Article about password alternatives

Wired News: Complex Passwords Foil Hacks
There's an interesting form of 2-factor authentication mentioned in this article on Wired. Scratchcards that reveal one-time passwords. One thing that does occur to me is that I suppose they will need to be used in sequence (so that only one is valid at any one time), so what would happen if you wanted to skip one, for example if the cover on one rubbed off in your wallet and you weren't sure if someone else had seen it...

An example of software patents being a bad thing(tm)

InfoWorld: Network Associates is granted broad antispam patent: June 01, 2004: By : SECURITY
Looks from this article like we'll be seeing some patent lawsuits soon in the security world. This is a good example of what I don't like about software patents, an overly broad patent, for which there may well be prior art, but in order to challenge it there will now have to be an expensive court case out of which no-one will win but the lawyers!!!
sigh

Pointer to a great paper on economics and security

Dana Epp's ramblings at the Sanctuary : Economics of Information Security
Dana has a link from a link on Axel's blog to a great article about Security and economics by Ross Anderson(Gee blogging gets a bit overly linked at times :op)...
As with a lot of Ross Andersons writings it's very thought provoking, with many interesting ideas in it. A recommended read even if you're not into InfoSec as it provides one possible explanation for things like why Microsoft dominates certain computing markets....
One of the many interesting ideas in it was an analysis of why even the best funded security team can fall foul of a relatively poorly funded attacked in the computing world (starts on Page 4)

Good password sudy

Slashdot | Password Memorability and Securability
There's an interesting story on Slashdot, linking to a study on password quality, it has a couple of interesting conclusions amongst some other confirmations of common themes in password quality. Most interesting is probably the conclusion that in practice mnemonic passwords are as strong as randomly chosen passwords and are far easier to remember....

Novel way of Learning about Cisco Products

Over at RouterGod there's a very informative series of articles about various Cisco topics. They're in the News Archives section and they've got an..... interesting way of presenting the information ...

Story on the Cisco code theft

New evidence points to Cisco network hack
An article providing some more info on the Cisco code theft, over at Network World. One point mentioned in it that I would disagree with though is the comment that
"Unlike open source software products, the security of Cisco's systems, like those of other proprietary software vendors, depends on the source code being kept out of public view, he said"
This is a bit on the sweeping side really... Although it is a salutory lesson that companies shouldn't rely on the secrecy of their code to provide security.