noooooooo.

Schneier on Security: Impressive Phishing Attack
Wow phishers with genuine SSL certs, issued by Certificate authoritys that are installed, by default, in every browser on the planet...
Just goes to show, when there's money involved the criminals will evolve and get real smart real quick...
As to the SSL cert providers assertions that they rigourously check SSL cert applications... well yeah.

Good example of one of those counter intuitive security things

Insights into Information Security: IPSEC everywhere? Bad idea
Excellent post pointing out why encryption can be a bad thing. It sounds counter-intuitive at first, in that security people will spend a lot of time telling you to use things like SSH instead of telnet and SFTP instead of FTP because the they use encryption...
but too much encryption can be a bad thing. It can blind devices like Intrusion detection systems and actually help an attacker, if that attacker has already broken into an endpoint system, and in the majority of attack scenarios that will be the case...
so the net effect of encrypting everything is actually a decrease in security...

NMAP 4's out!

Nmap 4.00 with Fyodor
Well NMAP 4's out and from the link it looks like there are a fair number of cool new features and enhancements to it...
One to try out over the next couple of days.

Some good points on Client Security

Security Fix - Brian Krebs on Computer and Internet Security - (washingtonpost.com)
An interesting posting on a somewhat neglected area of risk to client machines.
The point that potentially exploitable 3rd party Active X controls will be installed on many, if not all client PC's is a good one.
I've seen companies that more or less successfully patch browsers and audit client software, but I'm not aware of any that track Active X component versions...
Sounds like a good reason to lock down Active X installations on Corporate Clients..

Oracle Security Slowness

Zero-day details underscore criticism of Oracle
Article about the slowness with which Oracle is patching its software. Given the fact that many companies will be using Oracle software to store a lot of their critical information, it's quite worrying that they can take over 2 years to deploy a fix for a bug.
We've seen with the current worm/botnet problems, a trend for security exploits to be part of professional criminal activities. So I wonder what the likelihood that there are Blackhats actively working on finding database flaws... I'd say reasonably likely, with that likelihood increasing over time.
So if we assume that, then we can assume that they'll be finding the same things that security researchers have been finding and notifying Oracle of, at which point it becomes pretty worrying that Oracle are so unresponsive in terms of patching these flaws...

Blog Worm....

Although my paranoia does make me worry as to whether there are any potential downsides to this, it's too funny to pass up

Blog.Worm

UPDATE : now edited to use a non-updating version, in case of malicious alteration of source... for more info. see link here