<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Short-term defenses for web applications</title>
	<atom:link href="http://www.tssci-security.com/archives/2008/03/11/short-term-defenses-for-web-applications/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.tssci-security.com/archives/2008/03/11/short-term-defenses-for-web-applications/</link>
	<description>top secret/secure computing information</description>
	<lastBuildDate>Sun, 27 Mar 2011 12:47:22 -0500</lastBuildDate>
	<generator>http://wordpress.org/?v=2.8.6</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: dre</title>
		<link>http://www.tssci-security.com/archives/2008/03/11/short-term-defenses-for-web-applications/comment-page-1/#comment-5007</link>
		<dc:creator>dre</dc:creator>
		<pubDate>Wed, 12 Mar 2008 20:57:14 +0000</pubDate>
		<guid isPermaLink="false">http://www.tssci-security.com/archives/2008/03/11/short-term-defenses-for-web-applications/#comment-5007</guid>
		<description>@ Marcin:

Of course.  This isn&#039;t about providing &quot;a solution&quot; to PCI-DSS 1.1 Requirement 6.6.  This is about providing the &quot;only solution&quot; for PCI-DSS 1.2/1.3/etc Requirement 6.6.

Future conversation:
Alice: Hey, Bob, did you get certified for AFV?
Bob: Yeah, it only cost me $100K to certify this year, but I&#039;ve got 25 clients at $40K each to install a WHS Guard and F5 Big/IP LB pair!
Alice: Wow, what a smart business model.  You&#039;re such a genius, Bob.
Bob: Don&#039;t thank me - Thank the PCI Council for this one.
Alice: How do I become an AFV?
Bob: Oh, that&#039;s easy.  All you have to do is pay the $100K and show up with these two boxes.  The WHS box costs $30K and the Big/IP box costs $50K.  Then the vendor verifies that you know how to how to setup the IP address from the front-panel LCD&#039;s.  Don&#039;t worry about that though, there&#039;s a help guide if you get lost.
Alice: Wow, that sounds really easy.
Bob: It is.
Alice: I heard that Breach Security makes a comparable product to the Big/IP.  Can I bring one of those instead?
Bob: Whoah, careful now.  I talked with Charlie, who brought a Breach box to the certification test last year.  He failed the test and was out the $100K.  If you want to pass the AFV and get certified, you have to bring both a WHS box and a Big/IP.
Alice: Oh sorry to hear that about Charlie.  Speaking of breaches, didn&#039;t all of your clients get breached last year?
Bob: Well, yeah, but that&#039;s not my problem.
Alice: There&#039;s no repercussions?  I thought you were supposed to help your clients prevent these kinds of attacks?
Bob: No, I just install these boxes which are only a &quot;layer&quot; in their &quot;defense-in-depth&quot; strategy.  I can&#039;t save the world!
Mallory (secretly listening): [To herself: Muhahaahhahaha!]</description>
		<content:encoded><![CDATA[<p>@ Marcin:</p>
<p>Of course.  This isn&#8217;t about providing &#8220;a solution&#8221; to PCI-DSS 1.1 Requirement 6.6.  This is about providing the &#8220;only solution&#8221; for PCI-DSS 1.2/1.3/etc Requirement 6.6.</p>
<p>Future conversation:<br />
Alice: Hey, Bob, did you get certified for AFV?<br />
Bob: Yeah, it only cost me $100K to certify this year, but I&#8217;ve got 25 clients at $40K each to install a WHS Guard and F5 Big/IP LB pair!<br />
Alice: Wow, what a smart business model.  You&#8217;re such a genius, Bob.<br />
Bob: Don&#8217;t thank me &#8211; Thank the PCI Council for this one.<br />
Alice: How do I become an AFV?<br />
Bob: Oh, that&#8217;s easy.  All you have to do is pay the $100K and show up with these two boxes.  The WHS box costs $30K and the Big/IP box costs $50K.  Then the vendor verifies that you know how to how to setup the IP address from the front-panel LCD&#8217;s.  Don&#8217;t worry about that though, there&#8217;s a help guide if you get lost.<br />
Alice: Wow, that sounds really easy.<br />
Bob: It is.<br />
Alice: I heard that Breach Security makes a comparable product to the Big/IP.  Can I bring one of those instead?<br />
Bob: Whoah, careful now.  I talked with Charlie, who brought a Breach box to the certification test last year.  He failed the test and was out the $100K.  If you want to pass the AFV and get certified, you have to bring both a WHS box and a Big/IP.<br />
Alice: Oh sorry to hear that about Charlie.  Speaking of breaches, didn&#8217;t all of your clients get breached last year?<br />
Bob: Well, yeah, but that&#8217;s not my problem.<br />
Alice: There&#8217;s no repercussions?  I thought you were supposed to help your clients prevent these kinds of attacks?<br />
Bob: No, I just install these boxes which are only a &#8220;layer&#8221; in their &#8220;defense-in-depth&#8221; strategy.  I can&#8217;t save the world!<br />
Mallory (secretly listening): [To herself: Muhahaahhahaha!]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Marcin</title>
		<link>http://www.tssci-security.com/archives/2008/03/11/short-term-defenses-for-web-applications/comment-page-1/#comment-5002</link>
		<dc:creator>Marcin</dc:creator>
		<pubDate>Wed, 12 Mar 2008 15:38:23 +0000</pubDate>
		<guid isPermaLink="false">http://www.tssci-security.com/archives/2008/03/11/short-term-defenses-for-web-applications/#comment-5002</guid>
		<description>Rybolov, you forgot the C-word too!</description>
		<content:encoded><![CDATA[<p>Rybolov, you forgot the C-word too!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: rybolov</title>
		<link>http://www.tssci-security.com/archives/2008/03/11/short-term-defenses-for-web-applications/comment-page-1/#comment-5001</link>
		<dc:creator>rybolov</dc:creator>
		<pubDate>Wed, 12 Mar 2008 14:47:01 +0000</pubDate>
		<guid isPermaLink="false">http://www.tssci-security.com/archives/2008/03/11/short-term-defenses-for-web-applications/#comment-5001</guid>
		<description>Hi Dre

Somebody overdose on their curmudgeon pills this morning?   =)

As a techie, you underestimate the ultimate vendor strategy:  putting &quot;The Big S&quot; on a product makes it sell for 50% more.  Today, a BigIP Load Balancer for $40K, tomorrow, a BigIP Load Balancer with Integrated Security for $60K.</description>
		<content:encoded><![CDATA[<p>Hi Dre</p>
<p>Somebody overdose on their curmudgeon pills this morning?   =)</p>
<p>As a techie, you underestimate the ultimate vendor strategy:  putting &#8220;The Big S&#8221; on a product makes it sell for 50% more.  Today, a BigIP Load Balancer for $40K, tomorrow, a BigIP Load Balancer with Integrated Security for $60K.</p>
]]></content:encoded>
	</item>
</channel>
</rss>

