Announcing Uncommon Criteria
While there is a desperate need for creative ideas or inventions in the general area of information risk and security controls, specifically for defensive purposes, the implementation phase of innovation is also in need of creativity and care.
Information security products (both goods and services) that are inherently insecure are not uncommon, unfortunately. Aside from simple bugs, implementation issues, incompetence and ineptitude, we occasionally see evidence of fundamental security flaws in the designs, while rumours of backdoors being deliberately inserted by the authorities persist (partly a reflection of justifiable distrust in Big Brother).
Given the trusted nature of their products, social engineering, insider threats and subterfuge are likely to occur in organizations that produce security products .... so we also need innovation in the area of security assessment and certification of security products, as well as various internal security controls.
In government and military circles, schemes such as Common Criteria improve product assurance but are unbelievably costly. A more affordable version of CC for the general commercial and personal markets would be cool ... so today I am delighted to announce UC (Uncommon Criteria), a brand new cut-price assessment scheme for security innovations.
Simply send me your idea to evaluate, along with US$10 via PayPal. I'll take a quick look at your suggestion and let you know what I think of it.
To keep costs down, and in light of my IT audit expertise, I'll respond with a simple numeric code as follows:
- Already in production
- Already on the market
- Already broken
- Already withdrawn as a dead loss
- Already superceded
- Been there done that
- Been tried a million times already
- Bends the rules
- Breaks the law
- Breaks the laws of physics
- Commercially-challenged
- Clumsy
- Crude
- Costly
- Cheesy
- Details missing
- Details excessive
- Details hid the devil
- Ethically-challenged
- Environmentally unsound
- Fantastic, call me, let's talk!
- Flammable
- Go find another hobby
- Grrrrr
- Hackers' delight
- Have you checked the patent databases?
- Impractical
- Impracticable
- Inflammable
- Inherently flawed
- Inherently insecure
- Intellectually-challenged
- Interesting, special even
- Joking, right?
- JAiT (Just Another insecure Thing)
- Killer idea, literally: step away from the keyboard
- Lewd
- Likely to plummet like a lead brick
- Makes no sense
- Makes me wonder what you are on
- Makes Bill Gates look like a security evangelist
- Life, the universe and EVERYTHiNG
- Needs more work
- Need more coffee
- Not new: have you even Googled it yet?
- Now I know this, you'll probably have to shoot me
- Now you know I know, I know
- Over-simplified
- Overly-complex
- Over-ambitious
- Peturbing
- Practically infeasible
- Risky as a Chinese bungy cord (the jump off a cliff kind)
- Shows promise
- Shows signs of having been backdoored (painful!)
- Shows total disregard for the field
- Terrible
- Terrifying
- Terminal
- Trust me, this is the rottenest thing since Edward the Rotter of Rotterdam
- Trust me I'm a doctor
- Trust me I'm an infosec pro
- Trust me, just trust me OK?
- Unattractive
- Unable to evaluate
- Unwilling to evaluate
- Unbelievable
- Unbelievably naive
- Unethical
- Unimaginable
- Unimpressed
- Unconscionable
- Unlikely to be fundable
- Unworkable
- Very very very over-blown: are you in marketing?
- Won't fly
- Wouldn't even glide
- Worst thing since sliced bread
- X marks the spot
- You should be ashamed, ashamed I say
- Zero points, computer says "no"