Updated: 17.6.2003; 0:01:39 GMT

blogattic
weblog mostly about security


daily link  Wednesday, May 14, 2003

Additions to the weblog list

Have come across some new (at least for me) security weblogs:

  • TaoSecurity: network security, news alerts, book reviews
  • Troy Jessup Security Blog: good network security stuff, but a bit quiet recently
  • Lasipalatsi: various topics, incl. some ideas on digital identity which I can identify (pun intended) with

    Added all of them on the Security Weblogs list

  •   8:58:55 PM  permalink  
    Failing gracefully

    If you are in security profession and think that systems must be made secure at any cost, think twice. One would assume that design making sure system fails in a secure state (one of the requirements in Orange Book ages ago) would be an absolute, but consider the following story (courtesy of Interesting People).

    "Thailand's Finance Minister Suchart Jaovisidha had to be rescued today from
    inside his expensive BMW limousine after the onboard computer crashed,
    leaving the vehicle immobilized.

    Once the computer failed, neither the door locks, power windows nor air
    conditioning systems would function, leaving the Minister and his driver
    trapped inside the rapidly heating vehicle."

    Obviously car systems designer made the decision that that when the on-board computer crashes, it should go down in 'safe' mode. Now the question is what safe means. Doors locked, so that noone can get into the parked car? Or door unlocked, in case someone is inside? This conflict of priorities nicely illustrates why the notion that systems should be 'as secure as possible' that can be frequently seen, is often not grounded in reality.  Being smart designing the type of security that is in line with the purpose of the system and which does not get in the way of actual use of the product is in most cases much more important.

      8:10:43 PM  permalink  

     
    May 2003
    Sun Mon Tue Wed Thu Fri Sat
            1 2 3
    4 5 6 7 8 9 10
    11 12 13 14 15 16 17
    18 19 20 21 22 23 24
    25 26 27 28 29 30 31
    Apr   Jun

    Click to see the XML version of this web page.

    jenett.radio.simplicity.1.3R
    Radio Userland



    Copyright 2003 © Jiri Ludvik.
    Last update: 17.6.2003; 0:01:39.