Our bulletin board has had this editorial from eWeek hanging for over 4 years now. Still worth a thought. We have to get over the bias that there’s something dishonorable about choosing languages that prize safety over pure efficiency. Hardware capacity is growing faster than programmer accuracy. It’s time to require case-by-case justification of C and C++, the tools that grease the floor and let developers run with knives. Have we reached that point yet? Have Java and .NET taken over, or are C and C++ still ruling the roost? If so, what is the holdup?

SecurityFocus is reporting that online attackers are hitting the U.S. Department of Commerce. The U.S. Department of Commerce took hundreds of computers offline following a series of attacks aimed at federal employees’ computer accounts by online thieves that appear to be based in China, according to media reports published on Monday. Kind of disappointing, considering NIST is an agency of the U.S. Commerce Department, and NIST has brought us the XP Security Guides and lots of other special publications. Good thing they also wrote SP 800-61, Computer Security Incident Handling Guide…

From eWeek, a link to a cute slideshow of Peter Coffee’s Dirty Dozen IT Embarrassments. 1999: Melissa Worm teaches crucial lessons—or does it? How many of this worm’s enablers are still common IT practice? The worm generated so much traffic, so quickly, that some sites had to turn off their e-mail servers. Melissa spread without user action by exploiting convenience features. Seven years later, we’re only beginning to rein in that syndrome—an effort that requires eternal vigilance. It’s a cute list, as with all “Top X” lists people will agree and disagree with parts of them. Perhaps most interesting is that five out of the twelve are directly related to security and privacy. Perhaps it is time for a “top[…]

I’m a little terrified about how easy it was to get a new key for my hotel room today. Came back from a long day of work, with dinner in a bag and laptop on my back. Walked to my hotel room, and the key didn’t work. I grabbed a nearby house phone, called the front desk, and explained that I wasn’t 100% sure about my room number, but I thought my key wasn’t working. I gave her my name, and she confirmed my room number. I said I’d try the key again, and if it didn’t work I’d come down. Came down, there was a key waiting for me. I handed her the broken one, she handed me the[…]

‘Phishing’ scams on the rise, survey finds. Next I expect to see an article about how water is still wet. Over 157,000 unique phishing messages were sent out around the world in the first half of 2006, an increase of 81 percent compared with the six-month period to end-December 2005…. according to the bi-annual Internet Security Threat Report from security software vendor Symantec. I guess Symantec has to do something to drum up business. After all, they’ve already warned customers will have a hard time getting their software security to work with Windows Vista thanks to Vista’s enhanced Security Center and PatchGuard features.

Wireless communications have been used on the battlefield since the first world war and are critical for staying in touch with deployments near and far. Word today is that Hezbollah hacked Israeli communications during the battles in Israel and Lebanon in August 2006. Using technology most likely supplied by Iran, special Hezbollah teams monitored the constantly changing radio frequencies of Israeli troops on the ground. That gave guerrillas a picture of Israeli movements, casualty reports and supply routes. It also allowed Hezbollah anti-tank units to more effectively target advancing Israeli armor, according to the officials. My guess is that they weren’t able to decipher the communications at all; Israel is host to some of the top cryptographic minds and companies.[…]