« The future of Vulnerability Management | Main | A good follow up on vulnerability management »

October 13, 2006

Toto, you are not in Kansas anymore

Seems Greg Toto, VP of Product Management at Big Fix, took a little offense to my comments regarding patch management and Big Fix. I would normally leave his comment condemned to right hand column purgatory, but Greg obviously feels pretty strongly about his position and frankly I think he is dead wrong.  So I am going to publish his comments into the middle column along with my response.  Of course, I will give Greg a chance to respond as well.  You should also know that I have spoken to Greg a few times in the past and though he is passionate about his product, I have nothing personal against him.  However, Pride is one of the 7 deadly sins.  Interestingly enough it was St. Gregory the Great who originally introduced the 7 deadly sins and he lists Pride as the first and most deadly.  It would appear Greg has not read his namesakes work and is certainly guilty here.  Lets look at what he has to say:

Alan,

Nice piece about patch management consolidation. I think you
addressed the inaccuracies in the SearchSecurity article well. However,
I think you missed the mark on a couple of things.

One is that scanning based vulnerability assessment vendors have any
long-term future at all – with or without remediation. I think they are
fundamentally doomed. Sorry, but the laws of physics are against the
network-scan paradigm. You cannot expect to control something (risk
profile, configuration, compliance, whatever), any more tightly that
half as fast as you measure it, and that assumes you can make your
measurements – vulnerability scans for example – accurately and
completely. Accuracy and comprehensiveness (can we say “mobile
assets”), are not hall-marks of scan-based VA.

Now on to BigFix. You mention that we have “tried to position”
ourselves as “so much more” that patching and may be left out of this
“feeding frenzy”. Oh Alan, how much you miss! You have confused our
point of entry into the enterprise market (patch management), with what
BigFix is - a disruptive platform for managing the health and security
of enterprise computing assets – anytime, anywhere – in real-time. And
note, I didn’t say “Windows assets”, I said “computing assets” - these
days every asset that connects to your network is part of your risk
equation and ultimately your management headache.

Nor is BigFix overly concerned about being acquired. We have the
right technology and team to upset the systems management apple-cart in
large enterprise (and I include security in that cart as well). But
don’t believe me, just ask BigFix’s global enterprise customers that
are now replacing SMS, and Tivoli, and Radia, and Altiris, and McAfee -
and their gaggle of point tools – like PatchLink - with a BigFix’s
security configuration management solution that covers network
discovery, inventory, software distribution, anti-malware, and yes,
patch! Like TRW Automotive, Pitney Bowes, Countrywide Financial and 500
more.

Regards,

Greg

OK, lets dig in here.  First of all to Greg's point about scanning based vulnerability assessment having a bleak future.  Greg's reasoning is that they are fundamentally doomed due to the laws of physics.  Greg sites what I guess is the Toto Law of Special Relativity, that says you cannot control something, any more tightly that (sic) half as fast as you measure it.  I assume he means any more tightly than half as fast.  In any event, I remember taking some physics in school.  I do remember some physics theories by a guy named Einstein and some laws by Newton, but I don't remember any by Greg Toto and I don't remember any law of physics anything like he is talking about.  Now maybe I was out in the Rathskeller that day drinking beers and missed it, but I doubt it.  So Greg I have to call BS on your laws of physics.  Next, what difference does it make anyway.  Are you telling me that your law would only apply to vulnerability scans but somehow host based assessments would be immune from this law of physics?  Are your host based assessments not subject to the laws of physics or do the laws of physics cease to function when applied to Big Fix.  Somehow, Greg says, that because I have an agent on a machine, the information I will receive from the assessment it does is of a higher accuracy, faster and more comprehensive than a network based scan.  Greg, maybe you should go to talk to Richard Stiennon and let him tell you about how you cannot believe an endpoint to honestly report on itself.  You probably need both views at certain times to truly deal with this problem.

House Then Greg you point out that network based scans might have a problem with "mobile assets".  Glad you brought it up.  Yes if the device is not on the network at that time, it cannot be scanned.  Let me throw one out at you, can we say "unmanaged mobile assets".  Yeah Greg, what do you do when you can't put your software on the device to test it.  Don't start rambling about your partnerships with Infoblox and such who can put it in quarantine.  That is diminishing productivity.  Greg, you can jump up and down and rant all you want.  Fact is that putting agents on every single device is never a complete answer in todays dynamic environments. You are going to have devices that you cannot install software on and then what do you do? On top of this, last I looked there was not a very big fan club of putting yet another agent on machines to manage.  Frankly I don't care if you have agents for Windows, Mac, Linux, OS/2 or the microwave oven for that matter.  The more agents, the more overhead!

I think any rational security expert without an ax to grind or a product to sell, will tell you that you need both host-based and network based security in place.  You need to make sure you are getting an independent view of what is coming on the network and what its posture is.  In fact much of today's security technologies  come down to network based and host based approaches.  Though our products are clearly network based, I am not too proud to say that they are all you need. There is certainly a need for host based security. But Greg don't be so prideful to think that the reverse is not also true. I find it hard to believe you would not agree with that Greg. 

Next Greg takes out the marketing hose and starts spraying Big Fix marketing hype all around.  So lets put our boots on and wade on in.  It seems Big Fix can do it all.  Greg I think you left out access control, I know you claim to do that as well.  In fact Greg, Big Fix does so many things it is sort of the Popeil Kitchen Magician of security configuration.  Maybe you can get Ron Popeil to put you guys on after the Showtime BBQ rotisserie.  It could be a new distribution channel for you.  Remember the old saying though, jack of all trades, master of none! 

Are we to believe that Big Fix is so disruptive that Microsoft should stop selling SMS, IBM better not bother with Tivoli and HP should just junk Radia, not to mention Altiris, McAfee and the rest.  Please Greg, like the title of this article says, you are not in Kansas anymore son.  Don't come out here spewing marketing spin and expect to score any points or fans. When you are taking on companies like this, you are playing in the big leagues and a little humility may do you some good. These are all companies with exponentially more resources, experience, sales footprint and distribution models than Big Fix.  You tell us about a few customers, last time I checked Tivoli and SMS had a few customers too.  Greg, your pride is showing through and blinding you to common sense. But lets be real, at the end of the day you are not in their league fella.  Big Fix's bread and butter is still patch.  When you get big enough to become a blip on the big boys radar they will swat you like a fly.  At that point I suggest you put on the ruby slippers, click your heels three times and wish you were just a patch manager again. It may be to late.


TrackBack

TrackBack URL for this entry:
http://www.typepad.com/services/trackback/6a00d83451e4d369e200d834f1660869e2

Listed below are links to weblogs that reference Toto, you are not in Kansas anymore:

Comments

My Photo

Subscribe to my blog

Enter your email address:

Delivered by FeedBurner

Lijit Search

Blog Networks

Creative Commons License
This work is licensed under a Creative Commons Attribution-Share Alike 2.5 License.

Search

Lijit Search

Attend a Computer Forensics Boot Camp to better your skills and become a better worker
Blog powered by TypePad
Member since 10/2005