Interesting Story about DDoS attacks

How a Bookmaker and a Whiz Kid Took On an Extortionist and Won - CSO Magazine - May 2005
The story recounts the efforts of one company to resist an extortion attempt based on DDoS of the targets website. This seems to be an increasing trend at the moment, and is additional evidence that the worm and virus writers we'll be seeing in the future won't be kids looking for kudos on IRC, but professionals who view compromised systems as a resource to be used, in this case, for criminal ends.

Thought provoking post on terrorism and statistics

The Musings of Harry: Let's not loose our heads
This is a very interesting post. "Harry" has done some work looking at the number of deaths from terrorism as opposed to other causes, in the UK and asks some questions about the level of emphasis and spending on those topics.
It's pretty obvious that a lot of this is based on the shock effect and media coverage. If you take heart disease as an example.. what sort of coverage do the 110,000 people who died in the UK of preventable heart disease, get... compared with the coverage of the London bombings...
Also if you think about it, if the governments goal was preventing the deaths of UK citizens, would they not be better legislating to ban (not just get rid of direct advertising for) unhealthy foods and cigarettes, instead of passing legislation which has a dubious effect, at best, on terrorism....

ToR

Nitesh Dhanjani
Post about using ToR to launch attacks (or in this case vulnerability scanners). Using this it appears that you can be more or less anonymous on the Internet, at a network level anyway. Only the entry point to the ToR network will know the origin of your traffic. Of course if you get to the site and put in identifiable information about yourself, that would somewhat defeat the purpose ;op
Of course it would be probably be possible to reconstruct traffic if you could grab the whole ToR network... but unless you're wanted by governmental agencies.. that shouldn't be a problem!
One thing though. I wonder whether we'll see cases of uninformed courts trying to press charges against the exit points of networks like ToR as they will be what turns up in the logs of destination web servers....

Declining E-commerce?

E-commerce now a turn-off - official | The Register
well not really, just growing more slowly.... But it's an interesting story all the same. It seems that, surprise surprise, Internet users are getting tired of all the phishing and spyware and viruses, and some are stopping useing the 'net for shopping and banking.
I actually think that this could become and accellerating trend. I don't see any magic bullets to make things easier for ordinary, non-technical, Internet users and without some sort of change more and more people will give up on using the 'net for e-commerce no matter how convenient it is.
The annoying thing is that this will hit all the banks and many retailers in the pocket, but because it's no one companies problem, none of them seem to be stepping up to take a lead in trying to combat this...

Excellent Interview with Marcus Ranum

Interview with Marcus Ranum
There's a great interview with Marcus Ranum over at Securityfocus. It's obvious from the responses that he's been around in network security for a while and knows what's what..
Also there's a couple of great quotes...
in response to "If a standard protocol is broken or insecure, what is the best solution? Maybe supporting only some features or adding a crypto layer?"
If it's broken, adding crypto just makes it broken and hidden. is a classic...
also there's some interesting thoughts on de-perimeterisation and advocacy of data-level protection as the solution to all evils