In the light of the jolly good rave: "REA, Triple-Entry Accounting and Blockchain: Converging Paths to Shared Ledger Systems" by Iba�ez et al, just out recently, I've been thinking of the relationship between TEA or triple entry accounting and the accounting-led analogue of REA or Resource-Entity-Agent. From my tech point of view, and my prior ignorance as not actually knowing about it until…
Tweet thread: This is a great research attack on a SWIFT-using payment institution (likely a British bank allowing the research to be conducted) from Oliver Simonnet. But I was struck by how the architectural flaw leapt out and screamed HIT ME HERE! 1/17 @mikko We were able to demonstrate a proof-of-concept for a fraudulent SWIFT payment message to move money. This was done by manually forging a…
Watching an argument (I started) (on the Internet) about Apple dropping iCloud encryption (allegedly) reminded me of how hard it is to get security & privacy right. What had actually happened was that Apple had made it possible for you to back up securely to iCloud and leave a key there, so if you got locked out, Apple could help you get your access back. Usability to the fore! But some were…
Way back in the 1980s, Yuji Ijiri came up with the idea of momentum accounting, which he also called triple entry bookeeping. This is a distinct idea to the triple entry we typically talk about in our circles, and indeed pre-dates the work of Todd Boyle, Gary Howland and myself. The collision in names was unfortunate and unintended, I only found out about Ijiri's idea when someone pointed me to it…
Danny Nelson Coindesk Two members of the prolific Romanian hacker gang Bayrob Group were sentenced to two decades in U.S. prison apiece after their malware mined crypto on 400,000 infected computers. Group leader Bogdan Nicolescu and co-conspirator Radu Miclaus were sentenced to 20 and 18 years respectively after being found guilty on 21 different counts of wire fraud, money laundering aggravated…
A post on Matthew Green's blog highlights that Snowden revelations helped the push for HTTPS everywhere. Firefox also has a similar result, indicating a web-wide world result of 80%. (It should be noted that google's decision to reward HTTPS users by prioritising it in search results probably helped more than anything, but before you jump for joy at this new-found love for security socialism, note…
@lochaiching reminds me that I made a 2 x 2 matrix of the 4 competing Types of Identity: To be read with the earlier piece "4 Types of Identity". This is just a thought experiment to see if there are alignments between the different schools. Thoughts?...
"Access to Cash Review" confirms much that we have been warning of as UK walks into its future financial gridlock. From WolfStreet: Transition to Cashless Society Could Lead to Financial Exclusion and System Vulnerability, Study Warns by Don Quijones � Mar 14, 2019 �Serious risks of sleepwalking into a cashless society before we�re ready � not just to individuals, but to society.� Ten years ago,…
From the annals of web research: A thriving marketplace for SSL and TLS certificates...exists on a hidden part of the Internet, according to new research by Georgia State University's Evidence-Based Cybersecurity Research Group (EBCS) and the University of Surrey. .... When these certificates are sold on the darknet, they are packaged with a wide range of crimeware that delivers machine identities…
In the video I did a few years ago, I explored 4 notions of Identity. These have seemed to survive some scrutiny, a little test of time. It appears a bit easier to call them by labels, but words can be too political. NB: now in Chinese: . How about numbers? There are four Types of Identity. They are: Type 1 - your State ID The state is the one that started the concept of identity as a national…
None of us love terrorists. A few of us study and admire warfare and revolutionary spirit and history and daring battles, but that doesn't match actual facts on the ground. War is 1% heroism and 99% death, destruction, scorched earth for causes nobody can remember. Terrorists are 100% ruthless killers that will stop at nothing. This however does not mean that we as a society should change our…
Finally, an actual financial system & terrorism case lands before the courts, relating to the Dusit attack. Is this a world first? I don't know because this conjunction is so rare, nobody's tracking it. The essential gripe is that since 9/11 the financial world decided to slap the terrorism label on their compliance process. Yet to no avail. Very few cases, so small that they fall between bayesian…
7 years after we called the cancer that is criminal activity in Bitcoin-like cryptocurrencies, here comes a report that suggests that 4.3% of Monero mining is siphoned off by criminals. A First Look at the Crypto-Mining MalwareEcosystem: A Decade of Unrestricted Wealth Sergio PastranaUniversidad Carlos III de Madrid*spastran@inf.uc3m.esGuillermo Suarez-TangilKing�s College…
Writes Andreas Antonopolous, a noted Bitcoin commentator, that he has been impersonated with a mere scan! More than anything else this points at the fallacy of Identity Documents as the God of our Identity. AA may very well be a victim of our penultimate post on cheap-as-chips scans of your identity. What's becoming clear is that identity is garnering more attention. Unwittingly, orgs and peoples…
So says NIST... 10 years ago I annoyed the entire crypto-supply industry: Hypothesis #1 -- The One True Cipher Suite In cryptoplumbing, the gravest choices are apparently on the nature of the cipher suite. To include latest fad algo or not? Instead, I offer you a simple solution. Don't. There is one cipher suite, and it is numbered Number 1. Cypersuite #1 is always negotiated as Number 1 in the…