Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs
A changing landscape
Rohyt Belani, 2005-09-07

In 2004, I came across an empirical study published by the CERT/CC that indicated a diminishing correlation between the number of vendor-issued vulnerabilities and the number of reported security incidents. In the years prior to 2002, the number of reported security breaches had always been proportional to the number of vendor-published vulnerabilities. That corollary made sense, since attacks and worms followed vulnerabilities. However, in 2003 and beyond this was no longer the case. The number of incidents rose dramatically as compared to the number of published vulnerabilities.

Submit Comment Mode:
Name:
Subject:
Message:
 
  Enter the characters that appear above
 
Re: Re: A changing landscape 2005-09-22
Anonymous
Barclays have an interesting approach to keyloggers; as part of their authentication, you must enter two letters from a password, but do so using drop-down menus.

On one hand, this is pretty much security-by-obscurity, but on the other - for now, at least - it would be somewhat harder to 'keylog'...

[ more ]  





 

Privacy Statement
Copyright 2009, SecurityFocus