Jeff's InfoSec Blog

Thoughts about information security, privacy, and regulatory compliance. Brought to you by Jeff Newfeld, the product unit manager for security solutions in Microsoft's Core Infrastructure Solutions group.

February, 2005

Posts
  • Jeff's InfoSec Blog

    Is finding security holes a good idea?

    • 35 Comments
    Some interesting papers came out of the third annual Workshop on Economics and Information Security. If you're an IEE Computer Society member you can read the full text. Eric Rescorla's article, "Is Finding Security Holes a Good Idea?", provides a statistical...
  • Jeff's InfoSec Blog

    Microsoft's Security Cooperation Program

    • 0 Comments
    I love how news reporting can subtly (or not so subtly) slant interpretations while professing to still be reporting facts. CNet's reporting of the Microsoft Security Cooperation Program is a great example. When I heard about this program I thought it...
  • Jeff's InfoSec Blog

    Former AOL employee pleads guilty in spam case

    • 0 Comments
    Ouch -- 92 million screen names and email addresses stolen from AOL. The guy netted $28k, and will have to pay $200-400k in restitution. Not exactly a lucrative business, was it? Once again we see privacy compromised from the inside -- nothing that...
  • Jeff's InfoSec Blog

    Hey, Mom finally gets security!

    • 0 Comments
    Interesting -- According to a UK study, demograpghics are skewing for home users, with older people buying a larger percentage of home infosec products (AV, etc.) and younger people being the ones that naively assume they're OK. Without the data it's...
  • Jeff's InfoSec Blog

    DRM is anti-privacy???

    • 0 Comments
    DRM is one of those fascinating areas where we really haven't explored the implications of our decisions. I have seen a lot of complaints about Napster's requiring you to be a mamber of their service in order to continue to listen to music that you downloaded...
  • Jeff's InfoSec Blog

    Improving commerce security for consumers

    • 0 Comments
    It's great that even the BBC understands the basic concepts behind identity management ( BBC NEWS | Technology | Solutions to net security fears ) and the problems associated with multiple identities. The token approach (as promulgated by RSA, Activcard...
Page 1 of 1 (6 items)