Slashdot Mirror


User: collinl

collinl's activity in the archive.

Stories
0
Comments
45
First seen
Last seen
Profile
(view on slashdot.org)

Comments · 45

  1. Re:May I be the first to say... on eBay Retires MS Passport Sign-In · · Score: 1

    No SMartcards are just a password verification, only remotely at user locaiton.
    Almost all the rest of the smarts goes into having the smart card tell the server that password verification passed.
    What good is that?

  2. Re:About time... on Free Certificate Authority Unveiled by Aussies · · Score: 1

    I'm not sure the CA are all that useful with revocation lists.
    The multiple US government CA/PKIs now have CRLs that reportedly take up to 14 minutes to process in a PKI-using client - a bit of a mess when you've a few dozen emails to verify every day.

    Distributed revocation is a bad thing.
    Just like DNS - PKI is distributed revocation since every user/client must do their own revocation status checking - imagine getting a DNS record for a web site once, then always trusting it to be accurate?.
    Every PKI-protected message/session should be checked for revocation status - that's the benefit of centralised revocation/user management (and it's waaayyyy cheaper to operate).
    lyal

  3. Re:As opposed to the security of PSTN? on Is Security Holding VoIP Back? · · Score: 1

    I think this PKI-edness of VOIP is basically silly.
    I can receive a phone call, or make one at any PSTN phone.
    With PKI based VOIP, I can only answer the phone, or make calls, from a single machine.
    Why remove that level of flexibility just to cut out the telco?

    A better idea might be to secure the link to the IP-based switching centre, and let their directory service manage the link to the remote end, including confidentiality, authentication and so on. Sounds a lot like a telco to me.

  4. Re:Let's get all the one-liners out at once... on Australian Firm Asks SCO To Detail Evidence · · Score: 1

    Who cares?
    SCO is basically a US problem, not ours.

  5. Pay by Snap on New Online Music Service For Australia · · Score: 1

    Get a Snap account and pay online for amounts as small as these.
    Why waste time going to a store to get as voucher?

  6. Application Security is a must on Changes in the Network Security Model? · · Score: 1

    The issue is that treating the problem of security at 2 levels (network and application) is flawed - each specialist area thinks the other is doing everything.

    The real goal OMHO is to dumb down the need to network security (i.e. stick to firewalls, routing controls and simple protocol checks) and boost security at the application messaging layer.

    The 3As (authentication, authorisation, accountability), confideentility, integrity and content inspection/management are a must.
    SSL, SSH and VPNs et al don't enable any of these attributes at the application layer.

    For those wishing to transform themselves into viable internet entities ffrom the early adopter mmodels, look for application level security tools.

  7. Re:No cryptography is unbreakable... on Quantum Cryptography Gets Nanotube Boost · · Score: 1

    Interesting.
    The first 4 digits can only have a few thousand permissible (i.e. issued) combinations.
    The next 4 digits relate to the type of card (gold, platimum, bog standard, special chacateristics of the bank's charging regime etc)
    8 digits of combinaiton will be limited to those card products issued by banks in your region of domicile
    The last digit is a checksum, so no need to brute force that.
    Only 7 digits to guess. A google search or two to guess your residential area and banks servicing that area, and cardmaster here we come!

  8. Re:Bayesian radio on America's Hams Embrace Linux · · Score: 1

    By this logic, electricity should not be regulated either.
    Electrons are just framgments of physics, right?

    I agree that over regulation is bad, but the way to discuss and promote alternatives should at least be sensible and justifiable, IMHO.

    Lyal

  9. Re:I can do better than that on E-Pass Can Resue Patent Case Against Palm · · Score: 1

    I agree - smartcard wer around much longer than that.
    However, how much of the work was in the public domain? If none, then a patent can be applied for, AFAIK.
    How much of the internal processes you worked on functioned as described in this patent in question?
    If none, then the patent was not infringed by your employer.

    lyal

  10. Re:Legal responsibility on Consumer Database Company Hacked · · Score: 1

    Debit is significantly cheaper than credit IF you use a PIN, not signature.
    It's only weird card scheme rules that create huge price difference for the small difference of a signature vs a PIN - a difference settled in a ~$5bn case by Mastercard and Visa in a case against them by Walmart and other retailers.

    Use a PIN, save yourself money, save the merchant money, and reduce your risk of fraudulent use of your signature.
    Now, we just need the card schemes to enforce the strong terminal security like the rest of the developed world has had for 10+ years.

  11. Re:How to make WiFi Cost Effective. on A Solution For Making WiFi Cost Effective · · Score: 1

    Because those doing it were taking planned, systemaic hostile actions against one or more targets to find weaknesses, with the goal usally of finding cheap telephone access.

  12. Re:KIsmet saves the day on Detecting 802.11 Discovery Apps · · Score: 1

    Most high-gain antennas are very directional.
    So the mechanics of being able to point this antena over a 360 degree sphere of interest (or multiple antennae) will cost more time and effort than actually securing the wlan itself

    Lyal

  13. Re:dead on German Crypto Mobile Announced · · Score: 1

    Using hardware crypto means the distribution of the keys is a whole lot simpler - just do it when the handset is shipped.
    None of this computationally and bandwidth expensive overheads with PKI which no one trusts to the level necessary to protect a phone conversation.

  14. Re:Abolish patent laws on Byte Offers An Explanation Of Patent Law · · Score: 1

    Well, probably A is covered by paying upwards of $20k over 2-3 years - if that's not a form intent, then what is?
    re B) Right now it appears 17 or 20 years is considered the appropriate amount of time. The time to get something to market must start AFTER the patent applciation is lodged - you can't patent anything that is marketed as it is then prior art, and no longer unique.
    re c) The publishing of patents after an initial patent office examination already occurs, and any interested party can challenge the patent application.
    re D) - Isn't this just commercial good sense? Why would I cause someone to shut down a profitable line of business when I can ask for a reasonable market fee, and gain access to a ready-built market that has cost me nothing to build??????

    Lyal

  15. Re:Abolish patent laws on Byte Offers An Explanation Of Patent Law · · Score: 1

    As far as I know, it is difficult to legally distinguish between a person and a company in law - both a recognised entities with many similar rights.

    Lyal

  16. Re:You are by god going to have to pay! on House Passes Digital Signature Bill · · Score: 1

    "Do you have any proof of this? Point out exactly where in the bill it says this, please."

    The Mastercard/Visa rule changes put all the liability onto the cardhoolder under SET.
    Unless you can prove you didn't generate the elelctronic transaction, you're stuck with the bill! No questions
    No-one has any idea on how to prove you didn't create a digital signature.
    Meanwhile, hacking attacks to steal a copy of your Private key are almost trivial today.

    Lyal

  17. Rubbish!! about electrinc signatures on House Passes Digital Signature Bill · · Score: 1

    How many financial transactions occur using RSA?
    Almost none, as there is no accepted standards for financial transactions using PKI (ignoring SET, it's a joke).
    Over 16 billion DES protected transactions (ATM, POS etc) occurred in the US in 1997.

    Tell me which has market share and reliability?

    Lyal

  18. Re:PGP Signatures? on House Passes Digital Signature Bill · · Score: 1

    There are brute-force password attacks on PGP key files - fast as well, much faster than key-cracking.

    About as fast as l0pthcrack, actually

    With PGP key file-stealing rojans around, PGP is definitely suspect as a trust tool - still good for confidentiality, uses right.

    Lyal

  19. Re:Everything can be hacked on House Passes Digital Signature Bill · · Score: 1

    Exactly


    lyal

  20. Re:foo on House Passes Digital Signature Bill · · Score: 1

    4096 bit PKI is no better than your password used to protect the private key.

    And passwords as subject to dictionary attack.



    Finally, a digital signature has no intrinsic way to prove you did it. By contrast, a handwritten signature can be shown forensically to be consistent with all other signatures known to have been made by you.

    In the case of disputed digital signatures, it is your word against that of someones machine.
    Guess who wins?

    I have no idea either - but I'm not trusting my electronic life to such uncertainty!


    Lyal