Coverage of the "Tsunami Hacker"

Justice versus legality - the case of Daniel Cuthbert | Samizdata.net
some coverage here of the case of Daniel Cuthbert who's been convicted of breach of the Computer Misuse Act for (if the articles I've read are accurate) putting ../../../ into a URL to see if a site he'd just given his credit card to was insecure..
I'm in two minds about this case, on the one hand he shouldn't have done that really it could be construed as an attack and he should've realised that it would trip IDS (although how quiet must they've been in the BT offices that they were investigating ever IDS alarm of that type!)
On the other hand, the Internet is a public place and websites are public resources by definition (unless they have access control configured). what concerns me is that people accessing websites in unusual ways run the risk of being prosecuted.. for example if they see a parameter in a URL and think "I'll just skip ahead by changing that by 5 instead of clicking forward 5 times" ... is that a breach of the computer misuse act..?
also it's waaay to easy to abuse this kind of thing.. how long before someone sends an email with a link which has something like "../../../" in it , causing a recipient who clicks it to appear to be a "hacker"...
Not sure either of those are great reasons, but this case does make me feel uncomfortable for some reason.

Insecure encrypted email?!

Espion automates e-mail encryption
Maybe I'm missing something here but reading this article it seems that someone's come up with an encrypted mail product that's pretty insecure... from the article
"MXLock uses two-key encryption; one of the 1,024-bit keys resides at the sender

Just a touch scary...

Wired News: Nun Terrorized by Terror Watch
This is a liitle bit scary... The terrorist watch list has an AFGHANI MAN using an alias of McPhee on it... and they start stopping an AMERICAN WOMAN because her surname is McPhee.....
I actually think I can see why something like this might happen. I reckon that the culture in this environment is one where everyone is really scared of making a mistake that leads to a successful terrorist attack so they follow instructions to the letter, no matter how stupid..
The only problem is that that approach ignores the opportunity cost and allows people to avoid your checks
- if you spend loads of time with people who are not really suspects, there's less time to look for people who are...
- if you rely on stupid basic measures like surnames, then it's really easy for someone who needs to (and doesn't mind breaking the law), to avoid them...

Airmagnet Spectrum analyser review

TomsNetworking Product Reviews : TomsNetworking :
Review of a very interesting product from Airmagnet. I've used their laptop analyser product, which is great for Wireless Security Site Surveys, but the spectrum analyser is more focused on the performance site survey side of things.
V.cool to be able to track down all the sources of interference (and find the microwave in a big building!)

Implementing software whitelists

Following on from Marcus Ranum's piece on the six dumbest ideas in computer security which I talked about earlier there's been some chat on the CISSPforum which mentions some companies which have software which moves away from the idea of badness enumerators and more towards the idea of whitelists for allowed software...
I've not had a good chance to review the products, but sounds very interesting in concept at least.
these are the two I've seen mentioned, but I'd be interested to hear of any others....
http://bit9.com/products.html
http://www.sanasecurity.com/

Article on Microsofts secure development Lifecycle

Microsoft: Software Security Trendsetter?
Interesting article on Microsofts continued moved to improve the security in their new applications...
It's good stuff and I'm very happy to see the quantity of information about software security that Microsoft make available for free on their website... Hopefully will encourage windows developers in general to take software security more seriously...
Now all Microsoft need to do is allow users to not to have to install millions of lines of unnecessary code on servers (hint think Media player, Internet Explorer etc) and re-write the older legacy code that still seems to cause problems, and they'll be sorted :o)