Sabtu, 07 Februari 2009

How important is Identity Based Encryption?

Luther Martin of Voltage published a blog entry entitled How important is IBE? which I will provide some deeper analysis on...



Voltage primarily makes much of its revenue from email encryption which is a solution to a problem that helps enterprises comply at the expense of their customers customers.

Consider a scenario where I may be an independent insurance agent who does business with dozens of insurance carriers such as AIG, Travelers, Chubb, Progressive and USAA. The insurance ecosystem has lots of personally identifiable information from your drivers license which is used to do Driving record checks, to social security numbers for credit scores to health information on the chance you crashed your overpriced SUV into a bridge and bled all over the dash. So, what do you think happens to this small independent insurance agent if Travelers chooses ZixMail, AIG chooses Voltage, Chubb chooses Tumblewed, Progressive chooses PGP and so on?

The answer is actually disturbing in that the user would either be forced to pay for client software licenses in order to be able to read his email in his own inbox or he would be required to establish a yet another credential (as if he doesn't have enough already) and read his email from other than his inbox. Does this feel right to anyone especially when there are standards-based approaches that could be had?

Why hasn't Microsoft championed interoperable email encryption? Could the Microsoft Exchange team solve this problem in an open manner and work with the folks over at Sendmail or Postfix? I have been working on a document that I hope to publish (it will be under Creative Commons) shortly that will outline some ideas on exactly how this should work. All I need are some names of some folks in these communities that would read, review and if in agreement, would take swift deliberate action in moving towards implementation of an interoperable solution.

Another aspect of IBE that I find somewhat troubling is that the conversation has centered around openness in an somewhat sinister way. Anyone can take the IBE algorithms and inspect them which is useful for the cryptography crowd but otherwise is incomplete. For example, being a member of OWASP, we don't review algorithms to determine security but we do look at APIs and implementations and in this scenario, OWASP cannot build a reference implementation, share it with others in an open manner, etc, so there is no way to understand it is truly secure.

PKI has multiple implementations ranging from closed source offerings such as Microsoft certificate services to open source offerings such as EJBCA, OpenSSL and so on. The ability to choose from open and closed offerings and offer the opportunity for deeper inspection is vital to the security of the IT ecosystem. Hopefully, the folks over at Voltage will champion the creation of open source alternatives in order to get the value proposition of IBE out to others to touch more deeply.

How come identity-based encryption isn't part of identity management? If I am an employee and I get keys to sign and encrypt, shouldn't the PKI solutions from Voltage, ChosenSecurity, Verisign, etc be managed from my identity infrastructure? Why aren't these types of vendors also thinking about SPML?

It feels to me that IBE could offer immense value if/when integrated into an ECM architecture. The ability to encrypt documents and content using this public key model is a lot better than PKI as it has many of the same characteristics of email, yet I haven't found evidence that IBE is even on the radar of smart ECM industry analysts such as Nick Patience of the 451 Group or Alan Pelz-Sharpe of CMSWatch. Equally, I cannot find evidence that anyone in the ECM community such as the folks over at Nuxeo, Alfresco, Joomla, OpenText or Filenet also understand its value. Here, I will cut Craig Randall of Documentum some slack as he would more than likely be forced to leverage RSA products which are counter to the IBE thinking.

More importantly, I don't understand risk of deploying IBE. If I have a PKI deployment that leverages MD5 and the RSA algorithm and they break, I don't loose all my primitives. I can still switch out RSA for elliptic curves and MD5 for SHA-256 and keep rocking. If IBE breaks, what other algorithms could I switch it out for.

Anyway, I don't have expectations of transparency on this subject, simply sharing whats on my mind. I do hope that the cryptography crowd, folks at Gartner and Forrester and software vendors will think about IBE and how it may work in large enterprises...

Jumat, 06 Februari 2009

Enterprise Architecture: Is 2009 the year of anti-process? (Part Two)

Continuing previous blog post on how excessive focus on process is harmful to the enterprise...



Processes should be enablers and multipliers for sound IT work, not replacements. Processes and their value proposition should also be apparent to all those infected by it. Sadly, ITIL is starting to become an even worse practice and is surpassing the CMMI crowd by factors.

ITIL as a framework is to help align IT operations, yet many of its adopters have lost sight of the overall goal of doing quality work. It's difficult to say if, in the absence of an IT management framework, they would have made the same mistakes, more mistakes, or less. But it's hard to blame the process when the problem lies at layer 8.

The biggest debacle in most enterprises is the notion of change management where they put lots of controls around change but production has lower availability numbers than when the process didn't exist. In many implementations of change management, the burden of identifying and conducting appropriate coordinations fell on the subject matter expert submitting the change. When combined with the fact that the organization chart doesn't have anyone that has full visibility into the IT lifecycle, this becomes like mixing gasoline with a arsonist. Something is bound to blow up.

So, can we just give a middle finger to process? I don't care how well-written your processes are, IT professionals owe it to their employers and customers to do the best work they can, regardless of the presence or absence of process. Regardless of outsourcing, managers still need to evaluate the quality of work that IT professionals produce and the degree in which they are serving their customers.

Frameworks like ITIL are there to help the IT organization use their collective skill sets to better serve their customers. They are not however justification for IT professionals to abdicate the very assets that make them valuable technologists.

Kamis, 05 Februari 2009

Enterprise Architecture: Are you willing to take a paycut to save jobs?

Many executives are indoctrinated into the repeat after me, I believe that top talent needs to be compensated to market rates as an excuse to make extreme compensation...



In today's economy, the real leaders will their own needs aside and do what is right for others. Real leadership requires followership and no one today is stupid enough to follow a CEO who is excessively compensated in today's marketplace regardless of the factors at play. Consider:

  • Bear Stearns: $34 million for CEO James Cayne. The acknowledged direct cost to the taxpayers from Bear's demise so far is $2.7 billion; ten times that number may be a more reasonable assessment of the actual cost.

  • Lehman Brothers: $27 million for CEO Richard Fuld. The financial freeze that followed the collapse of Lehman is seen by many as the key event that turned the recession of 2007-08 into the frightening freefall currently under way.

  • Citigroup: $25 million for CEO Charles Prince. Citi's stock price has since fallen from $50 a share to $3.50.

  • Countrywide Financial: $43 million for CEO Angelo Mozilo. According to Ashcraft and Schuermann, Countrywide was at that time the nation's leading issuer of subprime mortgage-backed securities and the third biggest originator of subprime mortgages.

That these individuals should have profited so richly from running their companies into the ground, and bringing the rest of us down with them, offends anyone's sense of justice. But it also raises a profoundly important question from the perspective of economic efficiency, in that the above numbers constitute a prima facie case that there were powerful economic incentives for these individuals to make decisions that were in fact not in their companies' or society's best interest.

Leadership isn't just focusing on Wall Street but also Main Street and we all have to look out for each other. The 2009 leadership theme should be to encourage the enterprise to be more human...

Related Posts Plugin for WordPress, Blogger...