More on Chip/PIN

there's some more comment on the ongoing Chip & PIN implementation in the UK at Schneier on Security and Financial Cryptography , with some interesting points being made about how this move co-incides with one to shift the liability for fraudulent transactions from banks to retailers where the terminals haven't been upgraded.
Interesting to note that I've recently received a credit card with an expiry in 2006 which doesn't have a chip on it... I wonder if retailers will start refusing to accept cards without chip&PIN in order to avoid liability.

Ethics and CISSP's

There's an interesting post over at <a title="The Quiet Earth

[OT]Firefox Tuning Info

Firefox Tuning - MozillaZine Forums
Information on firefox tuning. The section on pipelining is particularily cool. I've switched it on and definately see a speed up in my browsing...

Category-based Web content blocking... a bit useless really

Looking at a couple of tools I found on the web CGIProxy and PHProxy it seems to me that content based blocking by companies becomes a bit pointless, as you can put one of these scripts on a home PC on a DSL/cable modem connection and bypass anything which blocks based on URL, unless you use a "everything not explicitly allowed is denied" setup, which is kind of a hard sell in most companies.
Additionally, if you access these over a SSL connection, any proxies or content checkers won't see anything apart from the original URL so content scanning wouldn't work either...
Just goes to show, open one port on a firewall and be prepared for the fact that almost any content can come through....

An object lesson in the importance of maintaining domain names

Over at cryptome.org there's a page - British Military Intelligence Website Hijacked
Looks like the MOD forgot or didn't want to renew the DNS for intelligencecorps.co.uk!
As a result someone in the US (cryptome say that it's a former british agent, not sure where that info. comes from) has registered the domain, and will be getting e-mails sent by people using the Intelligence Corps part of the mod site... (as well as any other mail that may be sent to that domain!!)
DNS management.. It's important!

Article on the relationship between ITIL and InfoSec

SecurityFocus HOME Infocus: How ITIL Can Improve Information Security
Internesting article on ITIL and InfoSec.

Know Your Enemy stats.. Linux getting harder to compromise...

Martin McKeay's Network Security Blog: KYE Trend Analysis
An interesting entry over at Martin McKeay's blog covering the info. from the Honeynet Project about trends seen in compromise of systems on the Internet from their research..
Looks like Linux systems are getting harder to compromise out of the box, while the time to compromise windows systems goes down..
Hopefully the windows time will go up as more machines ship with SP2 on by default (thus giving the user enough time to get the patches, before they're compromised)

WEP ... toast this time?

Interesting article at SecurityFocus SecurityFocus on new tools which are available, which can crack WEP keys much more quickly than you'd expect based on their key length...
Time to start using WPA!

[OT] Amarok Rules....

Not really security related at all, but I thought I'd post about a really cool media player I've been using recently on Linux... Amarok has many cool features, but the ones I like best are..
- Catalogues all your songs reading all the tags and sorting by artist
- Cover manager, automatically grabs the covers for the CD's from amazon
- Nice statistics down the left side with things like "other albums by this artist" and "most popular song"
- looks really nice...

Implications of SOX for Security Professionals

HNS - Sarbanes-Oxley: An Opportunity for Security Professionals
This is a quite interesting article presenting Sarbanes-Oxley as an opportunity for Information Security teams to prove their worth to businesses.