, SecurityFocus 2000-05-01
Security companies can make headlines by using the right jargon, even when it's wrong.
Expand all |
Post comment
A couple of comments
2000-05-01
Anonymous (3 replies)
Anonymous (3 replies)
Re: A couple of comments
2000-05-01
Elias Levy <aleph1 (at) securityfocus (dot) com [email concealed]> (1 replies)
Elias Levy <aleph1 (at) securityfocus (dot) com [email concealed]> (1 replies)
Re: A couple of comments
2000-05-01
Anonymous (1 replies)
Anonymous (1 replies)
Re: A couple of comments
2000-05-01
Elias Levy <aleph1 (at) securityfocus (dot) com [email concealed]> (3 replies)
Elias Levy <aleph1 (at) securityfocus (dot) com [email concealed]> (3 replies)
Re: A couple of comments
2000-05-02
Anonymous (1 replies)
Anonymous (1 replies)
Re: A couple of comments
2000-05-02
Elias Levy <aleph1 (at) securityfocus (dot) com [email concealed]>
Elias Levy <aleph1 (at) securityfocus (dot) com [email concealed]>
Re: A couple of comments
2000-05-02
Anonymous (2 replies)
Anonymous (2 replies)
Re: A couple of comments
2000-05-02
Elias Levy <aleph1 (at) securityfocus (dot) com [email concealed]> (1 replies)
Elias Levy <aleph1 (at) securityfocus (dot) com [email concealed]> (1 replies)
Re: A couple of comments
2000-05-02
Anonymous (1 replies)
Anonymous (1 replies)
Re: A couple of comments
2000-05-02
Elias Levy <aleph1 (at) securityfocus (dot) com [email concealed]>
Elias Levy <aleph1 (at) securityfocus (dot) com [email concealed]>

The M$ "weenies" key was just misreported. It is a weak encryption key buried in a DLL most of us have on at least one computer we own / maintain (just what machine do you play games on?) Has anyone actually looked at the encryption tech - weak key and duff algorithm, or good basic tech and incredibly crap implementation (the last phrase TM M$ Corp, c/o 2001 Business Plan.)
The various shopping carts have had actual doors, bypassing the standard password mechanisms - no-one knew or could have known they were there without doing the sort of code analysis that no employed sysadmin could legitimately find time to justify, never mind do. What is worse is that, as these systems de facto require internet access, you can't even block them off at the boundary.
Ho hum, back to chasing ineffective anarchists.
[ reply ]
Link to this comment: http://www.securityfocus.com/comments/articles/25/1606#1606