Financial Applications Security Weblog
Secure Applications for Open Markets
April 2002
Sun Mon Tue Wed Thu Fri Sat
  1 2 3 4 5 6
7 8 9 10 11 12 13
14 15 16 17 18 19 20
21 22 23 24 25 26 27
28 29 30        
Mar   May

















Click to see the XML version of this web page.

Click here to send an email to the editor of this weblog.

Click on the coffee mug to add Pelle Braendgaard's Instant Outline to your Radio UserLand buddy list.
 
 

09 April 2002
 

Open for Business (Identity management & open networks).

Nikolaj at Digital Identity mentions Consult Hyperion's  whitepaper on identity management. Big points to him for also posting a link in the same article to Carl Ellison and Bruce Schneiers classic: What You're not Being Told about Public Key Infrastructure. Nice one.

[Digital Identity]
2:28:02 PM      comment []  

Cyber crime bleeds U.S. corporations, survey shows

Many sources have commented on the latest Computer Security Institue (CSI) survey, which was done in cooperation with the FBI. These surveys are quite interesting but I question the methodology used by the various respondents to the survey to get their answers.

For example the survey counts non work related web surfing as  a Cyber Crime. It specifies that in the past year the average cost per respondent has gone from $357,160 to $536,000 a year. The survey claims the two main issues here being productivity and liability. While I can definitely see liability as being a potential issue, I'm quite unsure of the methods they use to quantify their loss of productivity. Howabout the increase of productivity of employees who are happy because their employer doesn't chose to treat them like children.

Another area that might raise a few eyebrows is the losses based on theft of proprietary information. The report says that respondents reported a total loss of $170,827,000 last year. Yet only 20% of respondents reported such infractions. Granted these can be serious issues, however the Tech industry has a history of overreporting the value of such crimes. Just remember the Kevin Mitnick case where companies such as Sun, Nokia etc. made outrageous claims on losses caused by him.

Much more serious in my view is Financial Fraud. The survey states that 12% of respondents had a loss on average  of $957,384. Most of this from what I can acertain is basically traditional credit card fraud.  However I do believe we will see a growth over the next year or two in losses based on investment banking systems. Just imagine how much money could be made if someone managed to create large false trades or spread disinformation on trade/news feeds. Not covered under Financial Fraud but equally an issue would be the cost of DOS attacks targeted at realtime trade feeds.


2:23:19 PM      comment []  

Quick 5 minute intro to JCE for Developers

All enterprise java developers should have at least a passing knowledge of JCE. If you've never tried it before try this quick little intro to sample it: Master the basics of Java Cryptography Extension (JCE).  [builder.com]


1:33:43 PM      comment []  



© Copyright 2002 Pelle Braendgaard.
Last update: 09/04/2002; 13:33:47. <