I just read a paper on the political analysis of the Estonian Attack. If you are interested reading my post on my other blog (as the analysis is not really technical but interesting) there you go: Analysis of the Estonian Attacks
Roger
Shoaib's blog actually pointed me to a pretty interesting article called Face-Off: Is vulnerability research ethical? - Security Experts Bruce Schneier & Marcus Ranum Offer Their Opposing Points of View. Not surprisingly Bruce says "yes" and Marcus says "no". If you read through their points, you might even agree partly with each of them:
But to me, this is the wrong question: It is not so much about security research. To me it is about two things:
That's really bad if vendors make money selling security updates…
We just announced that we will add support for additional file formats in Office System 2007 SP2. Just read more on Open XML, ODF, PDF, and XPS in Office
You know that I criticize SANS from time to time. Especially when it come to their handlers, I am convinced that they are creating the problem rather than solving it.
This time I have to say that I am impressed as they are helping developing countries to help to fight Cybercrime. This is as "we are all in this together". As I say often, that we have to collaborate and build partnerships in order to fight the criminals.
Read the announcement by SANS: SANS Institute Commits $1 Million for Joint Cyber Defence Program with International Multilateral Partnership Against Cyber-Terrorism (IMPACT)
I just read this article on Cryptography Expert Wins ACM Award for Advances in Protecting Privacy of Information Retrieval. This is really cool to see that research with do at Microsoft Research not "only" leads to advancements in our products but to public recognition as well. Well done Sergey!