Trust is the hard part

Identity and security are not features to bolt on but the core problem — build trust in from first principles and be open about where it can break.

The Geeks Guide to Currencies: Trust and Promises

Published

Trust is probably the most fundamental property that money should have (but doesn’t always have). You need to be able to trust: that my money does not lose value that I can exchange it again This article is mainly about the trust of currencies without intrinsic value. A currency with intrinsic value is something like a …

How OAuth beat Chip and Pin

Published

2 news stories on the same day are quite interesting in their contrast. Pin and Chip is broken The first one has the collective might and minds of the European banking system and their suppliers who overlooked a slight issue in their authentication protocol for authenticating Chip cards with a pin number. In Europe …

The truth about identity (part 2 - Web 2.0 Apps)

Published

Surely we should understand these identity technologies for our new hot web 2.0 app. This is most likely something you have thought if you have a web application. The easy counter statement I would like to give you is don’t you already maintain the required identity for your application? This post is the second part of …

The truth about identity (part 1 - for bloggers)

Published

Identity is one of those things that technologists like to solve, and solve, and solve. The reason they keep solving it is that they don’t really go deep and analyse what identity is and what they are trying to solve. Oh, when saying they I should really say we as I’ve tried to reinvent the wheel as well. So we keep …

Spam blocking and Free Speech

Published

Talk.org is all about free speech. But after a few bouts of spam attacks and a bit of adolescent sausage fumbling I need to figure out where to draw the line between censorship and spam blocking. Believe me it is a very thin line. Do I search for bad words? If someone wants to talk anonymously about the benefits of …

Good example of how to deal with security

Published

I use the EasySpeedy for my hosting. They already provide the most transparent hosting plans and hosting contract I have seen, but they continue to impress me. I’ve got 2 servers there and will put my 3rd one there if need be. Apparently one of their clients where spamming with spoofed IP addresses from other …

$5M for fraud proof mobile credit card authorization?

Published

In Business 2.0 John Occhipinti from the Woodside fund wants to pay $5M in venture capital for a fraudproof credit card authorization via cell phones and PDAs. I found this via Nathan’s hilarious Odio.us Elevator Pitch generator. Lets first look at why John wants this from us: Credit card fraud is more rampant than …

If I was to create a new payment system...

Published

There is a lot of buzz going on right now about payment systems. First with the huge credit card theft which was seriously just waiting to happen (and will happen again), secondly with Google’s new Payment System which could have the potential to be interesting. This subject is dear to me as I have spent more than my …

Open security disclosure

Published

I have always been interested in security and cryptography and have always been annoyed with the security disclosures or lack of them that most web applications offer. Therefore I am making StakeItOut’s Security Page painfully public for the world to see. I think it is better for small fish like me to be honest and not …