Re: Secure phones from VectroTel?

2006-05-24 Thread mis
another contender (or could-be contender): http://www.cryptophone.de/products/CPG10/index.html (open source and built by people like rop gonggrijp and barry wels) On Tue, May 23, 2006 at 01:45:15PM -0400, John Ioannidis wrote: On Tue, May 23, 2006 at 11:19:38AM -0400, Perry E. Metzger wrote:

Re: VoIP and phishing

2006-04-27 Thread mis
the other point that should be made about voip is that callerid is trivial to spoof. so if you are counting on the calling party being who they say the are, or even within your company, based on callerid, don't. i predict a round of targeted attacks on help desks and customer service, as well

Re: VoIP and phishing

2006-04-27 Thread mis
On Thu, Apr 27, 2006 at 01:12:43PM -0700, [EMAIL PROTECTED] wrote: so if you are counting on the calling party being who they say the are, or even within your company, based on callerid, don't. does anyone know if time ANI from toll free services is still unspoofable? make that real-time

Re: Not everyone knows about strong crypto...

2006-04-19 Thread mis
and a second data point, not everyone in the mafia chooses good passphrases; a few years ago the government got a black bag warrant (once and a renewal) to install some still undescribed keystroke monitoring technology on nicky scarfo jr's pc, to find out the pgp key of a spreadsheet of a

Re: NY Times reports: Documents show link between ATT and NSA

2006-04-13 Thread mis
in this case, poorly chosen example. it's hard to not print documents used by the technician(s) to install splitters in the fibers and specify the details of wiring in and between various racks and cabinets. On Thu, Apr 13, 2006 at 08:04:07PM +0200, lorenzo wrote: On 4/13/06, Perry E. Metzger

Re: [Clips] Banks Seek Better Online-Security Tools

2005-12-06 Thread mis
please, can people tell us about what their country's liability framework is, as they understand it, and where the onus of proof is for what sorts of transactions? this is one of the few areas where consumers have some actual protection in the us. due to ross anderson, i have heard about the uk.

Re: [Clips] Banks Seek Better Online-Security Tools

2005-12-05 Thread mis
On Mon, Dec 05, 2005 at 09:24:04AM +, Ian G wrote: [EMAIL PROTECTED] wrote: it seems to me the question is how much liability do i expose myself to by doing this, in return for what savings and convenience. That part I agree with, but this part: i don't keep a lot of money in banks

Re: [Clips] Banks Seek Better Online-Security Tools

2005-12-04 Thread mis
dan, maybe you should just keep less money in the bank. i use online banking and financial services of almost every kind (except bill presentment, because i like paper bills). i ccannot do without it. it seems to me the question is how much liability do i expose myself to by doing this, in

Re: Digital Water Marks Thieves

2005-02-22 Thread mis
at the risk of being accused of being humor impaired: the particles are ignorant. it's the police officers that need to know to look for the taggants. civilians could look, but might not have access to the semantic content in the database. this is similar, i think to the taggants that are