FUD Watch: Patch Tuesday Panic? No Thanks
Are security vendors right to bang the alarm bell every Patch Tuesday? Yes. But only to a point.
Read more
Microsoft warns: Get ready for IE 8
Mary Jo Foley: Microsoft is cautioning Web site owners now that they need to be prepping now for possible problems the new, more standards-compliant browser may cause.
Mary Jo Foley: Microsoft caves: 'Super-standards' mode to become IE 8 default
The 16 TB RAM PC: When?
Robin Harris: The next version of Mac OS X will address 16 TB of RAM. Who will ever have 16 TB--16,000 GB--of RAM on a home computer? If the past is any guide, it might be a while.
Will The RIAA Sue Judge Kozinski For Sharing MP3s?
from the just-wondering dept
While judge Alex Kozinski is getting a ton of press for accidentally sharing pornographic images from his webserver, Justin Levine notes that the report concerning what was on the server also found music MP3s from musicians like Johnny Cash, Bob Dylan and Weird Al Yankovic. Levine wonders if the RIAA will now sue this federal judge as well. In fact, things could get tricky in that some research suggests not only was Kozinski storing MP3s, he may have actively been sharing some of those MP3s as well. That same link mentions that in one of many copyright infringement lawsuits concerning the company Perfect 10, Kozinski wrote a dissenting opinion suggesting that facilitating copyright infringement should be seen as infringement as well:
Do You Need To Schedule Your Technology Down Time?
from the shut-down-and-go-outside dept
One of the best decisions I made when I first start blogging on Techdirt oh-so-many-years ago, was that I wouldn't blog on weekends. While it wasn't on purpose, it's worked out nicely as it gives me plenty of time on weekends to disconnect and do other stuff. I've found (surprising to some, I'm sure) that it's not at all difficult for me to pretty much ignore my computer for the weekend if I need to. And, then, there are some weekends where I do end up using the computer, either for fun or to catch up on some work-related things. However, I never considered setting up an official "schedule" of tech down time. Yet, Mark Glaser, over at MediaShift notes that a growing number of people are setting aside "tech sabbaths" to force themselves to disconnect.
Even Lawyers Are Confused About What's Legal Or Not In The Prince/Radiohead Spat
UK Police Accused Of Violating Copyright By Listening To Music In Police Stations
from the keep-quiet dept
While we've seen performing rights groups like ASCAP be overly aggressive in trying to collect money from anyone holding a "performance" of music, it seems that the UK's "Performing Right Society" (PRS) is pushing the boundaries even more. This is the same group that we noted last year had sued a bunch of auto mechanics for listening to radios in their garages loud enough that customers in the waiting room could hear them. Yes, the PRS insisted that this required a performance license.
Job-Hunter Forged SEC Letter, Feds Say
MANHATTAN (CN) - A man trying to get hired as CFO of an international company has been charged with forging a letter on SEC letterhead, claiming to be from an SEC attorney, recommending him for the $300,000 job.
Report: Data breaches, stolen data, organized crime rampant
Chuck Miller June 12, 2008
A new report from Verizon Business Security Solutions shows that there is an escalating worldwide black market for stolen data.
Congressmen allege China-based PC hackings
Dan Kaplan June 11, 2008
Two lawmakers said on Wednesday that their office computers were infiltrated by hackers operating out of China.
British Hacker Faces Extradition Hearing Next WeekPC World - Fri Jun 13, 6:00 AM ET
A British hacker fighting extradition to the U.S. on charges of computer hacking is preparing for his final U.K. appeal on...
EU states extend life of Internet security body Reuters - Thu Jun 12, 10:28 AM ET
LUXEMBOURG (Reuters) - European Union telecoms ministers agreed on Thursday to extend the life of the bloc's Internet security watchdog by three years as threats to the Web increase.
Japan and France Agree to Closer Ties on Cybercrime PC World - Thu Jun 12, 5:20 AM ET
Japanese and French government ministers agreed at a meeting in Tokyo on Thursday to work more closely on cybercrime.
38,000 Credit Card Numbers Stolen From The Cotton Traders Website By Hackers By Grey McKenzie Today
Uniloc’s Top Ten Rules for Combating Cyber Attacks on Critical Infrastructure By Grey McKenzie Today
Cyber-Dissident Huang Qi kidnapped & Foreign Journalists Arrested In Sichuan By Grey McKenzie Today
United States Cyber Security Policy Frustrating & Dysfunctional Says Former DHS Official By Grey McKenzie Yesterday
NVD Primary Resources
Vulnerability Search Engine (CVE software flaws and CCE misconfigurations)
National Checklist Program (automatable security configuration guidance in XCCDF and OVAL)
ISAP/SCAP (program and protocol that NVD supports)
SCAP Compatible Tools
SCAP Data Feeds (CVE, CCE, CPE, CVSS, XCCDF, OVAL)
Product Dictionary (CPE)
Impact Metrics (CVSS)
Common Weakness Enumeration (CWE)
"Differences in the type of memory and I/O controllers used in USB drives can make one device perform two or three times faster and last 10 times longer than another, even if both sport the USB 2.0 logo, according to a Computerworld story. While a slow USB drive may be fine for moving a few dozen megabytes of files around, when you get into larger data transfers, that's when bandwidth contrictions become noticeable. In 2009, controller manufacturers are expected to begin shipping drives with dual- and even four-channel controllers, which will increase speeds even for slower drives."
Top 5 Security Reasons to Use Windows Vista
by Derek Melber
Articles / Windows OS Security
The top 5 security based reasons to move to Windows Vista for all users in the environment. The reasons are valid and very reasonable.
Study: consumers lust after high-speed broadband, not HDTV
Top Secret Al Qaeda Documents Left on London Train
Oops. At least they were found and returned.
Keith Vaz MP, chairman of the powerful Home Affairs select committee told the BBC: "Such confidential documents should be locked away...they should not be read on trains."
You think?
Malware Silently Alters Wireless Router Settings
http://blogs.washingtonpost.com/securityfix/
A new Trojan horse masquerading as a video "codec" required to view content on certain Web sites tries to change key settings on the victim's Internet router so that all of the victim's Web traffic is routed through servers controlled by the attackers.
http://www.routerpasswords.com/ has all the manufacturer's default passwords.
The 2008 Olympics and Your Privacy
Businesses and federal officials are being warned that attendance at the 2008 Olympics will likely put data on laptops and e-mail devices at risk. Chinese intelligence services may actively work to breach data devices in search of secrets, install surveillance technology, and access secure networks.
Olympic visitors' data is at risk, USA Today, June 10, 2008
Posted by EPIC on June 12, 2008.Permanent link to this item.
Verizon Study Links External Hacks to Internal Mistakes - 6/12/2008 10:50:00 AM Most breaches come from outside the company, but they are often triggered by unfound errors on the inside
Danish filter catches Romanian child-porn sites
Experts: Spyware legislation needs more work
ACLU files lawsuit on behalf of Virginia privacy advocate
Friday, June 13, 2008
Wednesday, June 11, 2008
Wednesday News Feed 6/11/08
Out of cycle patch here:
Internet Explorer "substringData()" Memory Corruption Vulnerability - Highly critical - From remoteIssued 1 day ago. Updated 11 hours ago.
A vulnerability has been reported in Internet Explorer, which can be exploited by malicious people to compromise a user's system.
OpenOffice 2.4.1 Out - Fixes One Vuln
CitectSCADA Buffer Overflow Vulnerability
If you don't know what SCADA systems are then read this and change your underwear...
The TSA has a new photo ID requirement:
Beginning Saturday, June 21, 2008 passengers that willfully refuse to provide identification at security checkpoint will be denied access to the secure area of airports. This change will apply exclusively to individuals that simply refuse to provide any identification or assist transportation security officers in ascertaining their identity.
This new procedure will not affect passengers that may have misplaced, lost or otherwise do not have ID but are cooperative with officers. Cooperative passengers without ID may be subjected to additional screening protocols, including enhanced physical screening, enhanced carry-on and/or checked baggage screening, interviews with behavior detection or law enforcement officers and other measures.
That's right; people who refuse to show ID on principle will not be allowed to fly, but people who claim to have lost their ID will. I feel well-protected against terrorists who can't lie.
I don't think any further proof is needed that the ID requirement has nothing to do with security, and everything to do with control.
Apple QuickTime Multiple Vulnerabilities - Highly critical - From remote
Issued 2 days ago. Updated 8 hours ago.
Some vulnerabilities have been reported in Apple QuickTime, which can be exploited by malicious people to compromise a user's system.
Boycott spotlights antivirus testing issues Robert Lemos, 2008-06-09 Security firm Trend Micro refuses to apply for future VB100 certifications, highlighting a debate over how to best test antivirus software.
Safari flaw enables Windows attack
"Google largely conquered the Earth — now it is taking aim at space. At least co-founder Sergei Brin is. Brin today said he put down $5 million toward a flight to the International Space Station in 2011. Brin's space travel will be brokered by Space Adventures, the space outfit that sent billionaire software developer Charles Simonyi to the station in 2007. Computer game developer (and son of a former NASA astronaut) Richard Garriott is currently planning a mission to the ISS in October 2008. Garriott is paying at least $30 million to launch toward the space station aboard a Russian Soyuz spaceship according to Space Adventures."
"Researchers at Ohio State University and the University of California, Irvine conducted a telephone study by randomly surveying individuals employed full-time who use computers in an office environment at least five hours per week. They netted 912 respondents, of which 29.8 percent claimed to use IM in the workplace 'to keep connected with coworkers and clients.' Neither occupation, education, gender, nor age seem to have an impact on whether an individual is an IM user or not. The study theorizes that using IM enables individuals to 'flag their availability.' Doing so can limit when IM interruptions occur. Even if an IM interruption comes when it is not necessarily convenient to the recipient, it is 'often socially acceptable' to ignore an incoming message or respond with a terse reply stating that the recipient is too busy at the moment to properly respond."
Also another study recently found that water is wet, and a third study found that most studies waste money.
Overview of the Windows Server 2008 Firewall with Advanced Security Part 2: Inbound and Outbound Firewall Rules
by Thomas Shinder
Articles / Firewalls & VPNs
The inbound and outbound firewall rules that you can create to control incoming and outgoing connections to and from the Windows Server 2008 computer.
Dancho Danchev: Fake ImageShack site serving malware, links distributed over IM
Father's Day gifts for gadget freaks
Openoffice vs Microsoft Office
Microsoft has applied for a patent on a system for "device manner policy" (DMP). Basically, such a DMP system would restrict the use of certain features in certain locations. So, for example, a mobile phone that has the DMP technology might not be able to ring in a movie theater, but would instead shift to vibrate.
WILMINGTON, DEL. (CN) - LandSource Communities Development, whose assets include the 15,000-acre Newhall Land and Farming Co. north of Los Angeles, have filed for bankruptcy, listing more than $1 billion in debts. The California Public Employees' Retirement System, or CalPERS, owns 68% of LandSource; Lennar Corp. and Cerberus Capital Management's LNR Property each own 16% of it, Reuters reported.
This is not a phishing site. Now, be a good victim and enter your login credentials in the form!
Kaiser Permanente partners with Microsoft on health records
Sue Marquette Poremba June 10, 2008
Kaiser Permanente and Microsoft are partnering on a new pilot program to provide patients with better access to their medical records.
Faster, cheaper iPhone portends IT security headaches
Jim Carr June 09, 2008
While the throngs are going crazy about the new iPhone's lower cost and faster download speeds, IT professionals are gearing up for more security headaches from the Apple's latest smart phone.
Tuesday, June 10, 2008 11:52 AM
MS08-036: PGM? What is PGM?
This morning we released MS08-036 to fix two denial-of-service vulnerabilities in the Windows implementation of the Pragmatic General Multicast (PGM) protocol (RFC 3208). You probably have never heard of PGM. Only one engineer on our team had ever heard of it and he previously worked as a tester on the core network components team. PGM is a multicast transport protocol that guarantees reliable delivery from multiple sources to multiple receivers. It is a layer 4 transport protocol, peer to TCP and UDP.
Secret Spy Court Repeatedly Questions FBI Eavesdropping Network
Tech Problem Stumps Yahoo, Forces Mail Features RollbackPC World - Tue Jun 10, 9:10 PM ET
Yahoo is rolling back security and anti-spam enhancements to its Webmail service because they interfered with users' ability...
Hacker Pleads Guilty to Attacking Anti-phishing Group PC World - Tue Jun 10, 7:00 PM ET
A California hacker pleaded guilty to launching a computer attack last year that almost knocked the Castlecops anti-phishing...
10 Tips To Keep Your Kids Safe Online By Grey McKenzie Today
Russian Drug Maker GlavMed Teams Up With Spammers To Make Millions By Grey McKenzie Today
Canadian Law Enforcement Partners With Microsoft To Deal With Cyber Security By Grey McKenzie Today
Electronic Audit Trails From 259,761 High-Risk Consumers Prove Consumer Participation Can Virtually Eliminate New Account Fraud By Grey McKenzie Yesterday
FBI Charges Blind Phone Phreak With Intimidating a Verizon Security Official By Grey McKenzie Yesterday
Police Routinely Gain Access to Cellphone Information
Law enforcement rarely have trouble gaining access to cellphone information from service providers. If the request for information comes within the cellphone service providers retention period then it is often shared with police.
Law Enforcement Use of Cell Info Raises New Privacy Concerns, Heartland Institute, (June 8, 2008)
Cellphone Users' Locations Tracked by Study
A study that used data on 100,000 cellphone users' locations was published in "Nature." The study found that 75% of those tracked remained within a 20-mile radius of their home. Participation in the study was nonconsensual. The research involved information provided by cellphone service providers on its users. Similar tracking of US cellphone customers is technically possible be illegal without the user's permission.
Study tracking people via cell phone raises privacy issues, CNet News.com, June 5, 2008
Researchers Link Storm Botnet to Illegal Pharmaceutical Sales - 6/11/2008 10:10:00 AM Prescription drug spammers are bankrolling botnet's growth, IronPort study says
Major Security Vendors' Sites Could Be Launchpads for Phishing Attacks - 6/10/2008 10:45:00 AM McAfee, Symantec, and VeriSign sites all found to contain cross-site scripting flaws
Safari 'carpet bomb' attack code released
Microsoft hires antiphishing crusader
June 10, 2008 (IDG News Service) Microsoft Corp. has hired Paul Laudanski, the man behind the antiphishing CastleCops.com Web site, to help with the software company's phishing and spam investigations.
Laudanski, a former volunteer firefighter, announced the move on CastleCops.com last week, saying that he's looking to find someone else to run the site that he founded in 2002.
With his new job at Microsoft, he simply doesn't have time to keep up with the CastleCops work, he said in an interview on Tuesday. "I won't be able to ensure the same kind of support that I was able to provide in the past," he said. "I won't be able to do it justice."
CastleCops had been a full-time job for Laudanski and his wife, Robin, since 2005.
At Microsoft, he will work as an Internet safety investigator for Microsoft's live consumer services group. Microsoft has a large Internet safety enforcement team that works with law enforcement to fight spam, viruses, botnets, typo-squatting and even child pornography on the Internet.
At CastleCops, Laudanski managed a team of about 120 volunteers who processed user-submitted spam, phishing and malicious code reports. The group worked as a clearinghouse for complaints and was often active in taking down malicious Web sites and servers. On a typical day, it processes about 1,000 phishing attempts, Laudanski said.
CastleCops clearly has the attention of the bad guys.
Last year, it was attacked by Gregory King, a 21-year-old hacker who operated a botnet network of 7,000 hacked computers. On Tuesday, King pleaded guilty to attacking CastleCops with a distributed denial-of-service attack and is facing a two-year prison sentence.
Internet Explorer "substringData()" Memory Corruption Vulnerability - Highly critical - From remoteIssued 1 day ago. Updated 11 hours ago.
A vulnerability has been reported in Internet Explorer, which can be exploited by malicious people to compromise a user's system.
OpenOffice 2.4.1 Out - Fixes One Vuln
CitectSCADA Buffer Overflow Vulnerability
If you don't know what SCADA systems are then read this and change your underwear...
The TSA has a new photo ID requirement:
Beginning Saturday, June 21, 2008 passengers that willfully refuse to provide identification at security checkpoint will be denied access to the secure area of airports. This change will apply exclusively to individuals that simply refuse to provide any identification or assist transportation security officers in ascertaining their identity.
This new procedure will not affect passengers that may have misplaced, lost or otherwise do not have ID but are cooperative with officers. Cooperative passengers without ID may be subjected to additional screening protocols, including enhanced physical screening, enhanced carry-on and/or checked baggage screening, interviews with behavior detection or law enforcement officers and other measures.
That's right; people who refuse to show ID on principle will not be allowed to fly, but people who claim to have lost their ID will. I feel well-protected against terrorists who can't lie.
I don't think any further proof is needed that the ID requirement has nothing to do with security, and everything to do with control.
Apple QuickTime Multiple Vulnerabilities - Highly critical - From remote
Issued 2 days ago. Updated 8 hours ago.
Some vulnerabilities have been reported in Apple QuickTime, which can be exploited by malicious people to compromise a user's system.
Boycott spotlights antivirus testing issues Robert Lemos, 2008-06-09 Security firm Trend Micro refuses to apply for future VB100 certifications, highlighting a debate over how to best test antivirus software.
Safari flaw enables Windows attack
"Google largely conquered the Earth — now it is taking aim at space. At least co-founder Sergei Brin is. Brin today said he put down $5 million toward a flight to the International Space Station in 2011. Brin's space travel will be brokered by Space Adventures, the space outfit that sent billionaire software developer Charles Simonyi to the station in 2007. Computer game developer (and son of a former NASA astronaut) Richard Garriott is currently planning a mission to the ISS in October 2008. Garriott is paying at least $30 million to launch toward the space station aboard a Russian Soyuz spaceship according to Space Adventures."
"Researchers at Ohio State University and the University of California, Irvine conducted a telephone study by randomly surveying individuals employed full-time who use computers in an office environment at least five hours per week. They netted 912 respondents, of which 29.8 percent claimed to use IM in the workplace 'to keep connected with coworkers and clients.' Neither occupation, education, gender, nor age seem to have an impact on whether an individual is an IM user or not. The study theorizes that using IM enables individuals to 'flag their availability.' Doing so can limit when IM interruptions occur. Even if an IM interruption comes when it is not necessarily convenient to the recipient, it is 'often socially acceptable' to ignore an incoming message or respond with a terse reply stating that the recipient is too busy at the moment to properly respond."
Also another study recently found that water is wet, and a third study found that most studies waste money.
Overview of the Windows Server 2008 Firewall with Advanced Security Part 2: Inbound and Outbound Firewall Rules
by Thomas Shinder
Articles / Firewalls & VPNs
The inbound and outbound firewall rules that you can create to control incoming and outgoing connections to and from the Windows Server 2008 computer.
Dancho Danchev: Fake ImageShack site serving malware, links distributed over IM
Father's Day gifts for gadget freaks
Openoffice vs Microsoft Office
Microsoft has applied for a patent on a system for "device manner policy" (DMP). Basically, such a DMP system would restrict the use of certain features in certain locations. So, for example, a mobile phone that has the DMP technology might not be able to ring in a movie theater, but would instead shift to vibrate.
WILMINGTON, DEL. (CN) - LandSource Communities Development, whose assets include the 15,000-acre Newhall Land and Farming Co. north of Los Angeles, have filed for bankruptcy, listing more than $1 billion in debts. The California Public Employees' Retirement System, or CalPERS, owns 68% of LandSource; Lennar Corp. and Cerberus Capital Management's LNR Property each own 16% of it, Reuters reported.
This is not a phishing site. Now, be a good victim and enter your login credentials in the form!
Kaiser Permanente partners with Microsoft on health records
Sue Marquette Poremba June 10, 2008
Kaiser Permanente and Microsoft are partnering on a new pilot program to provide patients with better access to their medical records.
Faster, cheaper iPhone portends IT security headaches
Jim Carr June 09, 2008
While the throngs are going crazy about the new iPhone's lower cost and faster download speeds, IT professionals are gearing up for more security headaches from the Apple's latest smart phone.
Tuesday, June 10, 2008 11:52 AM
MS08-036: PGM? What is PGM?
This morning we released MS08-036 to fix two denial-of-service vulnerabilities in the Windows implementation of the Pragmatic General Multicast (PGM) protocol (RFC 3208). You probably have never heard of PGM. Only one engineer on our team had ever heard of it and he previously worked as a tester on the core network components team. PGM is a multicast transport protocol that guarantees reliable delivery from multiple sources to multiple receivers. It is a layer 4 transport protocol, peer to TCP and UDP.
Secret Spy Court Repeatedly Questions FBI Eavesdropping Network
Tech Problem Stumps Yahoo, Forces Mail Features RollbackPC World - Tue Jun 10, 9:10 PM ET
Yahoo is rolling back security and anti-spam enhancements to its Webmail service because they interfered with users' ability...
Hacker Pleads Guilty to Attacking Anti-phishing Group PC World - Tue Jun 10, 7:00 PM ET
A California hacker pleaded guilty to launching a computer attack last year that almost knocked the Castlecops anti-phishing...
10 Tips To Keep Your Kids Safe Online By Grey McKenzie Today
Russian Drug Maker GlavMed Teams Up With Spammers To Make Millions By Grey McKenzie Today
Canadian Law Enforcement Partners With Microsoft To Deal With Cyber Security By Grey McKenzie Today
Electronic Audit Trails From 259,761 High-Risk Consumers Prove Consumer Participation Can Virtually Eliminate New Account Fraud By Grey McKenzie Yesterday
FBI Charges Blind Phone Phreak With Intimidating a Verizon Security Official By Grey McKenzie Yesterday
Police Routinely Gain Access to Cellphone Information
Law enforcement rarely have trouble gaining access to cellphone information from service providers. If the request for information comes within the cellphone service providers retention period then it is often shared with police.
Law Enforcement Use of Cell Info Raises New Privacy Concerns, Heartland Institute, (June 8, 2008)
Cellphone Users' Locations Tracked by Study
A study that used data on 100,000 cellphone users' locations was published in "Nature." The study found that 75% of those tracked remained within a 20-mile radius of their home. Participation in the study was nonconsensual. The research involved information provided by cellphone service providers on its users. Similar tracking of US cellphone customers is technically possible be illegal without the user's permission.
Study tracking people via cell phone raises privacy issues, CNet News.com, June 5, 2008
Researchers Link Storm Botnet to Illegal Pharmaceutical Sales - 6/11/2008 10:10:00 AM Prescription drug spammers are bankrolling botnet's growth, IronPort study says
Major Security Vendors' Sites Could Be Launchpads for Phishing Attacks - 6/10/2008 10:45:00 AM McAfee, Symantec, and VeriSign sites all found to contain cross-site scripting flaws
Safari 'carpet bomb' attack code released
Microsoft hires antiphishing crusader
June 10, 2008 (IDG News Service) Microsoft Corp. has hired Paul Laudanski, the man behind the antiphishing CastleCops.com Web site, to help with the software company's phishing and spam investigations.
Laudanski, a former volunteer firefighter, announced the move on CastleCops.com last week, saying that he's looking to find someone else to run the site that he founded in 2002.
With his new job at Microsoft, he simply doesn't have time to keep up with the CastleCops work, he said in an interview on Tuesday. "I won't be able to ensure the same kind of support that I was able to provide in the past," he said. "I won't be able to do it justice."
CastleCops had been a full-time job for Laudanski and his wife, Robin, since 2005.
At Microsoft, he will work as an Internet safety investigator for Microsoft's live consumer services group. Microsoft has a large Internet safety enforcement team that works with law enforcement to fight spam, viruses, botnets, typo-squatting and even child pornography on the Internet.
At CastleCops, Laudanski managed a team of about 120 volunteers who processed user-submitted spam, phishing and malicious code reports. The group worked as a clearinghouse for complaints and was often active in taking down malicious Web sites and servers. On a typical day, it processes about 1,000 phishing attempts, Laudanski said.
CastleCops clearly has the attention of the bad guys.
Last year, it was attacked by Gregory King, a 21-year-old hacker who operated a botnet network of 7,000 hacked computers. On Tuesday, King pleaded guilty to attacking CastleCops with a distributed denial-of-service attack and is facing a two-year prison sentence.
Tuesday, June 10, 2008
Tuesday News Feed 06/10/08
Internet companies to block child porn sites
Providers also will pay to help remove child porn from the Web
http://www.msnbc.msn.com/id/25077224/
ALBANY, N.Y. - Internet providers Verizon, Sprint and Time Warner Cable have agreed to block access to child pornography and eliminate the material from their servers, New York's attorney general said Tuesday.
The companies also will pay $1.1 million to help fund efforts to remove the online child porn created and disseminated by users through their services, Attorney General Andrew Cuomo said. The changes will affect customers nationwide.
France to blacklist Web sites
Country plans to ban porn, like in the U.S., but also terrorism, racism
http://www.msnbc.msn.com/id/25080044/
PARIS - The French state and Internet service providers have struck a deal to block sites carrying child pornography or content linked to terrorism or racial hatred, Interior Minister Michel Alliot-Marie announced Tuesday.
The plan, part of a larger effort to fight cybercriminality, is to go into effect in September when a "black list" will be built up based on input from Internet users who signal sites dealing with the offensive material, the minister said.
Teens sending nude photos via cell phones
Pictures meant for boyfriend or girlfriend are ending up on the Internet
http://www.msnbc.msn.com/id/24970829/
"It used to be that kids would make mistakes, and it was local and singular and everyone knew it was part of growing up," said Catherine Davis, a PTA co-president in Westport, Conn., who had a frank talk with her two sons after several students' nude self-portraits recently spread through the wealthy New York City bedroom community. "Now a stupid adolescent mistake can take on major implications and go on their record for the rest of their lives."
School administrators in Santa Fe, Texas, confiscated dozens of cell phones from students in May after nude photos of two junior high girls began circulating. The girls had sent the photos to their boyfriends, who forwarded them to others, officials said.
In La Crosse, Wis., a 17-year-old boy recently was charged with child pornography, sexual exploitation of a child and defamation for allegedly posting nude photos of his 16-year-old ex-girlfriend on his MySpace page. The girl had taken the pictures with her cell phone at her mother's home and e-mailed them to the boyfriend, authorities said.
Providers also will pay to help remove child porn from the Web
http://www.msnbc.msn.com/id/25077224/
ALBANY, N.Y. - Internet providers Verizon, Sprint and Time Warner Cable have agreed to block access to child pornography and eliminate the material from their servers, New York's attorney general said Tuesday.
The companies also will pay $1.1 million to help fund efforts to remove the online child porn created and disseminated by users through their services, Attorney General Andrew Cuomo said. The changes will affect customers nationwide.
France to blacklist Web sites
Country plans to ban porn, like in the U.S., but also terrorism, racism
http://www.msnbc.msn.com/id/25080044/
PARIS - The French state and Internet service providers have struck a deal to block sites carrying child pornography or content linked to terrorism or racial hatred, Interior Minister Michel Alliot-Marie announced Tuesday.
The plan, part of a larger effort to fight cybercriminality, is to go into effect in September when a "black list" will be built up based on input from Internet users who signal sites dealing with the offensive material, the minister said.
Teens sending nude photos via cell phones
Pictures meant for boyfriend or girlfriend are ending up on the Internet
http://www.msnbc.msn.com/id/24970829/
"It used to be that kids would make mistakes, and it was local and singular and everyone knew it was part of growing up," said Catherine Davis, a PTA co-president in Westport, Conn., who had a frank talk with her two sons after several students' nude self-portraits recently spread through the wealthy New York City bedroom community. "Now a stupid adolescent mistake can take on major implications and go on their record for the rest of their lives."
School administrators in Santa Fe, Texas, confiscated dozens of cell phones from students in May after nude photos of two junior high girls began circulating. The girls had sent the photos to their boyfriends, who forwarded them to others, officials said.
In La Crosse, Wis., a 17-year-old boy recently was charged with child pornography, sexual exploitation of a child and defamation for allegedly posting nude photos of his 16-year-old ex-girlfriend on his MySpace page. The girl had taken the pictures with her cell phone at her mother's home and e-mailed them to the boyfriend, authorities said.
Monday, June 9, 2008
Monday News Feed 6/9/08
Microsoft slates seven fixes for next week
Stolen laptop teaches Stanford a lesson on need for encryption
Security firm asks for help cracking ransomware key
Posted at 09:30 AM ET, 06/ 9/2008
Ransomware Encrypts Victim Files With 1,028-Bit Key
Now more than ever, it's important that Windows users ensure their machines are safe from hackers. A dangerous new strain of malicious software that holds the victim's computers files for ransom has been unleashed, and Kaspersky Lab is warning that security researchers have yet to crack the encryption key.
The malware in this case is the latest version of Gpcode (Kaspersky calls it Gpcode.ak), a nasty piece of "ransomware" that scrambles all of the victim's data files with an encryption key known only to the attacker(s). Victims are told via a pop-up message that they need to purchase a special decryption program to regain access to their data.
Kaspersky and other anti-virus companies have previously unraveled the secret encryption key for all previous versions of Gpcode, but this time, the malware author apparently has learned from his previous mistakes. Now, the Gpcode author is encrypting victim files with an extremely strong 1,028-bit RSA encryption key.
"We estimate it would take around 15 million modern computers, running for about a year, to crack such a key," writes Aleks Gostev, senior virus analyst at Kaspersky, on the company's blog.Continue reading this post »»
Posted by Brian Krebs Permalink Comments (3)
Groups call for investigation of ISP ad targeting
Spear-phishing attacks have hooked 15,000, says VeriSign
Symantec tool cleans up XP SP3 registry corruption
Update: Amazon Web site slowly returning after shutdown
June 6, 2008 (Computerworld) The Web site of Amazon.com Inc. was shut down for at least two hours today and was slowing coming back online, the online retailer said.
An Amazon spokesman said the site went down at 10:25 a.m. Pacific time.
"We're bringing the site back up," said Craig Berman, a spokesman for Seattle-based Amazon, in an e-mail statement at 2:09 p.m. Pacific time. "Amazon's systems are very complex and on rare occasions, despite our best efforts, they may experience problems. We work to minimize any disruption and to get the site back as quickly as possible. Amazon's Web services were not affected nor were our international sites."
At 1:49 p.m. Pacific time, Amazon updated the posting on its sellers' forum. The company said it was currently investigating an issue that had impacted the availability of the Amazon.com Web site.
"As a part of this resolution, some customers may experience error messages that indicate that their access to the Amazon Web site has been blocked for various reasons. These reasons may not be directly related to the customer's account. Access to the Web site will return when this technical issue is resolved."
June 09, 2008 Stark warning as UK faces cybercrime boom
http://www.crime-research.org/news/09.06.2008/3404/
The Onion on Airport Security and Voting
"Reporters Expose Airport Security Lapses By Blowing Up Plane" and "Diebold Accidentally Leaks Results Of 2008 Election Early".
Linux Kernel ASN.1 BER Decoding Vulnerability
- Moderately critical - From local network
Issued 8 hours ago.
A vulnerability has been reported in the Linux Kernel, which can be exploited by malicious people to cause a DoS (Denial of Service) and potentially compromise a vulnerable system.
Microsoft apologizes
Mary Jo Foley: Microsoft has pulled from its CodePlex site its Sandcastle project for failure to comply with the terms and conditions required in order to be qualify as bona-fide open source.
Expensive Patent Attorneys Know How To Cut & Paste, But Not Search & Replace
from the get-your-money's-worth dept
Well, it's a mistake plenty of folks are bound to make eventually, but that doesn't make it any less amusing. Joe Mullin has a short post about a big time patent law firm that has launched two recent patent lawsuits over the same basic patents held by a patent holding firm. The only problem? In filing the second lawsuit, it appears that the patent attorneys used cut & paste from the first lawsuit, but didn't use search & replace to get rid of the name of the original defendant. Hopefully, the patent holder didn't pay too much for the cost of filing that second lawsuit.
Sweden Considering Law To Let The Government Monitor All Forms Of Communications
Antigua Doesn't See Settlement With US Over WTO Plan To Let It Ignore US Copyrights
Why there won't be a security update for WkImgSrv.dll
Recently, there was a public post in milw0rm (http://www.milw0rm.com/exploits/5530), talking about an issue in the ActiveX control of Microsoft Works 7 WkImgSrv.dll. The PoC claims that it would achieve remote code execution. McAfee Avert Labs Blog also had a post about this (http://www.avertlabs.com/research/blog/index.php/2008/04/17/potential-microsoft-works-activex-0-day-surfaces/).
At first glance the issue sounds serious, right? Upon further investigation, there is no useful attack vector.
More Laws, Collaboration Required for Online Safety PC World - Thu Jun 5, 3:50 PM ET
Experts discussed ways to improve online safety and better prevent cybercrime at a security conference in Seattle.
Opera Browser and Haute Secure Partner To Prevent Drive By Downloads Of Malware From Compromised Websites
By Grey McKenzie Today
National Economies Threatened by Cybercrime By Grey McKenzie Today
Surge In Bank Account Hijacking Via Keyloggers & Phishing Says UK Threat Assessment By Grey McKenzie Today
Stolen laptop teaches Stanford a lesson on need for encryption
Security firm asks for help cracking ransomware key
Posted at 09:30 AM ET, 06/ 9/2008
Ransomware Encrypts Victim Files With 1,028-Bit Key
Now more than ever, it's important that Windows users ensure their machines are safe from hackers. A dangerous new strain of malicious software that holds the victim's computers files for ransom has been unleashed, and Kaspersky Lab is warning that security researchers have yet to crack the encryption key.
The malware in this case is the latest version of Gpcode (Kaspersky calls it Gpcode.ak), a nasty piece of "ransomware" that scrambles all of the victim's data files with an encryption key known only to the attacker(s). Victims are told via a pop-up message that they need to purchase a special decryption program to regain access to their data.
Kaspersky and other anti-virus companies have previously unraveled the secret encryption key for all previous versions of Gpcode, but this time, the malware author apparently has learned from his previous mistakes. Now, the Gpcode author is encrypting victim files with an extremely strong 1,028-bit RSA encryption key.
"We estimate it would take around 15 million modern computers, running for about a year, to crack such a key," writes Aleks Gostev, senior virus analyst at Kaspersky, on the company's blog.Continue reading this post »»
Posted by Brian Krebs Permalink Comments (3)
Groups call for investigation of ISP ad targeting
Spear-phishing attacks have hooked 15,000, says VeriSign
Symantec tool cleans up XP SP3 registry corruption
Update: Amazon Web site slowly returning after shutdown
June 6, 2008 (Computerworld) The Web site of Amazon.com Inc. was shut down for at least two hours today and was slowing coming back online, the online retailer said.
An Amazon spokesman said the site went down at 10:25 a.m. Pacific time.
"We're bringing the site back up," said Craig Berman, a spokesman for Seattle-based Amazon, in an e-mail statement at 2:09 p.m. Pacific time. "Amazon's systems are very complex and on rare occasions, despite our best efforts, they may experience problems. We work to minimize any disruption and to get the site back as quickly as possible. Amazon's Web services were not affected nor were our international sites."
At 1:49 p.m. Pacific time, Amazon updated the posting on its sellers' forum. The company said it was currently investigating an issue that had impacted the availability of the Amazon.com Web site.
"As a part of this resolution, some customers may experience error messages that indicate that their access to the Amazon Web site has been blocked for various reasons. These reasons may not be directly related to the customer's account. Access to the Web site will return when this technical issue is resolved."
June 09, 2008 Stark warning as UK faces cybercrime boom
http://www.crime-research.org/news/09.06.2008/3404/
The Onion on Airport Security and Voting
"Reporters Expose Airport Security Lapses By Blowing Up Plane" and "Diebold Accidentally Leaks Results Of 2008 Election Early".
Linux Kernel ASN.1 BER Decoding Vulnerability
- Moderately critical - From local network
Issued 8 hours ago.
A vulnerability has been reported in the Linux Kernel, which can be exploited by malicious people to cause a DoS (Denial of Service) and potentially compromise a vulnerable system.
Microsoft apologizes
Mary Jo Foley: Microsoft has pulled from its CodePlex site its Sandcastle project for failure to comply with the terms and conditions required in order to be qualify as bona-fide open source.
Expensive Patent Attorneys Know How To Cut & Paste, But Not Search & Replace
from the get-your-money's-worth dept
Well, it's a mistake plenty of folks are bound to make eventually, but that doesn't make it any less amusing. Joe Mullin has a short post about a big time patent law firm that has launched two recent patent lawsuits over the same basic patents held by a patent holding firm. The only problem? In filing the second lawsuit, it appears that the patent attorneys used cut & paste from the first lawsuit, but didn't use search & replace to get rid of the name of the original defendant. Hopefully, the patent holder didn't pay too much for the cost of filing that second lawsuit.
Sweden Considering Law To Let The Government Monitor All Forms Of Communications
Antigua Doesn't See Settlement With US Over WTO Plan To Let It Ignore US Copyrights
Why there won't be a security update for WkImgSrv.dll
Recently, there was a public post in milw0rm (http://www.milw0rm.com/exploits/5530), talking about an issue in the ActiveX control of Microsoft Works 7 WkImgSrv.dll. The PoC claims that it would achieve remote code execution. McAfee Avert Labs Blog also had a post about this (http://www.avertlabs.com/research/blog/index.php/2008/04/17/potential-microsoft-works-activex-0-day-surfaces/).
At first glance the issue sounds serious, right? Upon further investigation, there is no useful attack vector.
More Laws, Collaboration Required for Online Safety PC World - Thu Jun 5, 3:50 PM ET
Experts discussed ways to improve online safety and better prevent cybercrime at a security conference in Seattle.
Opera Browser and Haute Secure Partner To Prevent Drive By Downloads Of Malware From Compromised Websites
By Grey McKenzie Today
National Economies Threatened by Cybercrime By Grey McKenzie Today
Surge In Bank Account Hijacking Via Keyloggers & Phishing Says UK Threat Assessment By Grey McKenzie Today
Friday, June 6, 2008
Friday News Feed 6/6/08
Spear-phishing attacks have hooked 15,000, says VeriSign VeriSign estimates that spear-phishing attacks have taken in 15,000 victims over the past 15 months. Read more...
Security Advisories
Cisco Security Advisory: Multiple Vulnerabilities in Cisco PIX and Cisco ASA
Cisco Applied Mitigation Bulletin: Identifying and Mitigating Exploitation of the Multiple Vulnerabilities in Cisco PIX and Cisco ASA
Microsoft slates seven fixes for next week
http://blogs.technet.com/msrc/
As part of our regularly scheduled bulletin release, we’re currently planning to release:
· Three Microsoft Security Bulletins rated Critical, three Important, and one Moderate. These updates may require a restart and will be detectable using the newly released version of the Microsoft Baseline Security Analyzer.
XP SP3 omits critical security update
Full Appeals court hearing sought in border laptop search case
UnitedHealthcare data breach leads to ID theft at UC Irvine
Medical ID Theft Threatens Finances and Lives
Medical identity theft adds a new twist to identity theft by potentially creating not only financial problems, but health risks. The theft of health insurance benefits to obtain health care can add erroneous information to the health records of victims. These changes to health records may go unnoticed, if ever detected, for years before they are caught.
Medical ID Theft can injure finances, endanger lives, Dallas Morning News, June 2, 2008
Posted by EPIC on June 3, 2008.Permanent link to this item.
Why your privacy still comes at a cost
http://www.latimes.com/business/la-fi-lazarus4-2008jun04,1,7565391.column
In case you missed it, your elected representatives bowed to intense pressure from phone companies last week and voted to allow them to keep charging whatever they want to protect your privacy.I'm talking, of course, about the up to $24 a year that millions of Californians are charged to keep their numbers out of the phone book and its electronic cousins.
June 06, 2008 KY Attorney General Creates Unit To Combat Cybercrime
http://www.crime-research.org/news/06.06.2008/3402/
A New Spin on Adaptive Security - 6/5/2008 5:25:00 PM
Gartner's next-generation security model has its roots in other efforts
The real-time, adaptive security infrastructure (ASI) posed by Gartner this week has triggered déjà vu and debate among security experts. (See Gartner Details Real-Time 'Adaptive' Security Infrastructure.)
Neil MacDonald, vice president and fellow at Gartner, described the vision of this next-generation security model during his keynote at the Gartner Security Summit on Tuesday. ASI adapts to threats in real time rather than in the aftermath of an attack, with interconnected services and tools that communicate and share information so that network, host, application, database, and content security are no longer separate “silos,” but one synchronized security system.
But some experts say this concept unveiled by Gartner is really nothing new. Network Associates (now part of McAfee), for example, in the late 1990s offered the Active Security family of products, which integrated a security assessment scanner, an early generation policy manager, firewall, and a PKI server. But Active Security never really caught on.
...
Skype File URI Code Execution Vulnerability - Moderately critical - From remoteIssued 1 day ago. A vulnerability has been reported in Skype, which can be exploited by malicious people to compromise a user's system.
Software Update Prompts Nuclear Plant Shutdown
http://blogs.washingtonpost.com/securityfix/
A nuclear power plant in Georgia was recently forced into an emergency shutdown for 48 hours after a software update was installed on a single computer.
The incident occurred on March 7 at Unit 2 of the Hatch nuclear power plant near Baxley, Georgia. The trouble started after an engineer from Southern Company, which manages the technology operations for the plant, installed a software update on a computer operating on the plant's business network.
Opera sings anti-malware tuneNews Brief, 2008-06-06The alternative browser's next version will block Web sites and links that attempt to compromise users' computers.
The number of moves necessary to solve an arbitrary Rubik's cube configuration has been cut down to 23 moves, according to an update on Tomas Rokicki's homepage (and here). As reported in March, Rokicki developed a very efficient strategy for studying cube solvability, which he used it to show that 25 moves are sufficient to solve any (solvable) Rubik's cube. Since then, he's upgraded from 8GB of memory and a Q6600 CPU, to the supercomputers at Sony Pictures Imageworks (his latest result was produced during idle-time between productions). Combined with some of Rokicki's earlier work, this new result implies that for any arbitrary cube configuration, a solution exists in either 21, 22, or 23 moves. This is in agreement with informal group-theoretic arguments (see Hofstadter 1996, ch. 14) suggesting that the necessary and sufficient number of moves should be in the low 20s.
Kaspersky Lab found a new variant of Gpcode which encrypts files with various extensions using an RSA encryption algorithm with a 1024-bit key. After Gpcode.ak encrypts files on the victim machine, it changes the extension of these files to ._CRYPT and places a text file named !_READ_ME_!.txt in the same folder. In the text file the criminal tells the victims that the file has been encrypted and offers to sell them a decryptor. Is this a look into the future where the majority of malware will function based on extortion?
Study paints grim picture of automated P2P enforcement
University of Washington researchers show that BitTorrent DMCA complaints aren't always accurate, and they prove it by "framing" a printer, a PC, and a wireless access point.
June 05, 2008 - 07:50PM CT - by Nate Anderson
Brand-jacking threatens customer trust
Dancho Danchev: Increasingly, online scammers are abusing the reputation of trusted brands in order to build more legitimacy into their phishing campaigns.
How Could Anyone Possibly Mess With With E-Voting Machines... When They're Left Unguarded For Days?
from the oh,-that's-right,-it's-easy dept
One of the common complaints from the e-voting companies about the various independent security tests that find problems with their machines, is that those test occur under conditions that would never happen in the real world. Specifically, the e-voting companies like to claim that most of the "hacks" revealed would require a lot of access to the machines with no one noticing -- and that just wouldn't be feasible during an election with election officials all around. While even that might be questioned, a much bigger issue is that most polling places leave the e-voting machines totally unguarded and totally unprotected, sometimes for days before the election -- giving anyone with nefarious intent plenty of time to mess around with the machines. Ed Felten has been pointing this out for years. He took photos of such machines at Princeton in 2006 and then again at the primary election earlier this year. This past Tuesday was another election day in many places, including New Jersey, and Ed Felten, once again, took photos of a whole bunch of totally unguarded e-voting machines that any passerby could have accessed. Of course, given that the software itself doesn't seem to work maybe someone will actually adjust the machines to make them work better. Always look on the bright side.
15 Comments Leave a Comment..
Trend Micro to boycott security tests
Richard Thurston June 05, 2008
The security vendor's chief technology officer said today the company will withdraw from the popular VB100 anti-malware tests, launching a tirade against the testers' methodology.
Ethical hacking site falls victim to hackers
Richard Thurston June 05, 2008
Metasploit, the hacking tools site which is widely used by white hat hackers, has itself fallen victim to ARP poisoning, which led to the defacement of the site.
Security Advisories
Cisco Security Advisory: Multiple Vulnerabilities in Cisco PIX and Cisco ASA
Cisco Applied Mitigation Bulletin: Identifying and Mitigating Exploitation of the Multiple Vulnerabilities in Cisco PIX and Cisco ASA
Microsoft slates seven fixes for next week
http://blogs.technet.com/msrc/
As part of our regularly scheduled bulletin release, we’re currently planning to release:
· Three Microsoft Security Bulletins rated Critical, three Important, and one Moderate. These updates may require a restart and will be detectable using the newly released version of the Microsoft Baseline Security Analyzer.
XP SP3 omits critical security update
Full Appeals court hearing sought in border laptop search case
UnitedHealthcare data breach leads to ID theft at UC Irvine
Medical ID Theft Threatens Finances and Lives
Medical identity theft adds a new twist to identity theft by potentially creating not only financial problems, but health risks. The theft of health insurance benefits to obtain health care can add erroneous information to the health records of victims. These changes to health records may go unnoticed, if ever detected, for years before they are caught.
Medical ID Theft can injure finances, endanger lives, Dallas Morning News, June 2, 2008
Posted by EPIC on June 3, 2008.Permanent link to this item.
Why your privacy still comes at a cost
http://www.latimes.com/business/la-fi-lazarus4-2008jun04,1,7565391.column
In case you missed it, your elected representatives bowed to intense pressure from phone companies last week and voted to allow them to keep charging whatever they want to protect your privacy.I'm talking, of course, about the up to $24 a year that millions of Californians are charged to keep their numbers out of the phone book and its electronic cousins.
June 06, 2008 KY Attorney General Creates Unit To Combat Cybercrime
http://www.crime-research.org/news/06.06.2008/3402/
A New Spin on Adaptive Security - 6/5/2008 5:25:00 PM
Gartner's next-generation security model has its roots in other efforts
The real-time, adaptive security infrastructure (ASI) posed by Gartner this week has triggered déjà vu and debate among security experts. (See Gartner Details Real-Time 'Adaptive' Security Infrastructure.)
Neil MacDonald, vice president and fellow at Gartner, described the vision of this next-generation security model during his keynote at the Gartner Security Summit on Tuesday. ASI adapts to threats in real time rather than in the aftermath of an attack, with interconnected services and tools that communicate and share information so that network, host, application, database, and content security are no longer separate “silos,” but one synchronized security system.
But some experts say this concept unveiled by Gartner is really nothing new. Network Associates (now part of McAfee), for example, in the late 1990s offered the Active Security family of products, which integrated a security assessment scanner, an early generation policy manager, firewall, and a PKI server. But Active Security never really caught on.
...
Skype File URI Code Execution Vulnerability - Moderately critical - From remoteIssued 1 day ago. A vulnerability has been reported in Skype, which can be exploited by malicious people to compromise a user's system.
Software Update Prompts Nuclear Plant Shutdown
http://blogs.washingtonpost.com/securityfix/
A nuclear power plant in Georgia was recently forced into an emergency shutdown for 48 hours after a software update was installed on a single computer.
The incident occurred on March 7 at Unit 2 of the Hatch nuclear power plant near Baxley, Georgia. The trouble started after an engineer from Southern Company, which manages the technology operations for the plant, installed a software update on a computer operating on the plant's business network.
Opera sings anti-malware tuneNews Brief, 2008-06-06The alternative browser's next version will block Web sites and links that attempt to compromise users' computers.
The number of moves necessary to solve an arbitrary Rubik's cube configuration has been cut down to 23 moves, according to an update on Tomas Rokicki's homepage (and here). As reported in March, Rokicki developed a very efficient strategy for studying cube solvability, which he used it to show that 25 moves are sufficient to solve any (solvable) Rubik's cube. Since then, he's upgraded from 8GB of memory and a Q6600 CPU, to the supercomputers at Sony Pictures Imageworks (his latest result was produced during idle-time between productions). Combined with some of Rokicki's earlier work, this new result implies that for any arbitrary cube configuration, a solution exists in either 21, 22, or 23 moves. This is in agreement with informal group-theoretic arguments (see Hofstadter 1996, ch. 14) suggesting that the necessary and sufficient number of moves should be in the low 20s.
Kaspersky Lab found a new variant of Gpcode which encrypts files with various extensions using an RSA encryption algorithm with a 1024-bit key. After Gpcode.ak encrypts files on the victim machine, it changes the extension of these files to ._CRYPT and places a text file named !_READ_ME_!.txt in the same folder. In the text file the criminal tells the victims that the file has been encrypted and offers to sell them a decryptor. Is this a look into the future where the majority of malware will function based on extortion?
Study paints grim picture of automated P2P enforcement
University of Washington researchers show that BitTorrent DMCA complaints aren't always accurate, and they prove it by "framing" a printer, a PC, and a wireless access point.
June 05, 2008 - 07:50PM CT - by Nate Anderson
Brand-jacking threatens customer trust
Dancho Danchev: Increasingly, online scammers are abusing the reputation of trusted brands in order to build more legitimacy into their phishing campaigns.
How Could Anyone Possibly Mess With With E-Voting Machines... When They're Left Unguarded For Days?
from the oh,-that's-right,-it's-easy dept
One of the common complaints from the e-voting companies about the various independent security tests that find problems with their machines, is that those test occur under conditions that would never happen in the real world. Specifically, the e-voting companies like to claim that most of the "hacks" revealed would require a lot of access to the machines with no one noticing -- and that just wouldn't be feasible during an election with election officials all around. While even that might be questioned, a much bigger issue is that most polling places leave the e-voting machines totally unguarded and totally unprotected, sometimes for days before the election -- giving anyone with nefarious intent plenty of time to mess around with the machines. Ed Felten has been pointing this out for years. He took photos of such machines at Princeton in 2006 and then again at the primary election earlier this year. This past Tuesday was another election day in many places, including New Jersey, and Ed Felten, once again, took photos of a whole bunch of totally unguarded e-voting machines that any passerby could have accessed. Of course, given that the software itself doesn't seem to work maybe someone will actually adjust the machines to make them work better. Always look on the bright side.
15 Comments Leave a Comment..
Trend Micro to boycott security tests
Richard Thurston June 05, 2008
The security vendor's chief technology officer said today the company will withdraw from the popular VB100 anti-malware tests, launching a tirade against the testers' methodology.
Ethical hacking site falls victim to hackers
Richard Thurston June 05, 2008
Metasploit, the hacking tools site which is widely used by white hat hackers, has itself fallen victim to ARP poisoning, which led to the defacement of the site.
Wednesday, June 4, 2008
Wednesday News Feed 6/4/08
Full Appeals court hearing sought in border laptop search case
A three-judge panel already sided with U.S. Customs officials
http://www.computerworld.com/action/article.do?command=viewArticleBasic&taxonomyName=security&articleId=9093018&taxonomyId=17&intsrc=kc_top
June 3, 2008 (Computerworld) A man facing child pornography charges based on evidence gathered during a search of his laptop by airport customs officials is asking for an en banc review of his case by the full U.S. Court of Appeals for the Ninth Circuit.
The petition by Michael Arnold follows a ruling in April by a three-judge panel of the court that found customs officials needed no reasonable suspicion to search the contents of any individual's laptop at U.S. borders. Arnold contends the search was unreasonable.
In an en banc hearing, typically all the judges in a court reconsider a decision made by a smaller panel of the court. The decision to grant such a hearing depends on the court's view of the public importance of the case under review.
Arnold's case is being closely watched by privacy and civil rights advocates who are concerned that the Ninth Circuit's ruling will increase the number of suspicionless searches of laptops and other electronic devices at U.S. borders. Arnold was returning home from a three-week vacation in the Philippines in July 2005, when he was pulled aside for secondary customs screening at Los Angeles International Airport. A customs officer who was inspecting Arnold's luggage asked him to start his computer and had it examined by colleagues who found several images of what they believed were child pornography on the computer and in several storage devices Arnold was carrying with him.
After a grand jury charged Arnold with knowingly transporting child pornography in interstate and foreign commerce, he filed a motion with the U.S. District Court for the Central District of California asking for the evidence against him to be suppressed. In his motion, Arnold argued that the search of his computer and storage devices by Customs officers was unreasonable and unwarranted.
http://blogs.adobe.com/psirt/
- This is not a zero-day exploit. Despite various reports that have been circulating, the Flash Player Standalone 9.0.124.0 and Linux Player 9.0.124.0 are NOT vulnerable to the exploits discussed in conjunction with the previously disclosed vulnerability Symantec posted on 5/27/08. Symantec originally believed this to be a zero-day, unpatched vulnerability, but as their latest update on their Threatcon page indicates, they have now confirmed this issue does not affect any versions of Flash Player 9.0.124.0.
McAfee: Beware the .hk domain, among others
Security company's new report ranks riskiest and safest domains on the Internet. Damage from risky sites runs from the "apocalyptic to the annoying."
Tue, Jun 03 21:01:00 PDT 2008 Read full story
Gartner Details Real-Time 'Adaptive' Security InfrastructureFuture security model addresses arrival of multiple perimeters, mobile users
Army Hospital Breach May Be Result of P2P LeakData loss at Walter Reed exposed personal information on 1,000 soldiers
Gartner: Security Budgets Growing SlowlyDemand for security services drives security market
APPLE.COM Apple Releases Mac OS Leopard Security Guide
CYBERINSECURITY Multiple Cross-Site Scripting Vulnerabilities on EA Sites
Hacking Network Computers Explained In Detail By Grey McKenzie Yesterday
House of Hackers Web Portal For The Hacker Community By Grey McKenzie Yesterday
EU sees security threats lurking in printers AP - Tue Jun 3, 11:48 AM ET
BRUSSELS, Belgium - Printers and copiers could be the weak link in many corporate cyber defenses, the European Union's information security agency warned Tuesday.
New report identifies dangerous Web domainsAP - Wed Jun 4, 7:09 AM ET
SAN JOSE, Calif. - When surfing the Internet for safe Web sites, not all domains are equal.
"Of all ".hk" sites McAfee tested, it flagged 19.2 percent as dangerous or potentially dangerous to visitors; it flagged 11.8 percent of ".cn" sites and 11.7 percent of ".info" sites that way."
Exploiting Security Holes Automatically
By Erica NaoneTuesday, June 03, 2008
Researchers call for changes in how software patches are distributed.
Does Future Hold Malpractice Liability for Psychics?
http://www.onpointnews.com/
"“Defendants knew or should have known that the services they offered to plaintiff were of no value while they fraudulently represented that they could and would assist plaintiff with her personal problem,” she alleges in a complaint filed last week."
AT&T management staff data on stolen laptop
Dan Kaplan June 04, 2008
An undisclosed number of management-level workers at AT&T have been notified that their personal information was stored unencrypted on a stolen laptop.
Google chief exec targeted over privacy policy
Richard Thurston June 04, 2008
Fourteen U.S. privacy groups have written to Eric Schmidt arguing that Google is breaking Californian law by not including a link to its privacy policy on its homepage.
Walter Reed suffers peer-to-peer data breach
Sue Marquette Poremba June 03, 2008
Unauthorized file-sharing is to blame for a data breach at Walter Reed Army Medical Center that exposed the personal information of nearly 1,000 patients.
Spammers use hosted services to send unwanted mail
Dan Kaplan June 03, 2008
Spammers are increasingly turning to hosted services to ship out their junk mail, the latest threat report from MessageLabs revealed.
Patent Battles Continue Over Wireless Email
from the make-it-stop dept
While RIM is often portrayed as a victim for having to pay out $612.5 million in the patent infringement lawsuit filed by patent holding firm NTP, what gets less attention is that part of what kicked off NTP's lawsuit was the fact that RIM itself was going around suing pretty much everyone for patent infringement itself. And, of course, that kicked off all sorts of copycats, such as Visto -- a company that clearly learned the art of wielding patents against more successful companies from NTP. Visto and RIM ended up in quite the patent battle, with Visto even claiming that RIM should be shut down.
But, in the end, rather than the other way around, it turned out that it was Visto that was found to be infringing on RIM's patents. At this point, though, hasn't anyone realized how ridiculous it is that there are so many companies claiming to hold patents on some aspect of "wireless email" that no one can enter the space without having a bunch of infringement lawsuits waiting for them? This is not what the patent system was designed for.
4 Comments Leave a Comment..
CVE ALERT DETAIL : CVE-2008-2528
PRIMARYSOURCE
Source: cve
Description:
Unspecified vulnerability in Citrix Access Gateway Standard Edition 4.5.7 and earlier and Advanced Edition 4.5 HF2 and earlier allows attackers to bypass authentication and gain "access to network resources" via unspecified vectors.
Metasploit Project's site hijacked through ARP poisoning
Online brand-jacking increasing
Phoenix Mars Lander's mission site hacked
Another bogus malware study
Ed Bott: Here we go again, with yet another round of bogus reporting about the extent of malware infections in the United States--this time it's one in four. But we've got the real story.
40GB for $55 per month: Time Warner bandwidth caps arrive
We might want to alert our home VPN users abo9ut these rate caps...
FiReaNGeL notes research presented this morning at Penn State on the discovery of a new, ultra-small species of bacteria that has survived for more than 120,000 years within the ice of a Greenland glacier at a depth of nearly two miles. From the psu.edu announcement:
"The microorganism's ability to persist in this low-temperature, high-pressure, reduced-oxygen, and nutrient-poor habitat makes it particularly useful for studying how life, in general, can survive in a variety of extreme environments on Earth and possibly elsewhere in the solar system. This new species is among the ubiquitous, yet mysterious, ultra-small bacteria, which are so tiny that they are able to pass through microbiological filters. Called Chryseobacterium greenlandensis, the species is related genetically to certain bacteria found in fish, marine mud, and the roots of some plants."
"The GPL version 3 is getting some attention in legal circles, especially as it relates to its interaction with proprietary software and patents. Edmund J. Walsh penned an article for Law.com discussing the GPLv3 and the risks it poses for hardware and software companies."
Beware of Error Messages At Bank Sites
http://blogs.washingtonpost.com/securityfix/
If you own or work at a small to mid-sized business, and are presented with an error message about data synchronization or site maintenance when trying to access your company's bank account online, you might want to give the bank a call: A criminal group that specializes in deploying malicious software to steal banking data is presenting victims with fake maintenance pages and error messages as a means of getting around anti-fraud safeguards erected by many banks.
From http://www.schneier.com/blog/
Fax Signatures
Aren't fax signatures the weirdest thing? It's trivial to cut and paste -- with real scissors and glue -- anyone's signature onto a document so that it'll look real when faxed. There is so little security in fax signatures that it's mind-boggling that anyone accepts them.
Yet people do, all the time. I've signed book contracts, credit card authorizations, nondisclosure agreements and all sorts of financial documents -- all by fax. I even have a scanned file of my signature on my computer, so I can virtually cut and paste it into documents and fax them directly from my computer without ever having to print them out. What in the world is going on here?
And, more importantly, why are fax signatures still being used after years of experience? Why aren't there many stories of signatures forged through the use of fax machines?
Medical ID Theft Threatens Finances and Lives
Medical identity theft adds a new twist to identity theft by potentially creating not only financial problems, but health risks. The theft of health insurance benefits to obtain health care can add erroneous information to the health records of victims. These changes to health records may go unnoticed, if ever detected, for years before they are caught.
Medical ID Theft can injure finances, endanger lives,
Dallas Morning News, June 2, 2008
Posted by EPIC on June 3, 2008.Permanent link to this item.
At Gartner Summit, Experts Question Security's Future - 6/2/2008 1:30:00 PM Analysts, sci-fi authors challenge security pros to rethink the status quo
A three-judge panel already sided with U.S. Customs officials
http://www.computerworld.com/action/article.do?command=viewArticleBasic&taxonomyName=security&articleId=9093018&taxonomyId=17&intsrc=kc_top
June 3, 2008 (Computerworld) A man facing child pornography charges based on evidence gathered during a search of his laptop by airport customs officials is asking for an en banc review of his case by the full U.S. Court of Appeals for the Ninth Circuit.
The petition by Michael Arnold follows a ruling in April by a three-judge panel of the court that found customs officials needed no reasonable suspicion to search the contents of any individual's laptop at U.S. borders. Arnold contends the search was unreasonable.
In an en banc hearing, typically all the judges in a court reconsider a decision made by a smaller panel of the court. The decision to grant such a hearing depends on the court's view of the public importance of the case under review.
Arnold's case is being closely watched by privacy and civil rights advocates who are concerned that the Ninth Circuit's ruling will increase the number of suspicionless searches of laptops and other electronic devices at U.S. borders. Arnold was returning home from a three-week vacation in the Philippines in July 2005, when he was pulled aside for secondary customs screening at Los Angeles International Airport. A customs officer who was inspecting Arnold's luggage asked him to start his computer and had it examined by colleagues who found several images of what they believed were child pornography on the computer and in several storage devices Arnold was carrying with him.
After a grand jury charged Arnold with knowingly transporting child pornography in interstate and foreign commerce, he filed a motion with the U.S. District Court for the Central District of California asking for the evidence against him to be suppressed. In his motion, Arnold argued that the search of his computer and storage devices by Customs officers was unreasonable and unwarranted.
http://blogs.adobe.com/psirt/
- This is not a zero-day exploit. Despite various reports that have been circulating, the Flash Player Standalone 9.0.124.0 and Linux Player 9.0.124.0 are NOT vulnerable to the exploits discussed in conjunction with the previously disclosed vulnerability Symantec posted on 5/27/08. Symantec originally believed this to be a zero-day, unpatched vulnerability, but as their latest update on their Threatcon page indicates, they have now confirmed this issue does not affect any versions of Flash Player 9.0.124.0.
McAfee: Beware the .hk domain, among others
Security company's new report ranks riskiest and safest domains on the Internet. Damage from risky sites runs from the "apocalyptic to the annoying."
Tue, Jun 03 21:01:00 PDT 2008 Read full story
Gartner Details Real-Time 'Adaptive' Security InfrastructureFuture security model addresses arrival of multiple perimeters, mobile users
Army Hospital Breach May Be Result of P2P LeakData loss at Walter Reed exposed personal information on 1,000 soldiers
Gartner: Security Budgets Growing SlowlyDemand for security services drives security market
APPLE.COM Apple Releases Mac OS Leopard Security Guide
CYBERINSECURITY Multiple Cross-Site Scripting Vulnerabilities on EA Sites
Hacking Network Computers Explained In Detail By Grey McKenzie Yesterday
House of Hackers Web Portal For The Hacker Community By Grey McKenzie Yesterday
EU sees security threats lurking in printers AP - Tue Jun 3, 11:48 AM ET
BRUSSELS, Belgium - Printers and copiers could be the weak link in many corporate cyber defenses, the European Union's information security agency warned Tuesday.
New report identifies dangerous Web domainsAP - Wed Jun 4, 7:09 AM ET
SAN JOSE, Calif. - When surfing the Internet for safe Web sites, not all domains are equal.
"Of all ".hk" sites McAfee tested, it flagged 19.2 percent as dangerous or potentially dangerous to visitors; it flagged 11.8 percent of ".cn" sites and 11.7 percent of ".info" sites that way."
Exploiting Security Holes Automatically
By Erica NaoneTuesday, June 03, 2008
Researchers call for changes in how software patches are distributed.
Does Future Hold Malpractice Liability for Psychics?
http://www.onpointnews.com/
"“Defendants knew or should have known that the services they offered to plaintiff were of no value while they fraudulently represented that they could and would assist plaintiff with her personal problem,” she alleges in a complaint filed last week."
AT&T management staff data on stolen laptop
Dan Kaplan June 04, 2008
An undisclosed number of management-level workers at AT&T have been notified that their personal information was stored unencrypted on a stolen laptop.
Google chief exec targeted over privacy policy
Richard Thurston June 04, 2008
Fourteen U.S. privacy groups have written to Eric Schmidt arguing that Google is breaking Californian law by not including a link to its privacy policy on its homepage.
Walter Reed suffers peer-to-peer data breach
Sue Marquette Poremba June 03, 2008
Unauthorized file-sharing is to blame for a data breach at Walter Reed Army Medical Center that exposed the personal information of nearly 1,000 patients.
Spammers use hosted services to send unwanted mail
Dan Kaplan June 03, 2008
Spammers are increasingly turning to hosted services to ship out their junk mail, the latest threat report from MessageLabs revealed.
Patent Battles Continue Over Wireless Email
from the make-it-stop dept
While RIM is often portrayed as a victim for having to pay out $612.5 million in the patent infringement lawsuit filed by patent holding firm NTP, what gets less attention is that part of what kicked off NTP's lawsuit was the fact that RIM itself was going around suing pretty much everyone for patent infringement itself. And, of course, that kicked off all sorts of copycats, such as Visto -- a company that clearly learned the art of wielding patents against more successful companies from NTP. Visto and RIM ended up in quite the patent battle, with Visto even claiming that RIM should be shut down.
But, in the end, rather than the other way around, it turned out that it was Visto that was found to be infringing on RIM's patents. At this point, though, hasn't anyone realized how ridiculous it is that there are so many companies claiming to hold patents on some aspect of "wireless email" that no one can enter the space without having a bunch of infringement lawsuits waiting for them? This is not what the patent system was designed for.
4 Comments Leave a Comment..
CVE ALERT DETAIL : CVE-2008-2528
PRIMARYSOURCE
Source: cve
Description:
Unspecified vulnerability in Citrix Access Gateway Standard Edition 4.5.7 and earlier and Advanced Edition 4.5 HF2 and earlier allows attackers to bypass authentication and gain "access to network resources" via unspecified vectors.
Metasploit Project's site hijacked through ARP poisoning
Online brand-jacking increasing
Phoenix Mars Lander's mission site hacked
Another bogus malware study
Ed Bott: Here we go again, with yet another round of bogus reporting about the extent of malware infections in the United States--this time it's one in four. But we've got the real story.
40GB for $55 per month: Time Warner bandwidth caps arrive
We might want to alert our home VPN users abo9ut these rate caps...
FiReaNGeL notes research presented this morning at Penn State on the discovery of a new, ultra-small species of bacteria that has survived for more than 120,000 years within the ice of a Greenland glacier at a depth of nearly two miles. From the psu.edu announcement:
"The microorganism's ability to persist in this low-temperature, high-pressure, reduced-oxygen, and nutrient-poor habitat makes it particularly useful for studying how life, in general, can survive in a variety of extreme environments on Earth and possibly elsewhere in the solar system. This new species is among the ubiquitous, yet mysterious, ultra-small bacteria, which are so tiny that they are able to pass through microbiological filters. Called Chryseobacterium greenlandensis, the species is related genetically to certain bacteria found in fish, marine mud, and the roots of some plants."
"The GPL version 3 is getting some attention in legal circles, especially as it relates to its interaction with proprietary software and patents. Edmund J. Walsh penned an article for Law.com discussing the GPLv3 and the risks it poses for hardware and software companies."
Beware of Error Messages At Bank Sites
http://blogs.washingtonpost.com/securityfix/
If you own or work at a small to mid-sized business, and are presented with an error message about data synchronization or site maintenance when trying to access your company's bank account online, you might want to give the bank a call: A criminal group that specializes in deploying malicious software to steal banking data is presenting victims with fake maintenance pages and error messages as a means of getting around anti-fraud safeguards erected by many banks.
From http://www.schneier.com/blog/
Fax Signatures
Aren't fax signatures the weirdest thing? It's trivial to cut and paste -- with real scissors and glue -- anyone's signature onto a document so that it'll look real when faxed. There is so little security in fax signatures that it's mind-boggling that anyone accepts them.
Yet people do, all the time. I've signed book contracts, credit card authorizations, nondisclosure agreements and all sorts of financial documents -- all by fax. I even have a scanned file of my signature on my computer, so I can virtually cut and paste it into documents and fax them directly from my computer without ever having to print them out. What in the world is going on here?
And, more importantly, why are fax signatures still being used after years of experience? Why aren't there many stories of signatures forged through the use of fax machines?
Medical ID Theft Threatens Finances and Lives
Medical identity theft adds a new twist to identity theft by potentially creating not only financial problems, but health risks. The theft of health insurance benefits to obtain health care can add erroneous information to the health records of victims. These changes to health records may go unnoticed, if ever detected, for years before they are caught.
Medical ID Theft can injure finances, endanger lives,
Dallas Morning News, June 2, 2008
Posted by EPIC on June 3, 2008.Permanent link to this item.
At Gartner Summit, Experts Question Security's Future - 6/2/2008 1:30:00 PM Analysts, sci-fi authors challenge security pros to rethink the status quo
Monday, June 2, 2008
Monday News Feed 6/2/08
Microsoft urges Windows users to shut down Safari Microsoft is warning Windows users to avoid Apple's Safari Web browser until a patch is available for holes that could let attackers compromise computers. Read more...
Security Advisory 953818 PostedPosted Friday, May 30, 2008 3:56 PM by MSRCTEAM
Hi,
This is Tim Rains.
Very quickly, I wanted to let you know that we’ve just posted Microsoft Security Advisory 953818. This security advisory talks about new public reports of a blended threat that allows remote code execution on all supported versions of Windows XP and Windows Vista when Apple’s Safari web browser for Windows has been installed. Safari is not installed with Windows XP or Windows Vista by default: it must be installed independently or through the Apple Software Update application.
If you run Safari on the affected platforms, we encourage you to review this advisory.
We’ve activated our Software Security Incident Response Process (SSIRP) and are working with our colleagues at Apple to investigate the issue. We have identified steps customers can take to protect themselves in the workaround section of the advisory.
Bank loses tapes with data on 4.5M clients
FAA: Sun box disk failure caused NOTAM database crash
RIM reportedly gets ultimatum over BlackBerry service in India
Apple patches 40 Mac OS X security bugs
Microsoft beta-tests free online diagnostic tools for Windows
Maiffret Starts New Security Venture - 6/2/2008 9:00:00 AM Former co-founder, CTO, and chief hacking officer of eEye Digital Security will provide consulting, training, and vulnerability research
Web 2.0 Sites a Thriving Marketplace for Malware
Malicious software makers are using social networks, video sites, and blogs to peddle their wares to other online criminals. 01-Jun-2008
U.S., China Lead in Hack Attacks
Two countries accounted for 30% of Internet-attack traffic for 2008 so far, researchers say. 01-Jun-2008
DR Case Study:
The Planet outage - what can we all learn from it?
...Next I saw they were "requiring us to take down all generators as instructed by the fire department". I had seen plans for BCP/DRP derail before due to officials stepping in and doing their response to an emergency in their way and not in the way the organization itself had planned it.
Ant ssnds in a disturbing report in The Scientist on an imminent threat to worldwide banana production. "The banana we eat today is not the one your grandparents ate. That one — known as the Gros Michel — was, by all accounts, bigger, tastier, and hardier than the variety we know and love, which is called the Cavendish. The unavailability of the Gros Michel is easily explained: it is virtually extinct. Introduced to our hemisphere in the late 19th century, the Gros Michel was almost immediately hit by a blight that wiped it out by 1960. The Cavendish was adopted at the last minute by the big banana companies — Chiquita and Dole — because it was resistant to that blight, a fungus known as Panama disease... [Now] Panama disease — or Fusarium wilt of banana — is back, and the Cavendish does not appear to be safe from this new strain, which appeared two decades ago in Malaysia, spread slowly at first, but is now moving at a geometrically quicker pace. There is no cure, and nearly every banana scientist says that though Panama disease has yet to hit the banana crops of Latin America, which feed our hemisphere, the question is not if this will happen, but when. Even worse, the malady has the potential to spread to dozens of other banana varieties, including African bananas, the primary source of nutrition for millions..."
Microsoft's CAPTCHA successfully broken
Sharing your login is a criminal offense
Phil Wainewright: Think about that next time you pass those notes around so everyone can get access to the Dun & Bradstreet credit reports, look up the Xignite currency data or share a single WebEx account. What you're doing is tantamount to criminal larceny.
Adobe's Acrobat.com an Office killer?
Larry Dignan: Adobe unveiled Acrobat.com, a suite that allows you to create word processing documents, share files, convert PDFs and hold Web conferences. What remains to be seen is whether online office users care about aesthetics.
Prince And Radiohead Fight Over YouTube Song
from the this-is-what-it's-come-to? dept
For years, Prince was the poster child for "getting" the internet and new media distribution opportunities. He experimented with a variety of different creative business models that suggested he got how the economics of music worked these days. It was working too -- with his efforts to give away his music helping him sell out concert after concert around the world. But then something changed, and Prince went ballistic, suing YouTube, The Pirate Bay and eBay and even threatening fan sites while demanding that even videos with tiny snippets of Prince music in the background get taken offline. The whole thing is quite surprising, and if he keeps this up, he's risking taking all that goodwill he built up for years, and turning himself into another Metallica. Becoming anti-fan is never a good idea. The latest story, though, has a twist. Prince apparently did a cover of a Radiohead song at a recent concert. Someone filmed it and put the video on YouTube. Given his newfound hatred for YouTube, Prince demanded that the song be taken down. And here's where it gets interesting: Radiohead's Thom Yorke is demanding that it be put back online, noting that he owns the copyright on the song: "Really? He's blocked it?... Well, tell him to unblock it. It's our ... song." Of course, as that LA Times report notes, in true Streisand Effect fashion, the effort to take down the song has only driven much more interest in people trying to find the song. If Prince weren't suing so many people, you might even think he was canny enough to have done this on purpose as a marketing campaign.
Publishers Demand Damages For ReportReleased 3 Minutes Ahead Of Time
CHICAGO (CN) - In an Internet age complaint, the publishers of the monthly "Chicago Business Barometer" claim Trade the News Inc. released their copyrighted report 3 minutes early, damaging them economically and harming their business relationships.
Alarming Open-Source Security Holes
By Simson Garfinkel 05/20/2008 29 Comments
How a programming error introduced profound security vulnerabilities in millions of computer systems.
Industry View
Five Ways to Turn Employees into Security Assets for Protecting Data
http://www2.csoonline.com/article/343968/Five_Ways_to_Turn_Employees_into_Security_Assets_for_Protecting_Data
Make data security part of the company culture
Integrate data leak prevention processes into overall workflow
Make employees feel like security assets, not liabilities
Prevent the temptation to engage in "harmless" policy violations
Teach employees about policies while enforcing them
Security Advisory 953818 PostedPosted Friday, May 30, 2008 3:56 PM by MSRCTEAM
Hi,
This is Tim Rains.
Very quickly, I wanted to let you know that we’ve just posted Microsoft Security Advisory 953818. This security advisory talks about new public reports of a blended threat that allows remote code execution on all supported versions of Windows XP and Windows Vista when Apple’s Safari web browser for Windows has been installed. Safari is not installed with Windows XP or Windows Vista by default: it must be installed independently or through the Apple Software Update application.
If you run Safari on the affected platforms, we encourage you to review this advisory.
We’ve activated our Software Security Incident Response Process (SSIRP) and are working with our colleagues at Apple to investigate the issue. We have identified steps customers can take to protect themselves in the workaround section of the advisory.
Bank loses tapes with data on 4.5M clients
FAA: Sun box disk failure caused NOTAM database crash
RIM reportedly gets ultimatum over BlackBerry service in India
Apple patches 40 Mac OS X security bugs
Microsoft beta-tests free online diagnostic tools for Windows
Maiffret Starts New Security Venture - 6/2/2008 9:00:00 AM Former co-founder, CTO, and chief hacking officer of eEye Digital Security will provide consulting, training, and vulnerability research
Web 2.0 Sites a Thriving Marketplace for Malware
Malicious software makers are using social networks, video sites, and blogs to peddle their wares to other online criminals. 01-Jun-2008
U.S., China Lead in Hack Attacks
Two countries accounted for 30% of Internet-attack traffic for 2008 so far, researchers say. 01-Jun-2008
DR Case Study:
The Planet outage - what can we all learn from it?
...Next I saw they were "requiring us to take down all generators as instructed by the fire department". I had seen plans for BCP/DRP derail before due to officials stepping in and doing their response to an emergency in their way and not in the way the organization itself had planned it.
Ant ssnds in a disturbing report in The Scientist on an imminent threat to worldwide banana production. "The banana we eat today is not the one your grandparents ate. That one — known as the Gros Michel — was, by all accounts, bigger, tastier, and hardier than the variety we know and love, which is called the Cavendish. The unavailability of the Gros Michel is easily explained: it is virtually extinct. Introduced to our hemisphere in the late 19th century, the Gros Michel was almost immediately hit by a blight that wiped it out by 1960. The Cavendish was adopted at the last minute by the big banana companies — Chiquita and Dole — because it was resistant to that blight, a fungus known as Panama disease... [Now] Panama disease — or Fusarium wilt of banana — is back, and the Cavendish does not appear to be safe from this new strain, which appeared two decades ago in Malaysia, spread slowly at first, but is now moving at a geometrically quicker pace. There is no cure, and nearly every banana scientist says that though Panama disease has yet to hit the banana crops of Latin America, which feed our hemisphere, the question is not if this will happen, but when. Even worse, the malady has the potential to spread to dozens of other banana varieties, including African bananas, the primary source of nutrition for millions..."
Microsoft's CAPTCHA successfully broken
Sharing your login is a criminal offense
Phil Wainewright: Think about that next time you pass those notes around so everyone can get access to the Dun & Bradstreet credit reports, look up the Xignite currency data or share a single WebEx account. What you're doing is tantamount to criminal larceny.
Adobe's Acrobat.com an Office killer?
Larry Dignan: Adobe unveiled Acrobat.com, a suite that allows you to create word processing documents, share files, convert PDFs and hold Web conferences. What remains to be seen is whether online office users care about aesthetics.
Prince And Radiohead Fight Over YouTube Song
from the this-is-what-it's-come-to? dept
For years, Prince was the poster child for "getting" the internet and new media distribution opportunities. He experimented with a variety of different creative business models that suggested he got how the economics of music worked these days. It was working too -- with his efforts to give away his music helping him sell out concert after concert around the world. But then something changed, and Prince went ballistic, suing YouTube, The Pirate Bay and eBay and even threatening fan sites while demanding that even videos with tiny snippets of Prince music in the background get taken offline. The whole thing is quite surprising, and if he keeps this up, he's risking taking all that goodwill he built up for years, and turning himself into another Metallica. Becoming anti-fan is never a good idea. The latest story, though, has a twist. Prince apparently did a cover of a Radiohead song at a recent concert. Someone filmed it and put the video on YouTube. Given his newfound hatred for YouTube, Prince demanded that the song be taken down. And here's where it gets interesting: Radiohead's Thom Yorke is demanding that it be put back online, noting that he owns the copyright on the song: "Really? He's blocked it?... Well, tell him to unblock it. It's our ... song." Of course, as that LA Times report notes, in true Streisand Effect fashion, the effort to take down the song has only driven much more interest in people trying to find the song. If Prince weren't suing so many people, you might even think he was canny enough to have done this on purpose as a marketing campaign.
Publishers Demand Damages For ReportReleased 3 Minutes Ahead Of Time
CHICAGO (CN) - In an Internet age complaint, the publishers of the monthly "Chicago Business Barometer" claim Trade the News Inc. released their copyrighted report 3 minutes early, damaging them economically and harming their business relationships.
Alarming Open-Source Security Holes
By Simson Garfinkel 05/20/2008 29 Comments
How a programming error introduced profound security vulnerabilities in millions of computer systems.
Industry View
Five Ways to Turn Employees into Security Assets for Protecting Data
http://www2.csoonline.com/article/343968/Five_Ways_to_Turn_Employees_into_Security_Assets_for_Protecting_Data
Make data security part of the company culture
Integrate data leak prevention processes into overall workflow
Make employees feel like security assets, not liabilities
Prevent the temptation to engage in "harmless" policy violations
Teach employees about policies while enforcing them
Subscribe to:
Posts (Atom)