Really, people. If I tell my rep that I will not be renewing, most renew-now messages stop. This is not the case with with the list servers. The ACM Bulletin, TechNews, and whatever else you may be subscribed to will continue on their merry way.
At a certain point, this becomes spam. If, after all, I regarded those lists as being extremely valuable, I would likely never have left ACM in the first place.
Just saying.
There's a lot going on right now. which is how it comes to be that my first post of the month is on the 24th. Over a month since my last post. So I have to regard ACM mail as something that should have vanished at the end of last month. Just random stuff that I have to send unsubscribe messages to.
Showing posts with label ACM. Show all posts
Showing posts with label ACM. Show all posts
Friday, April 17, 2015
Wednesday, December 3, 2014
Yet More Trouble in Toyland
The spasm of Point-of-Sale exploits this year and last (Target, Home Depot, Subway, Dairy Queen, Jimmy John's, and recently even car parking and washing facilities, etc.) has been enough to do some damage to consumer confidence.
Though these were Point-of-Sale issues, they were network attacks. So if any consumer was frustrated enough to decide that it was probably just as safe doing their holiday shopping online... Oops. And now we have more evidence, if any were needed, that those security seals commonly seen on eCommerce web sites offer less surety than a shopper might be led to expect. In some cases, they can even assist an attacker.
The paper is Clubbing Seals: Exploring the Ecosystem of Third-party Security Seals
Tom Van Goethem, Frank Piessens, Wouter Joosen, Nick Nikiforakis
in Proceedings of the 21st ACM Conference on Computer and Communications Security (CCS 2014).
Though these were Point-of-Sale issues, they were network attacks. So if any consumer was frustrated enough to decide that it was probably just as safe doing their holiday shopping online... Oops. And now we have more evidence, if any were needed, that those security seals commonly seen on eCommerce web sites offer less surety than a shopper might be led to expect. In some cases, they can even assist an attacker.
The paper is Clubbing Seals: Exploring the Ecosystem of Third-party Security Seals
Tom Van Goethem, Frank Piessens, Wouter Joosen, Nick Nikiforakis
in Proceedings of the 21st ACM Conference on Computer and Communications Security (CCS 2014).
It is available to the public at https://securitee.org/files/seals_ccs2014.pdf. It's only eight pages, a nice piece of work, and one example (see page 6) is jaw-droppingly funny. Which is good, because the news is pretty grim, and you will need your sense of humor.
Give it a read. If you are a consumer, quit trusting security seals on Web sites, to whatever extent that you ever did. If you are a site operator, be advised that you may not be getting what you thought you were paying for, if these scans were intended as a component of continuous audit.
Here's the abstract.
Here's the abstract.
In the current web of distrust, malware, and server compromises, convincing an online consumer that a website is secure, can make the difference between a visitor and a buyer. Third-party security seals position themselves as a solution to this problem, where a trusted external company vouches for the security of a website, and communicates it to visitors through a security seal which the certified website can embed in its pages.In this paper, we explore the ecosystem of third-party security seals focusing on their security claims, in an attempt to quantify the difference between the advertised guarantees of security seals, and reality. Through a series of automated and manual experiments, we discover a real lack of thoroughness from the side of the seal providers, which results in obviously insecure websites being certified as secure. Next to the incomplete protection, we demonstrate how malware can trivially evade detection by seal providers and detail a series of attacks that are actually facilitated by seal providers. Among other things, we show how seals can give more credence to phishing attacks, and how the current architecture of third-party security seals can be used as a completely passive vulnerability oracle, allowing attackers to focus their energy on websites with known vulnerabilities.The paper also notes that it would be trivial for a shady shopping site operator to dodge the scans these vendors perform, either to outright save themselves mitigation expense, or to give themselves a longer grace period, while still presenting the seal to the public.
Thursday, March 20, 2014
Congratulations to Leslie Lamport, winner of the 2013 Turing Award
"Lamport's practical and widely used algorithms and tools have applications in security, cloud computing, embedded systems and database systems as well as mission-critical computer systems that rely on secure information sharing and interoperability to prevent failure."
Many probably think of him mainly as the initial developer of LaTeX, for which I am often personally grateful, but his contributions go far beyond this. Have a look at
and form your own conclusions.
During the Ballmer era of Microsoft, there was much heat and noise related to claims that Linux could not innovate. Yet Turing award winners associated with Microsoft were a bit thin on the ground. Not absent: Charles P. Thacker won in 2009, and one of his many accomplishments was helping to establish Microsoft Research Cambridge in Cambridge, England.
Those days are hopefully behind us; it was mostly strategic corporate marketing noise. Microsoft has been been funding his work, by the simple means of employing him, since 2001. Microsoft deserves our thanks as well.
Wednesday, February 5, 2014
SACMAT call for papers
This is the 19th ACM Symposium on Access Control Models and Technologies. I am a practioner, rather than a researcher, in this area. Which means that while I have nothing to contribute, I am very interested in the results of this symposium.
Some details on what SACMAT is all about are available, appropriately enough, at the About page.
However, why I think SACMAT will inform my thinking is probably better seen in their call for papers. There are 24 in-scope topics, ranging through administration, cryptographic approaches, economic models and game theory, policy engineering and analysis, and trust management.
Where and when? London, Ontario, Canada. June 25-27, 2014.
Some details on what SACMAT is all about are available, appropriately enough, at the About page.
However, why I think SACMAT will inform my thinking is probably better seen in their call for papers. There are 24 in-scope topics, ranging through administration, cryptographic approaches, economic models and game theory, policy engineering and analysis, and trust management.
Where and when? London, Ontario, Canada. June 25-27, 2014.
Subscribe to:
Posts (Atom)
