Homeland Insecurity- (Found July 5, 2008 ) The September issue of the Atlantic Monthly has a remarkable special report called Homeland Insecurity (not yet excerpted online). It features none other than Bruce Schneier. I am delighted to see Schneier's philosophical transformation -- from crypto-infatuated fortress builder to pragmatic watchguard -- detailed in a mainstream magazine. People who would never have read Secrets and Lies will read this excellent article, and I hope will ponder Schneier's message: ...http://www.infoworld.com/weblog/udell/categories/security/2002/08/02.html#a362 (Untitled)- (Found July 5, 2008 ) ...http://www.infoworld.com/weblog/udell/categories/security/2002/01/18.html#a17 (Untitled)- (Found July 5, 2008 ) ...http://www.infoworld.com/weblog/udell/categories/security/2002/01/22.html#a33 (Untitled)- (Found July 5, 2008 ) Hackers Hit Global Leaders' Summit. An invisible cyber assault has cut off access for the second day running to the Web site of the World Economic Forum, organizers of the gathering confirmed. The New York Times: Technology ...http://www.infoworld.com/weblog/udell/categories/security/2002/02/02.html#a48 myNetWatchman: neighborhood watch for the Internet- (Found July 5, 2008 ) Thinking about trust and social capital, in online communities, reminds me of the work of Lawrence Baldwin, the creator of myNetWatchman.com. As I mentioned in a column on broadband security, Lawrence takes issue with the attitude of personal firewalls toward the steady stream of malicious probes that they repel. That attitude can be summed up as: "Don't worry, this is just the background noise of the Internet, and we're shielding you from it." ...http://www.infoworld.com/weblog/udell/categories/security/2002/04/08.html#a182 SOAP security and external underwear- (Found July 5, 2008 ) I'm sure Paul Kulchenko will soon fix the SOAP::Lite vulnerability that was just noticed. This episode got me to wondering, though, about the original rationale for the SOAPaction HTTP header, and what can or should be done to make filtering SOAP traffic workable. Several years ago, one of the original SOAP FAQs, from DevelopMentor, said: ...http://www.infoworld.com/weblog/udell/categories/security/2002/04/09.html#a184 PKI and SSL: house of cards- (Found July 5, 2008 ) Richard Forno, chief security officer for ShadowLogic, takes a dim view of the PKI industry. "Digital trust is a slick marketing tool put out by the PKI industry. DoD wants smartcards with certs by 2004. What's the value of that I don't know. They don't know." ...http://www.infoworld.com/weblog/udell/categories/security/2002/05/14.html#a239 PKI: no silver bullet, but not worthless either- (Found July 5, 2008 ) John Robb's comment -- certification isn't worth doody -- overstates the case. Despite exploitable flaws in the PKISSL infrastructure, I would rather transact business with a company that has identified itself to some third party than with a company that hasn't. ...http://www.infoworld.com/weblog/udell/categories/security/2002/05/15.html#a240 Security, insurance, and hard realities- (Found July 5, 2008 ) Here are some notes from Bruce Schneier's talk. Hard, cold realities. Microsoft and its peers don't care about security, he argues, because it's not rational for them to do so. As businesses, they shouldn't, because they're not liable for their practices. Schneier is running out of options, he says, and what he's left with is a two-pronged strategy. One, require businesses to use insurance to manage risk, just like businesses use it to manage all other risks. Two, beef up prosecution of...http://www.infoworld.com/weblog/udell/categories/security/2002/05/15.html#a242 Managing credentials with Counterpane's Password Safe- (Found July 5, 2008 ) ...http://www.infoworld.com/weblog/udell/categories/security/2002/05/18.html#a251 |