Tuesday, May 6, 2008

marginalizing threats

I sit through several presentations a month. It's part of my job, and some of the presentations can even be insightful. But lets talk about threats. This is something most people like to touch on; certainly it's a topic that can be on the more exotic side. Cloak and dagger, espionage (e-espionage? i-espionage?) and all that.
Some advice to separate you from your competitors:
Do not talk about RBN (or other such organizations) and then reference "people living in their mother's basement".

On second thought, do not mention pimply kids or mothers basements no matter what your discussing.

It marginalizes the threat into a pigeon-holed ideal of what the threat was in 1989. Nowadays, The guy may still be in the basement but he simply an agent of a larger threat. It's irrelevant where he lives, but the fact that he spends 40-60 hours a week on herding his bot or owning websites and generally being a symptom of a bigger problem.

Get out of the old mindset, you're hurting the real issue here if you keep floating back and forth between threat models.

additional reading: Evolving Threats by Corman.

