Re: two bits of light holiday reading

2008-12-27 Thread Steven M. Bellovin
On Fri, 26 Dec 2008 01:35:43 -0500 Ivan Krsti__ wrote: > 2. > > The DC-based Center for Strategic and International Studies recently > released a report titled 'Securing Cyberspace for the 44th > Presidency' written by a number of influential authors: > >

Re: Security by asking the drunk whether he's drunk

2008-12-27 Thread Ben Laurie
On Fri, Dec 26, 2008 at 7:39 AM, Peter Gutmann wrote: Adding support for a > service like Perspectives (discussed here a month or two back) would be a good > start since it provides some of the assurance that a commercial PKI can't (and > as an additional benefit it also works for SSH servers, sin

A History of U.S. Communications Security

2008-12-27 Thread Pehr Söderman
Freshly declassified and a rather interesting read: A History of U.S. Communications Security (Volumes I and II, 1973) David G. Boak Lectures, National Security Agency (NSA) http://www.governmentattic.org/2docs/Hist_US_COMSEC_Boak_NSA_1973.pdf (From Bruce Schneier/Governmentattic) /Pehr Söderma

Re: Security by asking the drunk whether he's drunk

2008-12-27 Thread Jerry Leichter
On Dec 26, 2008, at 2:39 AM, Peter Gutmann wrote: d...@geer.org writes: I'm hoping this is just a single instance but it makes you remember that the browser pre-trusted certificate authorities really needs to be cleaned up. Given the more or less complete failure of commercial PKI for bot