.com/submit/?submitUrl=http%3A%2F%2Fshermansolutionsllc.com%2Fsecmusings%2Farchives%2F57&amp;submitHeadline=No%20Free%20Lunch&amp;submitSummary=A%20hat%20tip%20to%20Spaf%20for%20this%20one.%20%20Hillary%20Clinton%20held%20a%20town%20hall%20for%20State%20Department%20employees%20recently%2C%20where%20a%20recent%20transfer%20from%20one%20of%20the%20intelligence%20agencies%20asked%20why%20they%20couldn%27t%20have%20Firefox%2C%20which%20was%20approved%20by%20NSA%20for%20use%20in%20the%20in&amp;submitCategory=science&amp;submitAssetType=text" title="Yahoo! Buzz"><img src="http://shermansolutionsllc.com/secmusings/wp-content/plugins/sociable/images/yahoobuzz.png" title="Yahoo! Buzz" alt="Yahoo! Buzz" class="sociable-hovers" /></a></li>
</ul>
</div>
]]></content:encoded>
			<wfw:commentRss>http://shermansolutionsllc.com/secmusings/archives/57/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Devolution</title>
		<link>http://shermansolutionsllc.com/secmusings/archives/46</link>
		<comments>http://shermansolutionsllc.com/secmusings/archives/46#comments</comments>
		<pubDate>Thu, 23 Apr 2009 03:14:56 +0000</pubDate>
		<dc:creator>andy</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[We can't make this stuff up]]></category>

		<guid isPermaLink="false">http://shermansolutionsllc.com/secmusings/?p=46</guid>
		<description><![CDATA[A hat tip to Bruce Schneir for spotting this one.  The BBC is reporting that the NHS Central Lancashire backed up health data on 6,360 prisoners and ex-prisoners by copying it on to a USB stick.  They even encrypted the data.
Then they lost the stick.
With a yellow sticky attached to it with the password.
We [...]]]></description>
			<content:encoded><![CDATA[<p>A hat tip to <a href="http://www.schneier.com/blog/archives/2009/04/lessons_in_key.html">Bruce Schneir</a> for spotting this one.  The <a href="http://news.bbc.co.uk/1/hi/england/lancashire/8003757.stm">BBC</a> is reporting that the NHS Central Lancashire backed up health data on 6,360 prisoners and ex-prisoners by copying it on to a USB stick.  They even encrypted the data.</p>
<p>Then they lost the stick.</p>
<p>With a yellow sticky attached to it with the password.</p>
<p>We really can&#8217;t make this stuff up.</p>

<div class="sociable">
<div class="sociable_tagline">
<strong>Share and Enjoy:</strong>
</div>
<ul>
	<li class="sociablefirst"><a rel="nofollow"  target="_blank" href="http://www.feedburner.com/fb/a/emailFlare?itemTitle=Devolution&amp;uri=http%3A%2F%2Fshermansolutionsllc.com%2Fsecmusings%2Farchives%2F46" title="email"><img src="http://shermansolutionsllc.com/secmusings/wp-content/plugins/sociable/images/email_link.png" title="email" alt="email" class="sociable-hovers" /></a></li>
	<li><a rel="nofollow"  target="_blank" href="http://www.printfriendly.com/print?url=http%3A%2F%2Fshermansolutionsllc.com%2Fsecmusings%2Farchives%2F46&amp;partner=sociable" title="Print"><img src="http://shermansolutionsllc.com/secmusings/wp-content/plugins/sociable/images/printfriendly.png" title="Print" alt="Print" class="sociable-hovers" /></a></li>
	<li><a rel="nofollow"  target="_blank" href="http://www.facebook.com/share.php?u=http%3A%2F%2Fshermansolutionsllc.com%2Fsecmusings%2Farchives%2F46&amp;t=Devolution" title="Facebook"><img src="http://shermansolutionsllc.com/secmusings/wp-content/plugins/sociable/images/facebook.png" title="Facebook" alt="Facebook" class="sociable-hovers" /></a></li>
	<li><a rel="nofollow"  target="_blank" href="http://twitter.com/home?status=Devolution%20-%20http%3A%2F%2Fshermansolutionsllc.com%2Fsecmusings%2Farchives%2F46" title="Twitter"><img src="http://shermansolutionsllc.com/secmusings/wp-content/plugins/sociable/images/twitter.png" title="Twitter" alt="Twitter" class="sociable-hovers" /></a></li>
	<li><a rel="nofollow"  target="_blank" href="http://www.linkedin.com/shareArticle?mini=true&amp;url=http%3A%2F%2Fshermansolutionsllc.com%2Fsecmusings%2Farchives%2F46&amp;title=Devolution&amp;source=SecMusings+Andy%27s+Reflections+on+Technology+and+Security&amp;summary=A%20hat%20tip%20to%20Bruce%20Schneir%20for%20spotting%20this%20one.%C2%A0%20The%20BBC%20is%20reporting%20that%20the%20NHS%20Central%20Lancashire%20backed%20up%20health%20data%20on%206%2C360%20prisoners%20and%20ex-prisoners%20by%20copying%20it%20on%20to%20a%20USB%20stick.%20%20They%20even%20encrypted%20the%20data.%0D%0A%0D%0AThen%20they%20lost%20the%20s" title="LinkedIn"><img src="http://shermansolutionsllc.com/secmusings/wp-content/plugins/sociable/images/linkedin.png" title="LinkedIn" alt="LinkedIn" class="sociable-hovers" /></a></li>
	<li><a rel="nofollow"  target="_blank" href="http://digg.com/submit?phase=2&amp;url=http%3A%2F%2Fshermansolutionsllc.com%2Fsecmusings%2Farchives%2F46&amp;title=Devolution&amp;bodytext=A%20hat%20tip%20to%20Bruce%20Schneir%20for%20spotting%20this%20one.%C2%A0%20The%20BBC%20is%20reporting%20that%20the%20NHS%20Central%20Lancashire%20backed%20up%20health%20data%20on%206%2C360%20prisoners%20and%20ex-prisoners%20by%20copying%20it%20on%20to%20a%20USB%20stick.%20%20They%20even%20encrypted%20the%20data.%0D%0A%0D%0AThen%20they%20lost%20the%20s" title="Digg"><img src="http://shermansolutionsllc.com/secmusings/wp-content/plugins/sociable/images/digg.png" title="Digg" alt="Digg" class="sociable-hovers" /></a></li>
	<li><a rel="nofollow"  target="_blank" href="http://delicious.com/post?url=http%3A%2F%2Fshermansolutionsllc.com%2Fsecmusings%2Farchives%2F46&amp;title=Devolution&amp;notes=A%20hat%20tip%20to%20Bruce%20Schneir%20for%20spotting%20this%20one.%C2%A0%20The%20BBC%20is%20reporting%20that%20the%20NHS%20Central%20Lancashire%20backed%20up%20health%20data%20on%206%2C360%20prisoners%20and%20ex-prisoners%20by%20copying%20it%20on%20to%20a%20USB%20stick.%20%20They%20even%20encrypted%20the%20data.%0D%0A%0D%0AThen%20they%20lost%20the%20s" title="del.icio.us"><img src="http://shermansolutionsllc.com/secmusings/wp-content/plugins/sociable/images/delicious.png" title="del.icio.us" alt="del.icio.us" class="sociable-hovers" /></a></li>
	<li><a rel="nofollow"  target="_blank" href="http://technorati.com/faves?add=http%3A%2F%2Fshermansolutionsllc.com%2Fsecmusings%2Farchives%2F46" title="Technorati"><img src="http://shermansolutionsllc.com/secmusings/wp-content/plugins/sociable/images/technorati.png" title="Technorati" alt="Technorati" class="sociable-hovers" /></a></li>
	<li><a rel="nofollow"  target="_blank" href="http://www.google.com/bookmarks/mark?op=edit&amp;bkmk=http%3A%2F%2Fshermansolutionsllc.com%2Fsecmusings%2Farchives%2F46&amp;title=Devolution&amp;annotation=A%20hat%20tip%20to%20Bruce%20Schneir%20for%20spotting%20this%20one.%C2%A0%20The%20BBC%20is%20reporting%20that%20the%20NHS%20Central%20Lancashire%20backed%20up%20health%20data%20on%206%2C360%20prisoners%20and%20ex-prisoners%20by%20copying%20it%20on%20to%20a%20USB%20stick.%20%20They%20even%20encrypted%20the%20data.%0D%0A%0D%0AThen%20they%20lost%20the%20s" title="Google Bookmarks"><img src="http://shermansolutionsllc.com/secmusings/wp-content/plugins/sociable/images/googlebookmark.png" title="Google Bookmarks" alt="Google Bookmarks" class="sociable-hovers" /></a></li>
	<li><a rel="nofollow"  target="_blank" href="https://favorites.live.com/quickadd.aspx?marklet=1&amp;url=http%3A%2F%2Fshermansolutionsllc.com%2Fsecmusings%2Farchives%2F46&amp;title=Devolution" title="Live"><img src="http://shermansolutionsllc.com/secmusings/wp-content/plugins/sociable/images/live.png" title="Live" alt="Live" class="sociable-hovers" /></a></li>
	<li><a rel="nofollow"  target="_blank" href="http://www.stumbleupon.com/submit?url=http%3A%2F%2Fshermansolutionsllc.com%2Fsecmusings%2Farchives%2F46&amp;title=Devolution" title="StumbleUpon"><img src="http://shermansolutionsllc.com/secmusings/wp-content/plugins/sociable/images/stumbleupon.png" title="StumbleUpon" alt="StumbleUpon" class="sociable-hovers" /></a></li>
	<li><a rel="nofollow"  target="_blank" href="http://slashdot.org/bookmark.pl?title=Devolution&amp;url=http%3A%2F%2Fshermansolutionsllc.com%2Fsecmusings%2Farchives%2F46" title="Slashdot"><img src="http://shermansolutionsllc.com/secmusings/wp-content/plugins/sociable/images/slashdot.png" title="Slashdot" alt="Slashdot" class="sociable-hovers" /></a></li>
	<li><a rel="nofollow"  target="_blank" href="http://www.blogospherenews.com/submit.php?url=http%3A%2F%2Fshermansolutionsllc.com%2Fsecmusings%2Farchives%2F46&amp;title=Devolution" title="Blogosphere News"><img src="http://shermansolutionsllc.com/secmusings/wp-content/plugins/sociable/images/blogospherenews.png" title="Blogosphere News" alt="Blogosphere News" class="sociable-hovers" /></a></li>
	<li class="sociablelast"><a rel="nofollow"  target="_blank" href="http://buzz.yahoo.com/submit/?submitUrl=http%3A%2F%2Fshermansolutionsllc.com%2Fsecmusings%2Farchives%2F46&amp;submitHeadline=Devolution&amp;submitSummary=A%20hat%20tip%20to%20Bruce%20Schneir%20for%20spotting%20this%20one.%C2%A0%20The%20BBC%20is%20reporting%20that%20the%20NHS%20Central%20Lancashire%20backed%20up%20health%20data%20on%206%2C360%20prisoners%20and%20ex-prisoners%20by%20copying%20it%20on%20to%20a%20USB%20stick.%20%20They%20even%20encrypted%20the%20data.%0D%0A%0D%0AThen%20they%20lost%20the%20s&amp;submitCategory=science&amp;submitAssetType=text" title="Yahoo! Buzz"><img src="http://shermansolutionsllc.com/secmusings/wp-content/plugins/sociable/images/yahoobuzz.png" title="Yahoo! Buzz" alt="Yahoo! Buzz" class="sociable-hovers" /></a></li>
</ul>
</div>
]]></content:encoded>
			<wfw:commentRss>http://shermansolutionsllc.com/secmusings/archives/46/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
