Warning

 

Close

Confirm Action

Are you sure you wish to do this?

Confirm Cancel
BCM
User Panel

Site Notices
Arrow Left Previous Page
Page / 4
Posted: 5/22/2015 12:21:42 PM EDT
So, I've been contemplating having some sort of UC summit.  Kinda a semi-formal where a bunch of us gurus can all get together on a google hangout and people can pick a topic and maybe give a 10 or 15min presentation followed by Q&A or a round table discussion or something.  Just as sort of a way that the industry experts here can exchange ideas, and have a good time for a couple of hours.


Thoughts?

ETA:

Summit Document - OneDrive
Link Posted: 5/22/2015 12:47:54 PM EDT
[#1]
I'd join in.
Link Posted: 5/22/2015 12:59:46 PM EDT
[#2]
I would be willing to attend, present not so much. I am a lightweight in this world, I prefer my dark corner.
Link Posted: 5/22/2015 1:29:17 PM EDT
[#3]
So, so far we have Psyber presenting on something while Angry-American hangs on every word
Link Posted: 5/22/2015 1:40:17 PM EDT
[#4]
I'm in.

I'll speak on whatever topic ya'll need, assuming I know it well enough.
Link Posted: 5/22/2015 1:55:36 PM EDT
[#5]
Link Posted: 5/22/2015 1:57:33 PM EDT
[#6]
Discussion ForumsJump to Quoted PostQuote History
Quoted:
I'd attend that.  

Problem is, I don't know how much value I bring to the table.  I'm very much a dabbler in many IT areas... mile-wide-and-an-inch-deep, so to speak.  I don't know how worthwhile my contribution would be any particular topic.

For instance:  

VOIP.  I use it, and have built/set-up several systems (including ZRTP-encrypted).  But you'd want Subnet for a serious treatment of the topic.
Forensics.  I know a little bit, but I bow in the presence of a master (Bcauz3y)
Cyber-security.  Any number of posters would do a FAR better job than myself
Coding.  Ditto

With the exception of the security-camera stuff, and the setup/networking thereof.  That I probably know in enough depth to provide something useful.
View Quote


I'd pay good money to attend your lecture on that subject.
Link Posted: 5/22/2015 2:27:54 PM EDT
[#7]
So we have the following:

Presenters and topics:

Psyber - undecided

bcauz3y - security stuff (most likely)

TheGreyMan - IP Security Cameras


Also added to the OP
Link Posted: 5/22/2015 2:42:46 PM EDT
[#8]
Why not just do something a little more informal without official presenters? Lower pressure and would get more people engaged.
Link Posted: 5/22/2015 3:04:41 PM EDT
[#9]
Discussion ForumsJump to Quoted PostQuote History
Quoted:
Why not just do something a little more informal without official presenters? Lower pressure and would get more people engaged.
View Quote


I could see that being fun as well.  Maybe for a first time?
Link Posted: 5/22/2015 3:06:23 PM EDT
[#10]
If it's open to the "public" I would love to attend. Right now I'm just a geek who is interested in turning all this into a career.

The most advanced thing I've done is setup a web host on Amazon EC2 from various tutorials and things. So not a guru in any sense of the word.
Link Posted: 5/22/2015 3:09:07 PM EDT
[#11]

Discussion ForumsJump to Quoted PostQuote History
Quoted:


If it's open to the "public" I would love to attend. Right now I'm just a geek who is interested in turning all this into a career.



The most advanced thing I've done is setup a web host on Amazon EC2 from various tutorials and things. So not a guru in any sense of the word.
View Quote
Ive been in IT now for 15 years and I am still am amateur, On a daily basis I feel like I am barely treading water.



 
Link Posted: 5/22/2015 3:19:09 PM EDT
[#12]
Hey what if we partnered with Subnet and he broadcasted the whole thing live?  That would be kinda neat.
Link Posted: 5/22/2015 3:21:55 PM EDT
[#13]
you can do google hangouts that have a public sidecar, essentially.

you don't have to give everyone that's watching a mic
Link Posted: 5/22/2015 3:51:22 PM EDT
[#14]
Discussion ForumsJump to Quoted PostQuote History
Quoted:
Hey what if we partnered with Subnet and he broadcasted the whole thing live?  That would be kinda neat.
View Quote

I'd be happy to, but I think it'd probably be better to see if Google Hangouts have a way to allow people to listen in, without being participants (I'm sure they do). It'll work on mobile devices this way. I'm actually in the middle of upgrading my broadcast server (it's still running win2k3).
Link Posted: 5/22/2015 3:59:33 PM EDT
[#15]
It's sounding like hangouts has a side car, I'll have to look into that when I get off work.

Sub how would you feel about being an MC?
Link Posted: 5/22/2015 4:17:05 PM EDT
[#16]
You can livestream Hangouts on your YouTube channel. Many BookTube folks do that when doing panel book discussions.
Link Posted: 5/22/2015 4:21:56 PM EDT
[#17]
I think this is a hell of an interesting idea and would be wildly informative.  Unlike a typical industry conference, presentation, or partner meeting, there's no "selling" or politics here.  People will get the unvarnished and ugly truth about the various subjects.

I'm a C level IT executive for a mid-size corporation in the security and investigations industry.  BEFORE you get out the torches and pitchforks, I spent 10 years in the trenches as a network and sys engineer for some sizable Silicon Valley companies before I went to the dark side!  Trust me, I'm the CIO/Director you wish you had.  

If that's useful, I'd be glad to offer my time.  Perhaps something like "Why your CIO/Director hates you and forces you to keep the AS400 system" or "How I made the shareholders happy by kicking the IT department in the balls"

ETA: I keed I keed!

sort of.

No seriously it's a joke.

Kind of....



Link Posted: 5/22/2015 4:24:04 PM EDT
[#18]
tag for short attention span.
Link Posted: 5/22/2015 4:26:29 PM EDT
[#19]
If Subnet is hosting than I might be better off in the sidecar, cause if he is drinking, so am I.
Link Posted: 5/22/2015 4:42:31 PM EDT
[#20]
Discussion ForumsJump to Quoted PostQuote History
Quoted:
I think this is a hell of an interesting idea and would be wildly informative.  Unlike a typical industry conference, presentation, or partner meeting, there's no "selling" or politics here.  People will get the unvarnished and ugly truth about the various subjects.

I'm a C level IT executive for a mid-size corporation in the security and investigations industry.  BEFORE you get out the torches and pitchforks, I spent 10 years in the trenches as a network and sys engineer for some sizable Silicon Valley companies before I went to the dark side!  Trust me, I'm the CIO/Director you wish you had.  

If that's useful, I'd be glad to offer my time.  Perhaps something like "Why your CIO/Director hates you and forces you to keep the AS400 system" or "How I made the shareholders happy by kicking the IT department in the balls"

ETA: I keed I keed!

sort of.

No seriously it's a joke.

Kind of....



View Quote



I think something from the perspective of C-level would be awesome and informative, I think it's paramount that mid-level and senior engineers understand the drive behind top level decisions.
Link Posted: 5/22/2015 4:42:40 PM EDT
[#21]
Tag for interest. Off to see how far I'm behind on CPE's.
Link Posted: 5/22/2015 4:51:56 PM EDT
[#22]
Discussion ForumsJump to Quoted PostQuote History
Quoted:
Tag for interest. Off to see how far I'm behind on CPE's.
View Quote

Link Posted: 5/22/2015 5:08:26 PM EDT
[#23]

Discussion ForumsJump to Quoted PostQuote History
Quoted:





View Quote View All Quotes
View All Quotes
Discussion ForumsJump to Quoted PostQuote History
Quoted:



Quoted:

Tag for interest. Off to see how far I'm behind on CPE's.






 
Just wrapped up 32+ hours of physical security stuff which should help. It takes a special kind of asshole to design a certification program that requires continual upkeep after passing a six-hour test.
Link Posted: 5/22/2015 5:11:20 PM EDT
[#24]
IP everywhere.  does anyone want to know anything about how IP everywhere?  Should only take a minute or 2.  

actually, depending on when this is, I may be able to give a presentation on software defined networks using mininet.  apparently academia has some vision for this.  im already a huge gns3/dynamips homer, so I feel right at home with mininet, you can even script stuff with python in it.
Link Posted: 5/22/2015 5:14:42 PM EDT
[#25]
Discussion ForumsJump to Quoted PostQuote History
Quoted:
IP everywhere.  does anyone want to know anything about how IP everywhere?  Should only take a minute or 2.  

actually, depending on when this is, I may be able to give a presentation on software defined networks using mininet.  apparently academia has some vision for this.  im already a huge gns3/dynamips homer, so I feel right at home with mininet, you can even script stuff with python in it.
View Quote

I'll buy you a beer.
Link Posted: 5/22/2015 5:25:11 PM EDT
[#26]
i'd like to listen in and learn from the smart folks.

would love to hear from web dev experts as well btw.
Link Posted: 5/22/2015 5:27:22 PM EDT
[#27]
Discussion ForumsJump to Quoted PostQuote History
Quoted:

I'll buy you a beer.
View Quote View All Quotes
View All Quotes
Discussion ForumsJump to Quoted PostQuote History
Quoted:
Quoted:
IP everywhere.  does anyone want to know anything about how IP everywhere?  Should only take a minute or 2.  

actually, depending on when this is, I may be able to give a presentation on software defined networks using mininet.  apparently academia has some vision for this.  im already a huge gns3/dynamips homer, so I feel right at home with mininet, you can even script stuff with python in it.

I'll buy you a beer.


MORE BEER = MORE IP EVERYWHERE
Link Posted: 5/22/2015 5:49:37 PM EDT
[#28]
Discussion ForumsJump to Quoted PostQuote History
Quoted:
IP everywhere.  does anyone want to know anything about how IP everywhere?  Should only take a minute or 2.  

actually, depending on when this is, I may be able to give a presentation on software defined networks using mininet.  apparently academia has some vision for this.  im already a huge gns3/dynamips homer, so I feel right at home with mininet, you can even script stuff with python in it.
View Quote


I would love to hear something on software defined networks!
Link Posted: 5/22/2015 6:14:41 PM EDT
[#29]

in.  not sure what sort of presentation would be interesting to folks , but i'm in.

ar-jedi
Link Posted: 5/22/2015 6:34:34 PM EDT
[#30]
Discussion ForumsJump to Quoted PostQuote History
Quoted:

in.  not sure what sort of presentation would be interesting to folks , but i'm in.

ar-jedi
View Quote

I know I'd find pretty much anything you had to say about Net Neutrality to be interesting and informative.
Link Posted: 5/22/2015 6:46:36 PM EDT
[#31]
I'm in, depending on when it is as I'm on the other side of the world.

Let me think about presenting, I'm open to doing it, just not sure what people want to know about.

Link Posted: 5/22/2015 6:50:51 PM EDT
[#32]
Discussion ForumsJump to Quoted PostQuote History
Quoted:
I'm in, depending on when it is as I'm on the other side of the world.

Let me think about presenting, I'm open to doing it, just not sure what people want to know about.

View Quote


I'd like to hear your input on nation state threats.

I'm reasonable well connected into it, but not nearly as well as you.
Link Posted: 5/22/2015 6:51:16 PM EDT
[#33]
Discussion ForumsJump to Quoted PostQuote History
Quoted:


I'd like to hear your input on nation state threats.

I'm reasonable well connected into it, but not nearly as well as you.
View Quote View All Quotes
View All Quotes
Discussion ForumsJump to Quoted PostQuote History
Quoted:
Quoted:
I'm in, depending on when it is as I'm on the other side of the world.

Let me think about presenting, I'm open to doing it, just not sure what people want to know about.



I'd like to hear your input on nation state threats.

I'm reasonable well connected into it, but not nearly as well as you.


I like this idea.
Link Posted: 5/22/2015 6:54:58 PM EDT
[#34]
Discussion ForumsJump to Quoted PostQuote History
Quoted:

I know I'd find pretty much anything you had to say about Net Neutrality to be interesting and informative.
View Quote View All Quotes
View All Quotes
Discussion ForumsJump to Quoted PostQuote History
Quoted:
Quoted:

in.  not sure what sort of presentation would be interesting to folks , but i'm in.

ar-jedi

I know I'd find pretty much anything you had to say about Net Neutrality to be interesting and informative.


whatever solution sells the most hardware, i'm for!  

ar-jedi

ps
maybe this is an interesting point...

from a CALEA/NSA letter perspective, on the equipment manufacturer's side we are being pushed to develop encryption and key management solutions which take the burden of compliance off of the service provider.  

our customers ("tier 1" service providers and such) are working hard to get out themselves of the CALEA boondoggle. they are looking to sidestep the problem entirely by implementing end-to-end FIPS-certified encryption (AES256 on 10G/40G/100G/400G/++ optical spans) but moving the actual key management to the end client (e.g. banks, insurance companies, ISP's, cable companies, content providers, VoIP providers, etc). that is, the service provider does not have the encryption key to the span, and in fact can not retrieve it as the relevant FPGA and ASIC registers are write-only (but even if you could it's TTL is too short to be of practical value -- on a 100G span for example, a given rolling CBC or CTR key is only valid on the order of 10 minutes).

from both the service provider's and client's perspective, it's win/win -- the service provider can offer end to end logical transmission security (which is upcharged), the client doesn't have to take a throughput/latency hit at their border routers, and the client is protected against unknown eavesdropping/intercept threats. from a CALEA/NSA letter perspective, the service provider can only provide to LE/three letter agency the encrypted bitstream -- and you would need an eternity of computing cycles to turn that sausage back into a pig. most importantly, from a business perspective, the service provider does not have to lie to their clients.  you can do that maybe once with big clients -- major banks, brokerages, and the sort.  after that, they will find another service provider who will offer canary service.
Link Posted: 5/22/2015 7:04:14 PM EDT
[#35]
Discussion ForumsJump to Quoted PostQuote History
Quoted:


I'd like to hear your input on nation state threats.

I'm reasonable well connected into it, but not nearly as well as you.
View Quote View All Quotes
View All Quotes
Discussion ForumsJump to Quoted PostQuote History
Quoted:
Quoted:
I'm in, depending on when it is as I'm on the other side of the world.

Let me think about presenting, I'm open to doing it, just not sure what people want to know about.



I'd like to hear your input on nation state threats.

I'm reasonable well connected into it, but not nearly as well as you.


I could do that.
Link Posted: 5/22/2015 7:30:40 PM EDT
[#36]
Discussion ForumsJump to Quoted PostQuote History
Quoted:


whatever solution sells the most hardware, i'm for!  

ar-jedi

ps
maybe this is an interesting point...

from a CALEA/NSA letter perspective, on the equipment manufacturer's side we are being pushed to develop encryption and key management solutions which take the burden of compliance off of the service provider.  

our customers ("tier 1" service providers and such) are working hard to get out themselves of the CALEA boondoggle. they are looking to sidestep the problem entirely by implementing end-to-end FIPS-certified encryption (AES256 on 10G/40G/100G/400G/++ optical spans) but moving the actual key management to the end client (e.g. banks, insurance companies, ISP's, cable companies, content providers, VoIP providers, etc). that is, the service provider does not have the encryption key to the span, and in fact can not retrieve it as the relevant FGPA and ASIC registers are write-only (but even if you could it's TTL is too short to be of practical value -- on a 100G span for example, a given rolling CBC or CTR key is only valid on the order of 10 minutes).

from both the service provider's and client's perspective, it's win/win -- the service provider can offer end to end logical transmission security (which is upcharged), the client doesn't have to take a throughput/latency hit at their border routers, and the client is protected against unknown eavesdropping/intercept threats. from a CALEA/NSA letter perspective, the service provider can only provide to LE/three letter agency the encrypted bitstream -- and you would need an eternity of computing cycles to turn that sausage back into a pig. most importantly, from a business perspective, the service provider does not have to lie to their clients.  you can do that maybe once with big clients -- major banks, brokerages, and the sort.  after that, they will find another service provider who will offer canary service.
View Quote View All Quotes
View All Quotes
Discussion ForumsJump to Quoted PostQuote History
Quoted:
Quoted:
Quoted:

in.  not sure what sort of presentation would be interesting to folks , but i'm in.

ar-jedi

I know I'd find pretty much anything you had to say about Net Neutrality to be interesting and informative.


whatever solution sells the most hardware, i'm for!  

ar-jedi

ps
maybe this is an interesting point...

from a CALEA/NSA letter perspective, on the equipment manufacturer's side we are being pushed to develop encryption and key management solutions which take the burden of compliance off of the service provider.  

our customers ("tier 1" service providers and such) are working hard to get out themselves of the CALEA boondoggle. they are looking to sidestep the problem entirely by implementing end-to-end FIPS-certified encryption (AES256 on 10G/40G/100G/400G/++ optical spans) but moving the actual key management to the end client (e.g. banks, insurance companies, ISP's, cable companies, content providers, VoIP providers, etc). that is, the service provider does not have the encryption key to the span, and in fact can not retrieve it as the relevant FGPA and ASIC registers are write-only (but even if you could it's TTL is too short to be of practical value -- on a 100G span for example, a given rolling CBC or CTR key is only valid on the order of 10 minutes).

from both the service provider's and client's perspective, it's win/win -- the service provider can offer end to end logical transmission security (which is upcharged), the client doesn't have to take a throughput/latency hit at their border routers, and the client is protected against unknown eavesdropping/intercept threats. from a CALEA/NSA letter perspective, the service provider can only provide to LE/three letter agency the encrypted bitstream -- and you would need an eternity of computing cycles to turn that sausage back into a pig. most importantly, from a business perspective, the service provider does not have to lie to their clients.  you can do that maybe once with big clients -- major banks, brokerages, and the sort.  after that, they will find another service provider who will offer canary service.



Yes please talk on this and im sure i will have questions.  I designed and implemented a calea solution for a voip provider a few years ago.  It was voice only though - hi1/2/3 to verint who handled the leaf for us.  Ever since then ive wondered how the data side data works
Link Posted: 5/22/2015 7:34:38 PM EDT
[#37]
I'd be checking that out.  I like the idea but the implications and practical implementation gives me pause.  Is Cisco still pushing IPE via MPLS for things like superconnected grids?

Eh, off topic, my ADHD is kicking in.



Discussion ForumsJump to Quoted PostQuote History
Quoted:
IP everywhere.  does anyone want to know anything about how IP everywhere?  Should only take a minute or 2.  

actually, depending on when this is, I may be able to give a presentation on software defined networks using mininet.  apparently academia has some vision for this.  im already a huge gns3/dynamips homer, so I feel right at home with mininet, you can even script stuff with python in it.
View Quote

Link Posted: 5/22/2015 7:42:06 PM EDT
[#38]
Emphatically, me three, or four or whatever it is.

I am interested in the economic and market effects of the threat that nation states present.  I may not be a part of the national security puzzle but I have balance sheets, income statements, and shareholders to protect!  

I'm sort of being facetious but more and more I am finding this subject in forecasting, finance projections, and DR compliance and audit planning documents.  I'm behind the curve on the international aspect of IT security through my own fault.

The corporate community is worried and it's not all about Target-style breaches.  

Discussion ForumsJump to Quoted PostQuote History
Quoted:


I could do that.
View Quote View All Quotes
View All Quotes
Discussion ForumsJump to Quoted PostQuote History
Quoted:
Quoted:
Quoted:
I'm in, depending on when it is as I'm on the other side of the world.

Let me think about presenting, I'm open to doing it, just not sure what people want to know about.



I'd like to hear your input on nation state threats.

I'm reasonable well connected into it, but not nearly as well as you.


I could do that.

Link Posted: 5/22/2015 7:55:37 PM EDT
[#39]
So it looks like this thing is getting legit as fuck.  How about every one who wants to present, reply with the tentative title of your presentation and I'll update the ongoing list in the OP.
Link Posted: 5/22/2015 8:40:33 PM EDT
[#40]
I can provide insight into how the IT component of business is viewed and utilized from the ownership and C level/executive perspective.  Everything from strategic decision making, budgets, and staffing to aligning infrastructure, architecture, and development with the operations and profit model of the enterprise.  It's a huge subject with many variants.  I'd love it if people had specific questions or topics they want to know about.
Link Posted: 5/22/2015 8:51:16 PM EDT
[#41]
I guess I could give a two hour PowerPoint on MAC addresses, and why they are the AK-47s of the internets.
Link Posted: 5/22/2015 9:04:35 PM EDT
[#42]
Discussion ForumsJump to Quoted PostQuote History
Quoted:
I guess I could give a two hour PowerPoint on MAC addresses, and why they are the AK-47s of the internets.
View Quote


I would love to see a short presentation from you on the perspective of the IT guy just starting out.
Link Posted: 5/22/2015 9:05:59 PM EDT
[#43]
Link Posted: 5/22/2015 9:06:37 PM EDT
[#44]
My perspective has been temporarily warped by the last two days, but if anyone working for FedEx wants to step in and soothe my burns I suppose I could pull something off.
Link Posted: 5/22/2015 9:10:30 PM EDT
[#45]

Discussion ForumsJump to Quoted PostQuote History
Quoted:
I could do that.
View Quote View All Quotes
View All Quotes
Discussion ForumsJump to Quoted PostQuote History
Quoted:



Quoted:


Quoted:

I'm in, depending on when it is as I'm on the other side of the world.



Let me think about presenting, I'm open to doing it, just not sure what people want to know about.







I'd like to hear your input on nation state threats.



I'm reasonable well connected into it, but not nearly as well as you.




I could do that.




 
Bit tricky keeping it unclass.
Link Posted: 5/22/2015 9:10:38 PM EDT
[#46]
Discussion ForumsJump to Quoted PostQuote History
Quoted:


I would love to hear something on software defined networks!
View Quote View All Quotes
View All Quotes
Discussion ForumsJump to Quoted PostQuote History
Quoted:
Quoted:
IP everywhere.  does anyone want to know anything about how IP everywhere?  Should only take a minute or 2.  

actually, depending on when this is, I may be able to give a presentation on software defined networks using mininet.  apparently academia has some vision for this.  im already a huge gns3/dynamips homer, so I feel right at home with mininet, you can even script stuff with python in it.


I would love to hear something on software defined networks!

Wonder if we have any NSX guys here?
Link Posted: 5/22/2015 9:12:55 PM EDT
[#47]

Discussion ForumsJump to Quoted PostQuote History
Quoted:
As long as you cover the filtering.



That's the Holy Grail
View Quote View All Quotes
View All Quotes
Discussion ForumsJump to Quoted PostQuote History
Quoted:



Quoted:

I guess I could give a two hour PowerPoint on MAC addresses, and why they are the AK-47s of the internets.




As long as you cover the filtering.



That's the Holy Grail




 


Link Posted: 5/22/2015 9:13:23 PM EDT
[#48]

Discussion ForumsJump to Quoted PostQuote History
Quoted:
whatever solution sells the most hardware, i'm for!  



ar-jedi



ps

maybe this is an interesting point...



from a CALEA/NSA letter perspective, on the equipment manufacturer's side we are being pushed to develop encryption and key management solutions which take the burden of compliance off of the service provider.  



our customers ("tier 1" service providers and such) are working hard to get out themselves of the CALEA boondoggle. they are looking to sidestep the problem entirely by implementing end-to-end FIPS-certified encryption (AES256 on 10G/40G/100G/400G/++ optical spans) but moving the actual key management to the end client (e.g. banks, insurance companies, ISP's, cable companies, content providers, VoIP providers, etc). that is, the service provider does not have the encryption key to the span, and in fact can not retrieve it as the relevant FGPA and ASIC registers are write-only (but even if you could it's TTL is too short to be of practical value -- on a 100G span for example, a given rolling CBC or CTR key is only valid on the order of 10 minutes).



from both the service provider's and client's perspective, it's win/win -- the service provider can offer end to end logical transmission security (which is upcharged), the client doesn't have to take a throughput/latency hit at their border routers, and the client is protected against unknown eavesdropping/intercept threats. from a CALEA/NSA letter perspective, the service provider can only provide to LE/three letter agency the encrypted bitstream -- and you would need an eternity of computing cycles to turn that sausage back into a pig. most importantly, from a business perspective, the service provider does not have to lie to their clients.  you can do that maybe once with big clients -- major banks, brokerages, and the sort.  after that, they will find another service provider who will offer canary service.

View Quote View All Quotes
View All Quotes
Discussion ForumsJump to Quoted PostQuote History
Quoted:



Quoted:


Quoted:



in.  not sure what sort of presentation would be interesting to folks , but i'm in.



ar-jedi



I know I'd find pretty much anything you had to say about Net Neutrality to be interesting and informative.




whatever solution sells the most hardware, i'm for!  



ar-jedi



ps

maybe this is an interesting point...



from a CALEA/NSA letter perspective, on the equipment manufacturer's side we are being pushed to develop encryption and key management solutions which take the burden of compliance off of the service provider.  



our customers ("tier 1" service providers and such) are working hard to get out themselves of the CALEA boondoggle. they are looking to sidestep the problem entirely by implementing end-to-end FIPS-certified encryption (AES256 on 10G/40G/100G/400G/++ optical spans) but moving the actual key management to the end client (e.g. banks, insurance companies, ISP's, cable companies, content providers, VoIP providers, etc). that is, the service provider does not have the encryption key to the span, and in fact can not retrieve it as the relevant FGPA and ASIC registers are write-only (but even if you could it's TTL is too short to be of practical value -- on a 100G span for example, a given rolling CBC or CTR key is only valid on the order of 10 minutes).



from both the service provider's and client's perspective, it's win/win -- the service provider can offer end to end logical transmission security (which is upcharged), the client doesn't have to take a throughput/latency hit at their border routers, and the client is protected against unknown eavesdropping/intercept threats. from a CALEA/NSA letter perspective, the service provider can only provide to LE/three letter agency the encrypted bitstream -- and you would need an eternity of computing cycles to turn that sausage back into a pig. most importantly, from a business perspective, the service provider does not have to lie to their clients.  you can do that maybe once with big clients -- major banks, brokerages, and the sort.  after that, they will find another service provider who will offer canary service.

Ayup, I'm pretty much in the shortbus when it comes to this crowd, I am already lost. Consider the sidecar my home and call it the shortbus.



 
Link Posted: 5/22/2015 9:30:00 PM EDT
[#49]
Discussion ForumsJump to Quoted PostQuote History
Quoted:

  Bit tricky keeping it unclass.
View Quote View All Quotes
View All Quotes
Discussion ForumsJump to Quoted PostQuote History
Quoted:
Quoted:
Quoted:
Quoted:
I'm in, depending on when it is as I'm on the other side of the world.

Let me think about presenting, I'm open to doing it, just not sure what people want to know about.



I'd like to hear your input on nation state threats.

I'm reasonable well connected into it, but not nearly as well as you.


I could do that.

  Bit tricky keeping it unclass.


That was my first instinct...  then I thought, "Oh I can do it all open source"...  

Then I started thinking ppr...  I'm debating.

Link Posted: 5/22/2015 10:06:16 PM EDT
[#50]
So gents, here's a onedrive doc that you can edit.  Feel free to insert comments, or brush up your descriptions and what not.  I'll add this to the OP as well.

http://1drv.ms/1elIvpt
Arrow Left Previous Page
Page / 4
Close Join Our Mail List to Stay Up To Date! Win a FREE Membership!

Sign up for the ARFCOM weekly newsletter and be entered to win a free ARFCOM membership. One new winner* is announced every week!

You will receive an email every Friday morning featuring the latest chatter from the hottest topics, breaking news surrounding legislation, as well as exclusive deals only available to ARFCOM email subscribers.


By signing up you agree to our User Agreement. *Must have a registered ARFCOM account to win.
Top Top