Featured articles
Archive
Category: Security
President Signs the U.S. Consumer Privacy Bill of Rights
On February 23, 2012 U.S. time, President Barack Obama signed the administration white paper “Consumer Data Privacy in a Networked World”. The paper sets out a “Consumer Privacy Bi…
Standardization of JSON Web Signature (JWS) Has Begun at the IETF
Standardization of JSON Web Signature, a standard for attaching signatures to JSON, has begun in the IETF JOSE Working Group[1]. The initial draft is: http://tools.ietf.org/html/dr…
Using Plain OAuth 2.0 for Authentication Opens a Security Hole Big Enough to Drive a Car Through
Using the OAuth 2.0 implicit grant flow for authentication opens a security hole big enough to drive a car through, as explained in this excellent article by John Bradley[1]. The c…
A Christmas Present from the OpenID Foundation
And so, here is a Christmas present for everyone from the OpenID AB+Connect WG. As of today, the OpenID Connect specifications have entered an Implementer’s Draft review peri…
The sp-mode Mail Problem
The sp-mode mail problem—the one in which email addresses were switched—has become a hot topic. I could not fully understand it just by reading the articles, so I drew a diagram wh…
Trust Frameworks in Cyberspace and the Personal Data Economy: University of Tokyo Special Lecture on Applied Computer Science II (2011/12/07)
Today I delivered the University of Tokyo’s Special Lecture on Applied Computer Science II, entitled: “Trust Frameworks in Cyberspace and the Personal Data Economy: From the…
The Sensational Article “Successfully Stole PC Data—Is VISTA Security Up to the Task?”
This article has a very provocative title, but there is really nothing remarkable about it. The story is that a Windows XP PC broke, so its hard drive was removed and connected to…
How to Break Encryption and Security Policy
This June, it made major news that “DES was broken in only 3 and a half days.” Its significance lies in actually demonstrating something already understood in principle…

You must be logged in to post a comment.