Special Forces master sergeant. Doctor and combat medic. Linguist. And, of course… Georgia Tech graduate. Meet Captain Dan Godbee, USA.
Let’s get something straight
Dennis posted a link to an AP story in which some random yahoo claims that the soldiers accused in the Abu Ghraib torture cases reflect “a broad lack of moral values in the culture at large”. Leaving aside the issue of relativism, what he should be saying is simple: “Our soldiers knew that what they were doing was wrong, but they chose to do it anyway.”
You’d have to be retarded (and I mean that literally) not to pick up on the Geneva Convention instruction given in Army and Marine Corps boot camp. I don’t know about the USAF and Navy, but I assume there’s similar instruction there. Back in ’86, those of us in the tender care of the 1st Recruit Training Battalion at Parris Island got a thorough drilling in the Law of Land Warfare, which covers what is and isn’t permissible in actual combat. Guess what? Torture isn’t on the “OK” list. The soldiers implicated in the Abu Ghraib torture cases may not have been schooled in the fine points of Geneva Convention requirements for the care of military prisoners, which are more detailed and quite different than the Law of Land Warfare.
I’m prepared to concede that they weren’t; that they should have been, and that the fact that they were not is an indictment of those given the responsibility of supervising and training the troops who run the prison. However, I’m with Stryker on this one:
Let me say it clearly for anyone who may be morally befuddled by such things as “right” and “wrong”: You don’t follow illegal orders. In fact, you have a moral and professional obligation to refuse an illegal order. That’s what these Nevada soldiers did:
“There was one incident when we were asked to keep detainees awake, to wake them up with metal drums. We said, `Absolutely not.’ I stopped them from doing it,” said Armstrong, a 37-year-old child protective services worker from Las Vegas.
She said no. Read the rest of that article to see how real soldiers conduct themselves.
There is no excuse or justification for what these troops did, and they are a stain on the military. Once the investigation concludes, I expect that those found guilty will be punished. One related question: why are the enlisted troops already being court-martialed, while the officers seem to be skating? They’re not skating, as this post explains clearly. This one also points out that there are several investigations underway, including one to identify how the Taguba report got loose before the senior DoD structure obtained it.
Comments Off on Let’s get something straight
Filed under Musings
Security Tuesday: MS04-015
It’s Security Tuesday again. This month, we get MS04-015, which covers a vuln in Help and Support Center on XP SP1 and Windows 2003 RTM (32- and 64-bit versions), and updates to MS04-014 (pretty much everyone) and MS01-052 (NT4.0 TSE SP6 and Windows 2000 SP2). Happy patching!
Comments Off on Security Tuesday: MS04-015
Filed under Security
Louisiana to ban sagging pants
A revised version of House Bill 1640 by Rep. Derrick Shepherd, D-Marrero, would mandate three eight-hour days of community service for anyone who publicly wears clothing that intentionally exposes undergarments, or any portion of his or her pubic hair, cleft of the buttocks or genitals.
Fortunately, the ACLU, the governor, and at least one state lawmaker understand that this problem is best addressed at home. Now, if they’d ban public wearing of bicycle shorts, I could get behind that.
Comments Off on Louisiana to ban sagging pants
Filed under FAIL
Remember the giblets
Long-time Exchange developer Larry Osterman had a great blog entry today titled “Remember the Giblets”. An excerpt:
“Giblets” are the pieces of software that you include in your product that you don’t always remember. Like zlib, or LHA, or MSXML, or the C runtime library. Whenever you ship code, you need to consider what your response strategy is when a security hole occurs in your giblets. Do you even have a strategy? Are you monitoring all the security mailing lists (bugtraq, ntbugtraq) daily? Are you signed up for security announcements from the creator of your giblets? Are you prepared to offer a security update for your product when a problem is found in one of your giblets? How do your customers know what giblets your application includes?
As administrators, how much do you know about the giblets on your servers? Are you paying attention to them, or only to the big chunks (like Exchange or SQL Server)?
Comments Off on Remember the giblets
Filed under General Stuff, Musings
Compliance and S/MIME
In the comments to a previous post, Clement Kent asks a set of good questions about how to combine compliance requirements with encryption. The bottom line: if you have DCAR (discovery, compliance, archive and recovery) requirements, you have to be very careful with message encryption. You have two basic alternatives:
- Archive the encrypted messages, then make sure that you preserve the key material so you can decrypt them later. This is really, really complicated, since you have to keep the certificates and private keys and CRLs around for however long your DCAR window is. The problem with this approach is that the DCAR system can’t index the messages, so you won’t have a good way to tell whether those messages are in scope when you do a DCAR query. It’s hard enough for most organizations to deploy a PKI in the first place, much less guarantee that they’ll be able to retrieve Joe CEO’s certificate six or seven years from now.
- Add the archive system as a recipient on all encrypted messages. The problem with this approach is that it doesn’t work out of the box; you’ll need to write your own tools. You could accomplish this via a client-side add-in that adds the archive agent as a recipient to any message that’s encrypted, or you could use an event sink that would reject (or quarantine/flag for human attention) any encrypted message that the archiving agent couldn’t read. As a bonus (mis)feature, this approach creates a very valuable target– get the key to the archive account, and you can read all the sooper-secret encrypted traffic.
The US Defense Department chose option 2. Consider the situation where Alice and Bob, both CIA analysts, need to communicate securely. Alice is in Langley, and Bob is in Baghdad. If the CIA mail system allows direct encrypted mail between them, there’s no way for the CIA itself to inspect the message contents. They work around this by using option 2, and also by allowing the mail to travel around Langley and Baghdad unencrypted, but using a server-to-server superencryption like that described in the Open Group‘s S/MIME Gateway Profile.
It’s less clear how you’d preserve DCAR capability with messages protected by Outlook’s IRM features. For messages sent to large groups (like, say, “all employees”), it’s a simple matter to add the archiver to the group; then you just have to ensure that you keep the IRM system up and running for the required length of time. For messages sent to individuals, you’re back to the requirement of writing code to either add the archiving account or to reject the message, but the code has to be smarter because IRM messages lack the easily-recognized S/MIME headers (not to mention that an ordinary message might have an IRM-protected attachment.. but we won’t go there for now).
Filed under General Stuff
Off to EMD
I’m speaking today at Enterprise Messaging Decisions 2004. This is actually my first day trip in a while. When I lived in Huntsville, it was possible to fly out at 0530 or 0630, change planes in Atlanta, and make it to pretty much anywhere by noon– enough time for a meeting or presentation– and then get home again around 11pm. In Toledo, that’s just not happening because of Delta’s flight schedule ex Cincinnati. So, since EMD is in Chicago, I’m going to drive– should be fun. Here’s the slide deck.
Filed under General Tech Stuff
Off to EMD
I’m speaking today at Enterprise Messaging Decisions 2004. This is actually my first day trip in a while. When I lived in Huntsville, it was possible to fly out at 0530 or 0630, change planes in Atlanta, and make it to pretty much anywhere by noon– enough time for a meeting or presentation– and then get home again around 11pm. In Toledo, that’s just not happening because of Delta’s flight schedule ex Cincinnati. So, since EMD is in Chicago, I’m going to drive– should be fun. Here’s the slide deck.
Comments Off on Off to EMD
Filed under General Stuff, Musings
Sasser on the loose
There’s a new Windows worm: W32.sasser. It exploits a vulnerability in the Local Security Authority (LSASS.exe) service; the vuln was fixed by the MS04-011 patch. The original MS bulletin and patch were issued on 4/13, and the MS alert on Sasser was released on 5/1, so you can see the gap between patch and exploit is getting shorter. I’m sure all of you out there have already patched your systems, but tell a friend: install patches when they’re released.
Anecdote: on Saturday, 5/1, Delta Airlines had a little dispatch problem that resulted in all their flights out of Atlanta being grounded for almost seven hours. The problem appears to have been with the airport computers used to calculate weight and balance according to FAA specs. One passenger on an affected flight reports that the flight crew attributed the delay to the “Mayday virus”. I wonder what the real cause was?
Update: this WSJ article‘s last paragraph mentions Delta, Goldman Sachs, and JP Morgan Chase as companies affected; it also says that a Delta spokesman wouldn’t say whether Sasser was to blame.
Comments Off on Sasser on the loose
Filed under General Stuff, Musings
MSG381 TechEd deck posted
Well, it’s only two weeks late, but hey, who’s counting? (Besides the speaker manager at Microsoft, of course!) The first draft of my deck for MSG381, Designing High-Availability Exchange Solutions, is now available here. If you’re coming to TechEd, the session is Thursday at 8:30– stop by and say hello!
Update: Andy Webb was kind enough to point out a bad link, which is now fixed.
Comments Off on MSG381 TechEd deck posted
Filed under General Stuff, Musings
Running your own subordinate CA
Reader Remek Kocz says:
First of all, thanks for writing Secure Messaging. I’ve been doing a lot of research on Exchange 2K security recently, and your book pretty much filled in all the gaps. The reason I’m writing you is that I have not been able to find an answer to what I thought was a simple question (Usenet wasn’t much help, surprisingly). I’ve been tasked to secure our OWA servers w/SSL, and the issue of certificates came up. Is it possible to obtain a cert from a trusted authority like Verisign and then issue self-issued certificates with a path back to the Verisign one? Being a school district, albeit a large one, we need to look out for every dollar, so I wondered if it would be possible to combine the self-issuing CA &a commercial one. A pure self-issuing CA is not feasible for us, since many people travel without laptops, and there is no way of knowing how they’ll access the OWA servers.
This is a classic case for use of a subordinate CA: you want to create a CA that issues certs to end entities (in this case, your OWA servers; it might equally be used to issue certs to users), and you want that CA’s cert to be issued by a well-known commercial CA. You might think that Verisign, Thawte, and other commercial certificate vendors would provide this as a service, but as far as I can tell, they don’t. Why? Their preference is for you to use them as an issuer, offloading all CA work to them (and, incidentally, paying a per-certificate, per-year fee!) For the specific case you have in mind, Verisign offers their managed PKI service: they issue the certs, and you manage the issuance and revocation process via a web-based admin tool…but you don’t run your own CA. Section 3.1.1 of Verisign’s certification practices statement talks about the process of registering as a non-Verisign sub CA, but I can’t find where you actually do that on their web site. I’ll post more details if I can find a better answer.
Update: BeTrusted‘s OmniRoot service does exactly what you want. Thanks to David Cross for the tip.
Comments Off on Running your own subordinate CA
Filed under General Stuff
Bring back the draft?
From today’s New York Times, an editorial by William Broyles. His closing paragraph:
If this war is truly worth fighting, then the burdens of doing so should fall on all Americans. If you support this war, but assume that Pat Tillman and Other People’s Children should fight it, then you are worse than a hypocrite. If it’s not worth your family fighting it, then it’s not worth it, period. The draft is the truest test of public support for the administration’s handling of the war, which is perhaps why the administration is so dead set against bringing it back.
I’ve long supported the idea of bringing back some form of compulsory service. It’s proved to work well in a wide range of cultural and social environments, and it provides a powerful counterbalance to exactly the kind of problem we’re having now: the people calling the shots don’t have any personal stake in the way the military is used. However, I think Broyles is too quick to dismiss the difference in quality between an all-volunteer force (where presumably everyone there wants to be there) and a force of conscripts. There’s no question that a volunteer force tends to build up a more experienced core of non-commissioned officers, which (as any officer will tell you) is the real backbone of the armed forces. Without that core, it’s not clear that the US military would be able to maintain the same level of professionalism and discipline. It’s also an open question whether a mixed force of volunteers and conscripts would suffer from the same kinds of friction we’ve been seeing between regular and reserve/National Guard units. Interestingly, one benefit to come from the wars in Afghanistan and Iraq is that regular units are getting to see that reserve and NG units are just as prepared and capable, in most cases, as their regular counterparts.
Fire suppression
It doesn’t matter how secure your server is if it’s on fire. The other Scoble has two good posts that describe the current state of the art in fire-suppression systems: here and here. This is actually something I talk about in Chapter 5 (physical &operational security), even though most of us are stuck with whatever physical plant is already in the building. Interestingly, one commenter mentioned pre-action sprinkler systems, which use water but which aren’t activated without both heat and smoke alarms. (And hey, the inert suppression gas of choice is Inergen, not “Innergen”.)
Comments Off on Fire suppression
Filed under General Stuff, Musings
Thomas speaks
Tonight we had the four missionaries over for dinner. The discussion turned to one of the young women in our ward– she’s very attractive. I told Arlene that she cleaned up nicely, whereupon Thomas shouted out “But you cook even better than you clean, Mom!” Hilarity ensued.
Comments Off on Thomas speaks
Filed under Friends & Family
Entourage 2004 RTMs
Entourage 2004 has been released to manufacturing, so I can now talk about it. I’ve been working with it for the last several months, and it’s a great piece of work. I’m working on a long article on it for Exchange & Outlook Administrator, but in the meantime, you might be able to try it for free. What? It’s true. If you have valid Exchange CALs for your users, you’re able to use Entourage as a client. See this “how to buy” page for more details (but don’t ask me where you’re supposed to get the bits, because I don’t know!)
Comments Off on Entourage 2004 RTMs
Filed under General Stuff, Musings
