Someone asked me a question yesterday and I initially wanted to just point them at a document or website rather than type out my explanation. Unfortunately, 5 minutes of searching yielded no results. So, below is my guide to the difference between renewal, re-key, and re-issuance of an X.509 public key certificate. Renewal is when all the identifying information and the public key from the old certificate are duplicated in the new certificate, but there is a different (longer) validity period. Re-key is when all the identifying information from the old certificate is duplicated in the new certificate, but there is a different public key and (usually) a different validity period. Re-issuance is when a certificate holder registers for a[…]

The Wall Street Journal had an article today on Ten Things your IT Department Won’t Tell You (I was able to access it without a username, but YMMV). First off, the article is talking about circumventing your company’s IT security policies – in many cases, this means say goodbye to your job. In other cases, it means serious legal trouble for you and your company. All companies have sensitive information – formulas, financial data, processes, etc – for example, the Coca-Cola formula. This information is labeled sensitive or secret for a reason. In the case of companies, this information makes or breaks the company. In the case of the government, it protects everyone in the country. In a lot of[…]

Tuesday July 3’s Wall Street Journal had an article entitled “Signing Up for E-Signatures”. You can read the WSJ excerpt here, or go to this person’s blog who has copied the whole thing.

The software for computerizing pen-and-ink signatures on contracts, mortgages and other important documents was too complicated for most people to use…

I have just written a letter to the editor to respond to this article. Click through to read it.

I hope everyone remembers the TJX compromise in January Well, I received a letter from my bank yesterday telling me that my debit card was one of the numbers compromised. Let’s see the general timeline here: July 2005-December 2006: compromised time (estimated) December 2006: I buy some Christmas gifts at TJ Maxx using my debit card (as a credit card) January 2007: First public notification that something’s wrong January 2007: Some consumers are notified February 2007: Public notification that the compromise might include more cards than initially thought March 2007: TJX releases more details June 21, 2007: I’m notified of the potential compromise of my data My bank took 6 months to notify me that my information was compromised. I[…]

Again I feel the need to rant about a non-information security topic, but this is important to discuss. Unless you have been living under a rock, you have heard about the events of this past Monday.

I don’t think we learned anything from Columbine. Cho Seung-Hui exhibited all the classic warning signs, and was able to buy two guns and killed 32 innocent people. Read on for my rant.

Companies often try to enhance security without asking users to do anything. ‘Secure’ images are one such attempt and can be used in phishing attacks as demonstrated (QuickTime video). You can read more here and here. Secure images don’t help prevent phishing attacks, and we don’t like them either. Like Peter Parker’s Uncle Ben said, “with great power comes great responsibility.” Banks, TurboTax, and the like certainly have a lot of power, with little oversight.