Slashdot Mirror


User: johnharrisyankee

johnharrisyankee's activity in the archive.

Stories
0
Comments
22
First seen
Last seen
Profile
(view on slashdot.org)

Comments · 22

  1. Re:Plug for Rob Hanson on GWT in Action · · Score: 1

    Well, this is a plug for rob hanson's friend.... who i know not,
    but I agree with him :)

  2. Re:Wow on GWT in Action · · Score: 1

    i second that vote mate!

  3. Re:It is too complex! on PCI Compliance · · Score: 1

    >>I am not qualified to do an external audit

    So why not get the QSA cert. from the pci council?

  4. Re:Costly... on PCI Compliance · · Score: 1

    >>>Every time they do a scan you get charged and no matter what you do there will be false positives so it's almost always a 2 scan process.

    Negotiate, Negotiate, Negotiate. Yes, it can be expensive, but you can negotiate and quickly lower the price.

  5. Re:Useful book on PCI Compliance · · Score: 1

    sorrrrrry, i haaaave an ollllld keyboard and it stickzzzzzzzzzzzzzzzzz :))))))))))))))))))))))

  6. Re:Costly... on PCI Compliance · · Score: 1

    How can that be? My company spends $25k per year on Gartner research and they told us that the IDS is dead.

  7. Re:I read it, I'd give it 3 1/2 stars on Network Warrior · · Score: 1

    Yes, I will read it there and not buy it.

  8. Re:It is too complex! on PCI Compliance · · Score: 1

    Kerberos is awesome, cept that it requires every app to be rewrittern.
    How else would you implement the tickets?

  9. Re:It is too complex! on PCI Compliance · · Score: 1

    Many vendors, especially around logging and encryption are hawking their wares around PCI. They have data sheets on how to make their products around PCI.

    In fact, a lot of the data sheets have good info.

  10. Re:Maybe they do know. on PCI Compliance · · Score: 1

    I still don't see what the supposed flaw is.

  11. Re:I read it, I'd give it 3 1/2 stars on Network Warrior · · Score: 1

    thanks. i know not to read the book now.

    Do you have a web site with all your reviews?

  12. Re:Maybe they do know. on PCI Compliance · · Score: 1

    >>>>Whoever drew up the questionnaire is not competent. From the document:

    What??? Whoever drew up the questionnaire really knows what they are talking about.

    >>> 5.1 Deploy anti-virus software on all systems commonly affected by viruses (particularly personal computers and servers) Note: Systems commonly affected by viruses typically do not include UNIX-based operating systems or mainframes.

    What that means is AV only on Microsoft products. I can be pci compliant and not need AV on my Cray, AIX, HP/UX systems.

    >>> but unless the questionnaire makes a distinction regarding ssytems "commonly affected by viruses" then it is not compliant with the original requirements.

    What do you mean?

  13. Re:Just like HIPAA or Sarbanes-Oxley... on PCI Compliance · · Score: 1

    What????? The TJMAXX hack occurred under a year ago.

    PCI is a few years old. In fact, had TJMAXX been PCI compliant, they would never have had a breech.

  14. Re:Useful book on PCI Compliance · · Score: 1

    Really???? Name two mistakes you found in the glossary!!!!!!!!

  15. Re:Just like HIPAA or Sarbanes-Oxley... on PCI Compliance · · Score: 1

    >>>>..PCI is an excuse to hire the KPMGs, Accentures and EDSs of the world. They will charge you $xM for "experts" to put in controls and make your systems secure.

    Well.... If the merchants would have been smart enough to do a basic level of security in the first place, they would not have to spend such $$$$. In fact, this is a good fine and penalty for them since they were derelict in their duties in the first place.

    >>>>All the while, only a few percent of your card transactions are fraudulent.

    But one hacking breech makes ALL of the card holder data info vulnerable.

  16. Re:It is too complex! on PCI Compliance · · Score: 1

    If PCI is too complex, then security is too complex.
    And if security is too complex for them.... take away their business license.
    If you can't comply with PCI, then as a vendor are not grown up enough to accept credit cards.

  17. Re:OT, I know, but... on PCI Compliance · · Score: 1

    You missed the point, this has nothing to do with mil spec.
    It is about poorly made products. I know Gillette can make a razor that lasts much longer, but then again, I would buy less, and they would make less.
    And talk about Duracell batteries, of course they could last much much much longer, but then again, people would buy less of them.

  18. Re:What value DO the entry level certs have? on Network Warrior · · Score: 1

    should make that 'fat clueless' folks in HR.

  19. Re:I read it, I'd give it 3 1/2 stars on Network Warrior · · Score: 1

    >>>>>Also, i picked up Zen and the art of security as well and it too would get a 3 1/2 star rating from me.

    Ouch!

    >>>Nothing too great, nothing real bad... except the author seems a little stuck on himself and a bit of a dickwad.

    Dude, write a book review. Why so bad? Stuck on himself?????

  20. Re:I read it, I'd give it 3 1/2 stars on Network Warrior · · Score: 1

    >>>>>Also, i picked up Zen and the art of security as well and it too would get a 3 1/2 star rating from me.
    Ouch!

    >>>Nothing too great, nothing real bad... except the author seems a little stuck on himself and a bit of a dickwad.

    Dude, write a book review. Why so bad? Stuck on himself?????

  21. Re:Not accurate on Network Warrior · · Score: 1

    True. But I think the difference is that everyone I know that went for the CCNA certification, planned/plans to also go for CCNP.

  22. Re:What's with the militant terminology? on Network Warrior · · Score: 1

    Ninja sounds better than Network CPA :)