Verkställandet av dödsdomen mot Kimberly McCarthy, som i dag hade blivit den första kvinna att avrättas i USA sedan 2010, har skjutits upp till april, meddelar hennes advokat.
redletterdave writes "Mozilla announced on Tuesday that it has been named the 'Most Trusted Internet Company For Privacy' in 2012, according to a new independent study released by the Ponemon Institute early this morning (PDF). Ponemon Institute surveyed more than 100,000 adult-aged consumers over a 15-week period ending in December 2012; of the 6,704 respondents, representing 25 different industries, Mozilla was ranked the top Internet and social media company. While this is a great achievement for Mozilla, especially considering this was their first year making the list, Mozilla's team took note of the fact that 'Internet and social media' was still the least trustworthy sector out of the 25 total industries listed. 'It means we as an industry all have a lot more work to do,' Mozilla wrote on its blog."
Read more of this story at Slashdot.




Senatorn och Vietnamveteranen John Kerry har fått tillräckligt många röster i senaten för att bli USA:s nye utrikesminister.
Kan namnge alla länder och förklara hur inre organ fungerar.
Lakhdar Brahimi, FN:s Syriensändebud, sade i dag till FN:s säkerhetsråd att president al-Assad för tillfället håller sig kvar vid makten, men att landet håller på att ”brytas upp inför allas ögon”, enligt diplomatkällor.
”Migrationsministern för passiv”.
pigrabbitbear writes "It's been nearly a decade since Shin Dong-hyuk, an ex-prisoner of North Korea's Camp 14, crawled over the electrocuted body of a friend lying dead on a fence, a boundary he was born inside of and lived within for 23 years. He made his way across the Chinese border on foot and was granted political asylum and citizenship in Seoul. Now, thanks to updated Google maps of the region, you can actually (if somewhat loosely) retrace the steps of his incredible escape. Through its Map Maker program, which crowdsources cartographic info, Google has published finer details of some North Korean roads. More notably, it has included shaded-in locations of the country's notorious prison camps. The data has flowed in from a few different sources, including defected North Korean expats now living in Seoul. Geographically-minded tourists and visitors of North Korea have weighed in, and historic map data from pre-partitioned Korea into has also been helpful. (Google maintains that the recent trip to Pyongyang by CEO Eric Schmidt had nothing to do with this project.)"
Read more of this story at Slashdot.




This was a quote from a recent conference call hosted by Oracle (details on the call are here http://www.scmagazine.com/oracle-speaks-promises-to-get-java-fixed-up/article/277898/ ) In that call, Oracles full quoted statement is The plan for Java security is really simple, its to get Java fixed up, number one, and then, number two, to communicate our efforts widely. We really cant have one without the other.
This sounds very positive, right? With Java 6 rolling into unsupported status soon, and real problems (and no emphatic fix in sight) in Java 7, this sounds like good news for folks who need Java day-to-day, in support real business functions.
Ummm - not so much for me. personal opinion follows They make it sound like this might be something they can do in a couple of weeks, and fix with a service pack or a version update. When Microsoft was in a similar situation, they shut down development completely and re-tooled their methodology. I think Oracle is in a similar situation right now, but arent coming clean like Microsoft did back in the day (2002 - it doesnt seem that long ago to me ...)
While the current round of vulnerabilties in Java can certainly be resolved in the current framework, I think that if they dont retool their Development, Test and QA methodologies to place a higher emphasis on Security in the final product, well be having this same discussion again and again.
Putting a change freeze in for new features would be another excellent thing to do. Given recent events, freezing dev for an audit and security effort is likely a really good idea. I get the impression that in the race for new features, theres a significant technical debt on the security side that is coming home to roost.
I think that Oracle, and a few others while were discussing it, need to take a close look at what Microsoft did those few short years ago, and make some big changes on how things get written and rolled out.
Again, just my opinion. Feel free to set me straight (or even agree with me) in our comment form.
===============
Rob VandenBrink
Metafore
(c) SANS Internet Storm Center. http://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.
”Vissa var tonåringar. Flera vara bakbundna”.
Skärper konflikten om försvaret.