Bruce Schneier

Syndicate content
A blog covering security and security technology.
Updated: 1 hour 56 min ago

Economic Considerations of Website Password Policies

Tue, 2010-07-20 14:52
Two interesting research papers on website password policies. "Where Do Security Policies Come From?": Abstract: We examine the password policies of 75 different websites. Our goal is understand the enormous diversity of requirements: some will accept simple six-character passwords, while others impose rules of great complexity on their users. We compare different features of the sites to find which characteristics...

New GAO Cybersecurity Report

Tue, 2010-07-20 07:43
From the U.S. Government Accountability Office: "Cybersecurity: Key Challenges Need to Be Addressed to Improve Research and Development." Thirty-six pages; I haven't read it....

Violating Terms of Service Possibly a Crime

Mon, 2010-07-19 14:11
From Wired News: The four Wiseguy defendants, who also operated other ticket-reselling businesses, allegedly used sophisticated programming and inside information to bypass technological measures -- including CAPTCHA -- at Ticketmaster and other sites that were intended to prevent such bulk automated purchases. This violated the sites' terms of service, and according to prosecutors constituted unauthorized computer access under the anti-hacking...

Embedded Code in U.S. Cyber Command Logo

Mon, 2010-07-19 07:53
This is excellent. And it's been cracked already....

Friday Squid Blogging: Hawaiian Bobtail Squid

Fri, 2010-07-16 17:34
Symbiotic relationship between the Hawaiian bobtail squid and bioluminescent bacteria, with bonus security implications....

Skype's Cryptography Reverse-Engineered

Fri, 2010-07-16 13:08
Someone claims to have reverse-engineered Skype's proprietary encryption protocols, and has published pieces of it. If the crypto is good, this is less of a big deal than you might think. Good cryptography is designed to be made public; it's only for business reasons that it remains secret....

The NSA's Perfect Citizen

Fri, 2010-07-16 06:19
In what creepy back room do they come up with these names? The federal government is launching an expansive program dubbed "Perfect Citizen" to detect cyber assaults on private companies and government agencies running such critical infrastructure as the electricity grid and nuclear-power plants, according to people familiar with the program. The surveillance by the National Security Agency, the government's...