Introduction About Site Map

XML
RSS 2 Feed RSS 2 Feed
Navigation

Main Page | Blog Index

Archive for the ‘Security’ Category

On the State of Platform Security

Bill Gates

SANY items on security were published last night. Perhaps the most prominent among these was the mentioning of a possible Mac OSX vulnerability (more details here). On yet another front, a ‘bounty hunt’ for Windows critical flaws has begun. Last but not least, Red Hat further beef up Linux desktop security.

Linux appears to be the least notable victim of vulnerabilities, despite the prevalence of Linux (and UNIX derivatives or variants) servers. A survey confirms this while debunking Microsoft’s deceiving, self-funded campaigns, which try to convince people otherwise. With that in mind, Korea plans Linux city and Novell is preparing for the big Linux adoption wave.

Previous items on Windows security (or lack thereof):

On Mac security: the BBC article which begged for an outcry.

Technology commentator Bill Thompson is worried about the lack of herd immunity among his fellow Apple Mac users.

Firefox: the Secure Choice

Firefox in the dock

A recent study suggests that Mozilla Firefox is tremendously safer to use than the more prevalent Internet Explorer.

Internet Explorer users can be as much as 21 times more likely to end up with a spyware-infected PC than people who go online with Mozilla’s Firefox browser, academic researchers from Microsoft’s backyard said in a recently published paper.

In other news, the number of spyware per PC in Europe exceeds a dozen!!

Computer users whose machines have been hijacked by potentially dangerous software are being asked to add their tales of woe to an online campaign.

In Poland, 867 of every 1,000 domestic PCs have been infected by trojans, unsolicited programs that can allow remote users to control the machine.

Google Desktop Gets Dangerous

Google Desktop

GOOGLE have introduced and released cross-desktop search, which is an extension of their popular Google Desktop. That piece of software was recently embraced by IBM and it was included in a Windows ‘distribution’ from Google. It already raises many questions and privacy concerns. Not only your trusted colleagues will be able to gain access to your data.

Google Copies Your Hard Drive – Government Smiles in Anticipation

Consumers Should Not Use New Google Desktop

Related items:

Windows Wanker Live

Smashed screen

MICROSOFT have announced officially their intent to enter the anti-virus market a couple of months ago. They now unveil a service called OneCare (homonym of “wanker”) Live, which is paid for annually. In simple words, the customer gets protection for the operating system’s own flaws and pays $50 per year for the service from no-one but the O/S vendor. As reported by CNN:

Microsoft Corp. said on Tuesday it plans to launch a new computer security service in June, marking the world’s biggest software maker’s entry into the fast-growing consumer anti-virus market.

Microsoft’s Windows OneCare Live, a subscription-based, self-updating service, will push the software giant into competition with consumer security providers Symantec Corp. and McAfee Inc.

The article neglects to mention the controversy that is associated with this anti-competitive strategy. Microsoft exploits a monoploy in the desktop market and gives itself motives to create flaws intentionally, then offer the cure for a high cost. I believe Symantec filed an anti-trust lawsuit against Microsoft over a month ago.

Nanny Country Snatches Search Logs

CCTV

‘Smile! Big brother is watching you.”

MSN, AOL and Yahoo have handed over log data to the U.S. government. The controversial move has seen strong resistance from Google however.

Yahoo acknowledges handing over search data requested in a subpoena from the Bush administration, which is hoping to use the information to revive an anti-porn law that was rejected by the U.S. Supreme Court.

Exposure of one’s search history is nothing new. In fact, exposure through search giants and third parties extends beyond this . The same companies maintain mail accounts and even statistics from other Web sites (Google Analytics).

Given sheer demand from up above, will they carrying on caving and exposing their customers’ data? Also, what about the new laws regarding data retention by ISP‘s? Everything you do gets logged, unless you use encryption of course. Being watched may be acceptable, but a so-called ‘nanny country’ is not, at least in my humble opinion.

Related items:

The Baseless Security Promise

Bill Gates
Business as usual…

Slashdot has revealed to me this mild critique:

Four years ago, Bill Gates dispatched a companywide e-mail promising that security and privacy would be Microsoft’s top priorities. Gates urged that new design approaches must “dramatically reduce” the number of security-related issues as well as make fixes easier to administer. “Eventually,” he added, “our software should be so fundamentally secure that customers never even worry about it.”

The grim reality:

Signatures and Spam Filters

Hand signing

A long time ago I argued that more people ought to digitally sign their E-mail messages. Unfortunately, very few people bother to do so. There are many benefits to encryption-based verification of one’s identity. Ultimately, it can lead to more trust, which can in turn prevent spam and make communication less susceptible to ‘noise’.

There recently emerged a word-of-mouth that signed messages are less likely to be intercepted by spam filters. As to whether this is true or not, I would have to say I doubt it. I am sorry to antagonise some people’s hopes, but several messages that I PGP-signed got flagged as spam (not by SpamAssassin). At least I was informed in all (probably two) occasions, but it was nonetheless worrisome. Quite recently I mentioned a trend whereby banning of autoresponders becomes prevalent. It is very important that moderators up above can discern spammers from those who attempt to fight spam in genuine and effective ways.

Retrieval statistics: 21 queries taking a total of 0.260 seconds • Please report low bandwidth using the feedback form
Original styles created by Ian Main (all acknowledgements) • PHP scripts and styles later modified by Roy Schestowitz • Help yourself to a GPL'd copy
|— Proudly powered by W o r d P r e s s — based on a heavily-hacked version 1.2.1 (Mingus) installation —|