Updated: 8.5.2002; 0:56:41 GMT.

Security weblog



daily link  Monday, April 22, 2002

Do you want privacy? Are you sure?

"I don't think vendors are going to build in privacy protections if there is no incentive for profit," said Avi Rubin, principal researcher at AT&T Labs, who added that he would like to see a mix of technology and legislation that guards privacy. ...

"These (privacy-enhancing technologies) are built by geeks and only used by geeks. We have not conveyed their importance well to the general public," said Lorrie Faith Cranor, principal technical staff member for AT&T Labs Research, who was on the W3's P3P working group. [itworld covering CFP conference]

Not anything new, most people do not want the same "privacy" privacy advocates want them to want. And BTW, there is an excellent write-up  from Roger Clarke heavily commenting on biometrics and ID issues.

  9:42:38 PM  permalink  
What Microsoft could do better?

Today I have been on a meeting with Microsoft security people re our customers' issues and requirements. Seting aside the obvious priority of secure defaults and making their products "more secure", following things IMHO could improve detection side of Windows security.

Cryptographic file integrity checking. Currently when I inadverently install Back Orifice or other cleverly launched trojan horse, I have no means to find out that the config of my box has in fact changed. Simple tool that would allow to save the checksum of important directories, files, registry subtrees and keys would help here. This would help home users as well as corporations. Should then MS go and buy TripWire?

Logging facilities. Windows logging facilities are weak on the side of large scale log auditing. The facilties do not support secure consolidation of logs well and there are no tools to sift throu piles of data generated. IMHO some data mining tools enabling security administrator to follow trends would be more useful than building in signature host-based IDS.

Evidence generation. This is another twist on logging. Windows do not natively have facilities to build a secure logging server, that would sit behind a separate firewall, and where security relevant events would be forwarded from production servers. Support for writing the logs to read-only media would further improve evidential weight of the logs in case they would be used for formal investigation.

  6:51:06 PM  permalink  

 
April 2002
Sun Mon Tue Wed Thu Fri Sat
  1 2 3 4 5 6
7 8 9 10 11 12 13
14 15 16 17 18 19 20
21 22 23 24 25 26 27
28 29 30        
Mar   May

Misc

About
Reading list
Resources
Contact me

News

SANS NewsBites
Crypto-gram
UKCrypto
Information Security
Objectwatch
CBDi Forum

Channels

Radio UserLand users: click to subscribe. Other folks: use the RSS link to acquire this channel. Better Living Through Software (rss)
Radio UserLand users: click to subscribe. Other folks: use the RSS link to acquire this channel. Content Wire - Digital Copyright (rss)
Radio UserLand users: click to subscribe. Other folks: use the RSS link to acquire this channel. Dictionary.com Word of the Day (rss)
Radio UserLand users: click to subscribe. Other folks: use the RSS link to acquire this channel. Digital Identity (rss)
Radio UserLand users: click to subscribe. Other folks: use the RSS link to acquire this channel. Digital Identity World (rss)
Radio UserLand users: click to subscribe. Other folks: use the RSS link to acquire this channel. Financial Applications Security Weblog (rss)
Radio UserLand users: click to subscribe. Other folks: use the RSS link to acquire this channel. Joel on Software (rss)
Radio UserLand users: click to subscribe. Other folks: use the RSS link to acquire this channel. Jon's Radio (rss)
Radio UserLand users: click to subscribe. Other folks: use the RSS link to acquire this channel. Line56: B2B News (rss)
Radio UserLand users: click to subscribe. Other folks: use the RSS link to acquire this channel. O'Reilly Network Articles (rss)
Radio UserLand users: click to subscribe. Other folks: use the RSS link to acquire this channel. onlineblog.com (rss)
Radio UserLand users: click to subscribe. Other folks: use the RSS link to acquire this channel. RISKS Digest (rss)
Radio UserLand users: click to subscribe. Other folks: use the RSS link to acquire this channel. Scripting News (rss)
Radio UserLand users: click to subscribe. Other folks: use the RSS link to acquire this channel. SecurityFocus (rss)
Radio UserLand users: click to subscribe. Other folks: use the RSS link to acquire this channel. Web Services Architect (rss)
Radio UserLand users: click to subscribe. Other folks: use the RSS link to acquire this channel. WebServices.Org (rss)
Radio UserLand users: click to subscribe. Other folks: use the RSS link to acquire this channel. Wired News (rss)




jenett.radio.simplicity.1.3R
Radio Userland


Copyright 2002 © Jiri Ludvik.
Last update: 8.5.2002; 0:56:41.