Subscribe to

Blogs

Harrah's signs 10-year agreement with Cisco

 - 
Tuesday, May 20, 2008

I spoke with Cisco yesterday about their big news — a 10-year strategic agreement with Harrah's Operating Co. As you may well know, Harrah's is the largest provider of branded casino entertainment (its flagship is Caesar's Palace in Vegas. Also, one of the favorite places to shop in Sin City.)

I talked with Steve Collen, director of business development for Cisco's physical security business unit, and he said it is quite unusual to see a long-term agreement like this, even in the halls of Cisco.
The company will be providing Harrah's with and IT infrastructure to support digital signage capabilities and its very cool Telepresence system. I had the opportunity to use the solution when I visited Cisco's headquarters last year and it is really like being in a room with the person who is on the video screen.
In addition, 31 Harrah's properties will be migrating over to digital security and surveillance products from Cisco. The hope is that this project will expand to Harrah's approximately 50 casino locations.

Check out this presentation about the project.

Leave the standards to the SDOs or collaborate independently?

 - 
Thursday, May 15, 2008

This week began with an announcement from three manufacturers of a new cooperative effort to start a communications forum and develop an interoperability standard. I felt like the Jeff Goldblum character from the great "The Right Stuff" movie that would run down the hall to report on the latest activities by the Russians in space, only to hear "we know about it already."

It may have appeared that another group was doing an "end run" around the Standards Development Organization (the SIA) that has developed the only ANSI-approved interoperability standard for the Security Industry. The interesting thing is that this week's actions may have plans for working together with the impartial SDOs and Credentialing organizations. They are, after all in the best position to recognize, organize, focus and manage manpower to achieve realistic interoperability goals.

I completely understand how interoperability efforts are quite useful and will greatly benefit everyone in the Security Industry "food chain." When an effort exists, why not contribute to it and improve it rather than create another, duplicated, parallel effort.

Last year I had the benefit of meeting a particular end user that taught me something quite insightful. "Think of my customer as your customer."

Wow!

If I can help my customer improve their customer's experience, or contribute to savings for his (or her) organization that could mean savings passed onto their clients, we all win.

What does this have to do with a parallel standards efforts?

Simply put, it is industry resources not applied toward better helping the (hopeful) benefactors of this industry. If we took the time spent on multiple device and system interface efforts and applied those efforts to introduce more useful applications for the end user, we all win.

So where do we go now? What can we do to improve this situation?

Ask the SDO. They have a method in place for recognition of standards development activities and a way for these efforts to focused correctly and impartially.

Tags: 

A tale of a city

 - 
Thursday, May 15, 2008

I wrote about the city of Richmond's video surveillance project in the city and at its port a few months back but seeing the city in person definitely added another layer. Richmond is a town that struggles with crime — copper theft and illegal dumping to name two. This city, near San Francisco, Oakland and Berkeley, is quite different than its famous neighbors. While I feel relatively safe at Golden Gate Park, for example, I did not have the same reaction when standing in downtown Richmond yesterday. But the good news is that city officials want to make this a safer area and are in the midst of setting up a CCTV system (installed by ADT who is sponsoring my trip here) to augment police presence.
It is difficult to measure the success of a system by looking up at a camera installed on a light pole but who is to say what the success of the system is. Is it the 20 percent reduction in crime the city has reported since the installation began? Is is that residents feel safer? Officials said they are still trying to figure this out.
Sir Chris Fox, former president of the Association of Chief Police Officers in the U.K. who was a chief constable for 10 years, said in his presentation at the ADT event said determining how success is defined is key. Officials — both security and city officials — need to know what they want and how they know when they've reached it when deciding to deploy a municipal video system.
But is is also vital, he said, to determine whether "camera technology what I need? Sometimes it isn't."
"The U.K. has hundreds of (CCTV) systems. Some of them are awful. The good systems are fantastically effective" and when presenting cases to a judge "you can't beat a good old fashioned picture of what happened."
(I was going to post photos of the area but I seem to be having some technical difficulties with the blog.)

San Francisco treat

 - 
Wednesday, May 14, 2008

I'm in the Bay area this week for a media junket put on by ADT and today will have the opportunity to tour the wireless video surveillance project that is currently in the works at the city of Richmond, Calif., and the Port of Richmond. I'll have details and photos of the installation for you tomorrow.

I had the chance to chat with the event's closing speaker last night. Sir Chris Fox (yes, he's been knighted by Prince Charles but prefers to be called Chris) is a 34-year veteran of British law enforcement and played an integral part on the coordination of police operations after the July 2005 London Underground bombings. On Thursday morning, Chris will provide an overview of the public surveillance market: what's good, what's bad, what works and what doesn't both in the U.K. and here in the U.S. I'm looking forward to hearing his perspective. It's no secret that there is some confusion here about how, when and where video should be used.

Something new

 - 
Monday, May 12, 2008

We have a new blog here on our site — Industry View. It's part of my pet project (although some of my colleagues think it is an obsession) to continually improve the content and look of our web site.

This forum is a place for industry professionals — everyone from security directors to manufacturers — to post thoughts and ideas about the most important issues facing our industry today. I'll also contribute, mostly to post contributed articles that have not been published in our printed edition. But this forum is really for all of you. If you are interested in becoming a contributor, e-mail editor@securitydirectornews.com for more information.

Welcome to the world

 - 
Thursday, May 8, 2008
I was out of pocket today because my sister had her second child at 1:54 pm (or something close to that) this very day. I'm happy to report that happy, cute and healthy Bailey Anne joined her older sister, Camden Elizabeth, in my sister's ever-growing family that I am happy to be a part of.
But as I was sitting in the hospital, I noticed a few things that made me very happy to be part of the security industry (even as an outside-looking-in journalist, if I may.) First, every time a nurse made a note into my sister's computer record a message would come up when she walked away that said something along the lines of "confidentiality and security are our priorities." Also, when Bailey was given her first bath the nurse's aide took the time to check my sister's bracelet with Bailey's to make sure the two belonged together.
This are two simple things, but I think it shows that "security" can be as simple as two people paying attention to detail.

The 'official' ISC round-up

 - 
Wednesday, May 7, 2008
As promised, here are the rest of my adventures in Vegas.

*Proximex Surveillint 3.0 won the New Product Showcase in the convergence category. I spent time chatting with Al Liebel and Diane M.Z. Robinette about the company and the product. What I like best is that it guides security personnel through your company's policies if there is a situation that needs extra attention. Al said the command-and-control software takes "people out of the process as much as possible." In my opinion, I think it empowers employees to make decisions by providing them with the data they need to effectively do their jobs.

*I caught up with two ex-Cisco workers. Bob Beliles, now vice president of Enterprise Business Development for Hirsch Electronics, said the company will be taking a more aggressive stance in the market and noted that identity initiatives — FIPS 201, HSPD-12 — will have a trickle down effect, driving business in the corporate space.
I caught up with Mark Kolar, who with Beliles was integral in building Cisco's physical security business, over at his new company Agent Vi, where he serves at vice president of Channel Programs for the Americas. Kolar's enthusiasm regarding Agent's edge analytics is infectious. He and Rob Hile, vice president of business development for integration partner Adesta, told me about Agent's new "3-for-free" promo, which allows businesses to deploy any three of the company's analytics applications through it or its channel partners on up to three IP cameras for as long as 90 days. After the trial, companies that order more Agent Vi analytics for at least 10 cameras can keep the initial three free to change for the duration of the license. Pretty cool, huh?

*Ionit Technologies announced that it has completed the installation of its DVRs at 6,200 Walgreens facilities and distribution centers nationwide. Jim Talbot, CEO and founder of Ionit, said this is "a lot more than a DVR." Rather, it is a data collection system. I'm also hoping to catch up with Ken Amos, director of loss prevention for Walgreen's, this week.

*I sat down with Steve Walin, chairman and CEO at GVI Security/Samsung Electronics, and he was happy to report that the company is back in the black after some dismal financial and industry results. Now, GVI has experienced four quarters of profitability and Walin said that signifies a financial turnaround. GVI also launched its first line of IP products and annouced a line of $1.5 million in funding from Samsung to increase its market share. The goal is to "double our market share in three years," he said. It is currently marked at 2 percent in the Americas.

*As for the nightlife, it was plentiful as always. GE Security held a pretty neat party at Tao in the Venetian, so did Dedicated Micros the evening before. ADI held its annual customer bash at the House of Blues at Mandalay Bay with a band that played some cool Pink Floyd covers. Pelco had its party on Thursday night as well, but as with prior years I was left without a ticket. I did hear it was a good time from Pelco's CEO Dean Meyers — with two remaining members of Creedence Clearwater Revival taking the stage. As with any event in Vegas, these things are tough to get into. I found myself waiting behind a velvet rope and a bouncer to get in at a majority of them because they hit capacity early.

The case for a Cooperative Certification Program

 - 
Tuesday, May 6, 2008

Whether you are a self-commissioning end user, a multi-site integrator or a smaller reseller, your time is important and needs to be spent on what keeps your business going. Why would our industry require multiple certifications on different products that are similar and share a basic skillset for deployment?

Each manufacturer would like the opportunity to tell their story in front of these key influencers, and then train on the nuances of product deployment and adjustment. I'm thinking that on one hand manufacturers might find the comparison less fruitful, but on the other there's an opportunity to meet end users and resellers they would not have.

Why end users? There are a number of multi-site, large end users that will always use integrators for product purchase and commissioning, but need an understanding of the system deployment for planning, design and maintenance.

Stayed tuned; we may just be making history on this, yet!

Tags: 

The assistant vs. the security director

 - 
Tuesday, May 6, 2008
Dutchess County is located in the "heart of the New York Hudson River Valley," according to its tourism web site. Here's more:

Nestled in the Hudson River Valley, 90 minutes from New York City, it is accessible by car, train, bus and air. With its abundance of historic landmarks, restaurants, festivals and natural scenic beauty, Dutchess County is the ideal place for day trips or longer getaways. It's 800 square miles of fascinating sites, lively events and breathtaking vistas. Explore Dutchess for any reason in any season.

But things aren't so idyllic in the county government offices these days. The county doesn't think it should employ a security director and eliminated the position from its 2008 budget. But someone forgot to inform the county executive about the change (or maybe he conveniently forgot?) and the county is still shelling out $79,700 for the role.

The county says that the 2008 financial outlook is dim, even though it ended 2007 with a $8.1 million surplus.

Basically, the county needs to pay for the salary of the assistant to the chairman and there's some sort of hiring freeze in place.

Hmmm ... Assistant or security director? For me the choice would be simple, but I guess "assistant" outweighs "security director" in this neck of the woods.

I'd love to see these guys battle it out.

Wifi - Wardriving and the fleecing of the traveler or randonneur

 - 
Saturday, May 3, 2008

disclaimer: This article is for informational and educational purposes only. Hacking into a private security-enabled wireless network is illegal and is not the intent of this article.

Like sheep we are drawn to them. They are everywhere, in pockets and often located right at another addiction's distribution point, the coffee house. The WiFi hotspot is not a hotspot at all for connectivity, but for someone else's money.

When I fly into Vegas, I can feel the extra $$$ already leaving me as I know it will cost $15 per day at the hotel, and $40 at the convention center for three hours, and without adequate credit card transaction security.

In fact, the last trip to Vegas found my CC taken on one of those networks (I had a company firewall in place), and the rogue user began to selectively siphon $500 at a time from my account.

I drive or bike a good deal to my local destinations, so I'm not shy about getting on someone's unsecured network, doing what I have to and leaving. That is, if I haven't found a T-Mobile hotspot that I already pay for.

When in New York City, or a major city, there are times I am restricted to where the car, or a comfortable spot and PC can be, so sometimes I have to resort to looking at the person's router if its response is very slow.

Most people leave not only the default IP address and transmission unsecured, but also the router's password. A simple lookup and I find not less that 30 blackberrys consuming this network, and three PCs. I'm only going to be about 5 minutes, so I log on to the router, knock off the Blackberrys, keeping the users PC online, change the password on the router (I'll be changing that back before I leave), and limit the number of DHCP clients to 50.

I log off. I send my email and upload some large files and I'm almost out of there. I re-enter the router's admin app. and restore their settings, leaving the DHCP limit to 50, just in case they get another 30 visitors to crash their network.

Ethical or non-ethical? However you feel about the above, I can assure you that right now there could be predatory "klingons" on your Wifi network at home, especially if you have not:
1. stopped broadcasting your SSID
2. changed your default router password and applied WEP or better, WPA2
3. limited the number of DHCP users
4. upgraded your firmware
5. filtered your MACs

Hey, we take some and we give; please feel free to pass along this advice and the very good reference below to your neighbor.

That is, after you've downloaded Madonna's latest CD...

From The Ethical Hacker:

Just as it’s important to know how to utilize the aforementioned tools, it is important to know best practices on how to secure your Wireless Network Against these tools.

NetStumbler – Do not broadcast your SSID. Ensure your WLAN is protected by using advanced Authentication and Encryption.

Kismet – There’s really nothing you can do to stop Kismet from finding your WLAN, so ensure your WLAN is protected by using advanced Authentication and Encryption

Airsnort – Use a 128-bit, not a 40-bit WEP encryption key. This would take longer to crack. If your equipment supports it, use WPA or WPA2 instead of WEP (may require firmware or software update).

Cowpatty – Use a long and complex WPA Pre-Shared Key. This type of key would have less of a chance of residing in a dictionary file that would be used to try and guess your key and/or would take longer. If in a corporate scenario, don’t use WPA with Pre-Shared Key, use a good EAP type to protect the authentication and limit the amount of incorrect guesses that would take place before the account is locked-out. If using certificate-like functionality, it could also validate the remote system trying to gain access to the WLAN and not allow a rogue system access.

ASLeap – Use long and complex credentials, or better yet, switch to EAP-FAST or a different EAP type.

Ethereal – Use encryption, so that anything sniffed would be difficult or nearly impossible to break. WPA2, which uses AES, is essentially unrealistic to break by a normal hacker. Even WEP will encrypt the data. When in a Public Wireless Hotspot (which generally do not offer encryption), use application layer encryption, like Simplite to encrypt your IM sessions, or use SSL. For corporate users, use IPSec VPN with split-tunneling disabled. This will force all traffic leaving the machine through an encrypted tunnel that would be encrypted with DES, 3DES or AES.
courtesy to Daniel V. Hoffman, CISSP, CWNA

http://www.ethicalhacker.net/content/view/16/24/

BTW, there's one gentleman who is an ASIS Vice President who does a great job with a "wardriving" and prevention class. Should anyone be interested in him presenting at a conference or consulting on this subject, feel free to ask me for his contact information.

Pages