Category Archives: Technology

Technological Damnation 92: Data Loss

It is the information age and data is the life blood of the company and the supply chain. The financial chain is controlled by data. The physical flow of goods is dictated by data. People communicate electronically through data packets. It’s all data. And losing that data is a damnation. Not just because data is lost, but because:


Lost Intellectual Property data is a loss of competitive advantage

Sometimes the only edge a company has is it’s intellectual property that it can use to create a slightly better product, do better in a foreign market, or lower its costs enough to undersell the competition when its products are no better. If that gets stolen, and one or more competitors get their hands on it, the advantage is gone and all of a sudden the product is no better, the edge in the foreign market is lost, and there is no cost advantage to exploit in the end product.


Intrusions that result in lost or stolen data are hard to trace

If your systems or networks get hacked, and your data is stolen, good luck figuring out who got your data, because chances are that not only will you not be able to figure out who hacked you, but you will not even be able to figure out where the hack came from. Right now, there are free hacking toolkits for every major OS on the deep web that can bounce packets off of dozens of anonymous proxy servers, fake TCP/IP headers, and exploit dozens upon dozens of security holes that can be launched successfully against the average system by budding script kiddies — so imagine what real black-hats can do if this is what they give away for free. Do you know how many zero-day exploits are in your systems? They do!


Even if the intrusions are traced, loss is hard to recover

Let’s say you are able to afford, and hire, the best white-hat trackers from the top security firms on the planet and they trace the hack to, let’s say, a rogue hacker in China or Russia. Do you think you’re going to recover anything? Nope. And even if you can trace the hack to your country or a country that you operate in, do you think suing a hacker who got an untraceable payment to a Swiss or Cayman Islands account is going to net you anything? No way!


Data loss prevention requires very powerful, expensive, digital vaults

The only protection your organization has is to install the best systems with the best encryption configured by real security pros. This is not easy to do. Considering that most web sites are full of security holes that are easily uncovered by open source products like PortSwigger’s Burp Scanner, imagine how hard it is to properly secure a database, an ERP, an OS, and the communication lines between them. So not only do you have to buy a top of the line system with embedded security, but then you have to find a real security expert to properly configure and harden the system — who is extremely pricey if you manage to find that person.


And loads of security training, awareness, review, and enforcement.

The majority of data thefts are not the result of hacks, but the result of disgruntled employees with access or social engineering. That’s why you need good policies, training, and enforcement. An admin should not grant carte-blanche access to data in a system to an employee who does not need it just because it’s too hard to set up the roles based security, even if the employee is happy and trust-worthy. Chances are that security will never be reviewed and if, in two years, the employee gets disgruntled or falls on hard times, that’s an exploit waiting to happen.

But the biggest risk is the average employee who writes her password on a post it inside her drawer, a receptionist who does a system test when asked over the phone, or an office admin who grants a workman access to the server room because they look like they should be there. The most common way a hacker gets access to your system is by posing as the janitorial staff who gets to go into every cubicle to empty garbage (and check desks for password post-it notes), as the vendor rep who wants to test the server connection (and has the rep go to a site that looks like the vendor portal admin screen and login for a speed / reliability test when all it does is capture the authentication data before passing through to a real site), or by dressing up as an IT shop employee there to fix the server — because once you’re on the live system, you can suck all the admin codes you want for a remote access later. Poor security practices opens holes bigger than the Vredefort crater.

And the average person does not understand this, even after repeated instructions and explanations as to why writing the password down is dangerous. So this damnation will be with us for quite some time.

Technological Damnation 78: e-Privacy

Privacy is a good thing, and e-Privacy is a better thing, but that doesn’t mean it’s not an eternal damnation to Procurement. Why?

Customers are always demanding more privacy rights.

Including rights that they do not have in the off-line world. While you definitely should not post online that they shop at your location, they some consumers don’t even want you to keep records that they do. But in the real world, you can keep your security feeds, that show them, your physical credit card receipts for at least seven years, that show they shopped their, and the associated transaction receipts, that shows what they bought. But as soon as you store that data in a system, aggregate it, and use it to build a loyalty program and target appropriate rewards (even if you do so in a private way and don’t share the data with anyone), you’re trying to invade their privacy rights. So you have to be extra careful in Procurement that any systems you source have the highest safeguards and are only going to be used for legal, responsible uses.

Oversight requirements are increasing as regulatory acts are multiplying.

As more and more consumers demand their e-Privacy rights, and as more and more data breaches happen as a result of lax (or nonexistent) security, more and more regulations are being proposed and passed. There are so many provincial and federal acts addressing e-Privacy across finance, health-care, and technology that it’s dizzying. It’s impossible to keep up, and when something is missed, Procurement, who will be made responsible for Procuring the technological systems needed by the organization and the third party services providers to help with proper configuration, will be the organization given the blame.

The technological sophistication required to achieve an acceptable level of security and privacy safeguards is through the roof.

It’s not just buying a new database with built in 256-bit encryption, it’s getting all of the data into the database, making sure the data is encrypted on the way in, making sure it goes through a secure, encrypted channel from the port from the old database to the new database, and making sure the new database is appropriately configured and locked down to only authorized access through only authorized channels. This configuration is not easy, given the complexity of today’s encryption technology, the complexity of the tools that need to be encrypted, the arsenal of freely available hacking tools on the deep web, and the average security and third party systems knowledge of an average system administrator. Procurement has to first identify true security experts with experience security the systems and software that need to be secured, source a firm, vet the experts presented, and ensure that the person who shows up is the person who is actually the person whom they are expecting. A tall order for an organization typically tasked with sourcing products to keep production and operations going.

Consumer fear combined with the a lack of technological understanding of the underlying security requirements makes this a difficult damnation to tackle, but one that is only going to get more relevant and immediate as time goes on.

Fifty Years Ago Today …

The 1964 New York World’s Fair comes to a close after a two-year run. More than 51 Million people attended the exposition designed to showcase mid-20th-century American culture and technology that is still inspiring some people today, as evidenced by its inclusion in Walt Disney Pictures recent epic film, Tomorrowland. While it was not sanctioned by the Bureau International des Expositions, it was the first time many of the attendees saw, and interacted with, mainframe computers, computer terminals with keyboards and CRT displays, and telephone modems when the few corporations that had computer equipment kept it in back offices.

Major exhibitors included General Motors, IBM, Bell Systems, Sinclair Oil, and Ford Motor Company — still big names in American Industry 50 years later. While it may have been a financial disaster, it’s legacy and remnants still live on today, with a handful of the pavilions being relocated to new homes around the country, including a ski lodge in western New York, a radio station in Wisconsin, a Hilton Hotel in Missouri, a Four Seasons Lodge in Missouri, a church in California, a science center in Seattle, and attractions at Disneyland.

These days there are conventions galore, but when was the last time there was a true international exposition that really tried to look ahead to what we could achieve with peace and prosperity instead of war mongering (and that people remember) ?

Technological Damnation 91: Proprietary Madness Continued


Can I play with madness?
The prophet stared at his crystal ball
Can I play with madness?
There’s no vision there at all
  Dickinson, Harris, & Smith, 1988

And, as a result, big companies have decided to create their own vision, separate from everyone else’s, and thrust their own visions of damnation upon us. Locking us into technology platforms that we just can’t get out of.

Proprietary designs. Proprietary protocols. Proprietary APIs. All designed to lock you in and keep you in chains.

All the big companies in the tech space at large have done it. Adobe. Apple. Google. IBM. Microsoft. Etc. And now some, like Microsoft, are taking it further than we ever thought possible. Earlier this year, Microsoft decided to go beyond automatic updates to automatic OS upgrades without the user’s permissions. (Which, of course, bricked a number of machines due to problems with drivers and underlying hardware incompatibility.) Now, they’ve supposedly backtracked on this, but it seems that those who have been upgraded, or choose to upgrade, to Windows 10 will have updates forced upon them with no ability to choose or defer, meaning their machines could be bricked at anytime! Ouch! (And that’s why the doctor does not use Windows.)

But they didn’t start the fire. (Although it appears they did a lot of research in choosing the best accelerants.) Pretty much every big tech company has forced proprietary designs (that restrict upgrades to other products provided by the same company or authorized partners), protocols (for interfacing), or APIs (for developing) upon us and still does.

And it’s not limited to the tech space at large and underlying operating systems. In our space, we have proprietary networks, like Ariba, that mandates its hosted P2P tool users also use the Ariba network for all connectivity with suppliers, even in cases where suppliers are connected to other networks that then connect to Ariba’s in the same transaction stream (Source: SpendMatters: “Ariba Doesn’t Have Customers It Has Prisoners”). (And since suppliers have to pay to use the Ariba Network, this puts a heavy price tag on purchases through the network as opposed to a network where the buyer pays a flat fee and the supplier doesn’t, because the supplier is just going to increase their prices to cover this cost.) And to make matters worse, as Ariba starts to lose prominence in the traditional analyst rankings, it’s stepping up its efforts with the smaller tier firms who, probably lacking the manpower to do the in-depth analysis the larger firms are capable of, are giving it rave reviews on the plus side with very little mention of the weaknesses on the negative side. Case in point: a recent review by Ovum which called Ariba the “largest supplier network”, listed four strengths, and only one weakness. SI has to wholeheartedly agree with Spend Matter’s review of Ovum’s analysis  in “beware analyst research ovums review of the ariba network” — the coverage of the weaknesses was not thorough or fair and while SI does not have insight into Ariba’s network statistics beyond what they publish, SI does know that Basware’s volume is on par with Ariba’s published numbers. While Basware may not be a household name in North America, they are probably the biggest and most established network player in Europe in this space and one of the oldest (as the company turned 30 this year).

To make matters worse, there’s not a lot of open standards in our space. You could say that we have cXML, which a number of PunchOut sites are based on, but do we? While it is open and free for use without restrictions apart from restrictions relating to publications of modifications and naming, this protocol was not only created by Ariba in 1999 but is still controlled by Ariba. They could change it at any time, force all sites on the Ariba network to update at that time, and offer very little documentation or guidance as to how anyone outside of that network will go about doing that and, more importantly, support multiple versions simultaneously (for those in the network and those not), which would be a major IT headache. Even worse, they could decide to replace it with cXML 2.0, keep that version proprietary, and create a dichotomy where only those in the network have 2.0 and those don’t.

There is no completely free, non-proprietary, fully open-source standard in our space, and no guarantees. Proprietary Madness is a damnation that is going to haunt us for years to come.

Thirty Years Ago Today

The Free Software Foundation, which launched the GNU General Public License, was founded by Richard Stallman, and the fee software movement, which started when he launched the GNU Project on 27 September 1983, began in earnest.

It took less than 15 years from the start of the movement, to the dismay of companies like IBM and Microsoft, for many open source projects, including Linux (1991), Apache (1995), MySQL (1995), and PHP (1995), to dominate the web.

And allow LOLCats everywhere to dominate the web. 😉