Micosoft on Hailstorm (press conference)

Hailstorm:
Transcript of the Microsoft press conference today. [Scripting News]

Canonical XML now official

Canonical XML now official. Canonical XML, a technology particulary important for
implementation of XML-based digital signatures, has been
released as an official W3C Recommendation. [xmlhack]

The Network is the User Experience

Useit.Com: From June 25, 2000; Jakob Nielsen:
The Network is the User Experience [Tomalak’s Realm]

See also:
July 23, 2000:End of Web Design

OpenWall just published a security advisory entitled

OpenWall just published a security advisory entitled Passive Analysis of SSH (Secure Shell) Traffic. This advisory demonstrates several weaknesses in implementations of SSH (Secure Shell) protocols. When exploited, they let the attacker obtain sensitive information (basically password lengths) by passively monitoring encrypted SSH sessions. Fix information, patches to reduce the impact of traffic analysis, and a tool to demonstrate the attacks are provided.
[OpenWall]

Microsoft on HailStorm

White paper: Microsoft HailStorm. “Support will also be included for integration between Windows authentication and Passport authentication of users, so that a user logged onto Windows XP will also be logged onto Passport and therefore able to receive their HailStorm services.” [Scripting News]

New article in Intrusion Detection: Realistic Expectations for Intrusion Detection Systems

SSH Secure Shell Denial of Service Vulnerability

Secure Programming for Linux and Unix HOWTO (paper)

Earthlink tracks users via “super-cookie”?

Earthlink tracks users via “super-cookie”? [MacNN]

See also: Gibson Research, Shields UP, Earthlink

Update 3/20/2001: False Alarm: EarthLink explained that this scary looking “serial number like” tag was actually a composite of information gained from various characteristics of the user’s computer and their Internet connection.

TAXI to the Future