Senin, 05 September 2011

Apple vs the rest of the mobile ecosystem, Who is right and who is evil?

For users of iPads who want to read books or other content need to pay attention to recent moves by Amazon in how they changed their Kindle reader. One of the things that stimulated this change was the fact that Amazon didn't want to give Apple a 30% cut of content purchases. So, at some level I think the ecosystem understands that a store should make money off selling applications, but would agree that this is taking it a little too far when you have already sold the application and now want to also collect royalties on content within the application.

If you look at the other mobile stores such as those by Microsoft, they don't have a clear policy in this regard as to whether they will do what is best for the ecosystem vs simply looking out for their own interests. From a developer perspective, this also now means that you will most certainly be confronted with the potential of a new set of APIs at the expense of other mechanisms that may be used for purchasing content. Think about the possibilities of censorship if say the Wall Street Journal, New York Times or even the Drudge Report was forced to fork over dollars simply for accessing content through mobile channels.

The funny thing about this type of policy is this shows a lack of leadership in the marketplace. What should mobile software developers think if a company creates a policy and frequently changes their posture on it? Why can't various mobile App Stores simply have a policy and stick to it...

Senin, 29 Agustus 2011

Is the security model behind SSL certificates fundamentally busted?

Most recently, there was a breach of a trusted Root CA which caused a lot of people in the infosec community to come out of the woodwork to discuss. My take has been that this isn't the first nor the last. The better question to ask is whether the current model of issuing SSL certificates is fundamentally busted...







Everyone is focused on remediation without thinking about how to improve the model. Some have proposed draconian measures such as removing DigiNotar from the list of trusted CAs. This of course has a side effect of invalidating legimitate certificates which will introduce as another side effect the encouragement of users to bypass any browser certificate warnings.



The SSL specification has the notion of revocation lists built in whereby a browser can check either a revocation list or using OCSP query a service that will validate whether the certificate is current. Did anyone happen to notice that this approach doesn't really work for root CA's that are compromised? So the only remediation is to wait for all the vendors to issue patches and for admins to apply them. Anyone care to guess what the IT track record of applying timely security patches are?



The fundamental flaw in security is in thinking that anything hierachical will ever be secure. We have a better possibility if we acknowledge a basic principle.
    Hyperlinks subvert hierarchy
We should never be reliant on any notion of authority and should instead figure out how to migrate security to more of a peer-oriented reputation model.



So, when a certificate gets compromised, we lose the fact that we can no longer vouch for server identity but that we still need mechanisms to evoke encryption. Why do we have a model that couples identity to encryption? Shouldn't these things be two distinction mechanisms in a scalable architecture...



Rabu, 29 Juni 2011

Suboptimal Thinking within Enterprise Architecture Practices

Many organizations attempt to run their "airline" by ordering DC-3's for their transatlantic runs, building huge airports which are "best practice" based off Heathrow or LAX, giving the aircrew mechanics crash courses in nautical engineering, and selling free parachutes with each airline ticket as "added value". What is the stimulus for stopping the insanity of how enterprise architecture is practiced?



Consider the infamous Winchester House and its architecture that created rooms with no doors and stairs that lead to nowhere. At some level though, through the lens of perception management, it satisfied the whims of its creator and was built for purpose.

Many of us will focus on the fact that the Winchester House was built in a highly inefficient manner but at some level, we aren't acknowledging the inefficiencies in our own shops for fear they may be disturbingly similar.

What can we learn from the Winchester House? After all, it had an overall plan and a big framework, yet the outcome wasn't aesthetically pleasing. Maybe we need to figure out the line as professionals we shouldn't cross when it comes to managing perception? We need to remember that enterprises live and thrive beyond just the current person at the helm.

Lets face it, a solution needs a problem. If the people required to change do not perceive there is a problem, you can spend from now until the cows come home but you will never convince them to change and will be doomed to creating great plans, large frameworks and delivering monstrosities that are pleasing to the customer but no one else that comes afterwards...

Related Posts Plugin for WordPress, Blogger...