If this one doesn't give you pause about the businesses you deal with, nothing will.
Some security researchers take issue with the study, saying the numbers are simply wrong. No one disagrees with the basic conclusion, though. Major security incidents are the norm, not the exception.
The survey really is a little goofy. It equates spyware infections with genuine intrusions and several other assumptions are equally strange. I suspect this was done to simplify the form in order to not burden those responding unduly.
The point is that there is a lot more of this sort of thing going on than was generally acknowledged.
Jack
Thoughts and links from the crew of the On Computers Radio Show as we wander the Web.
Saturday, January 21, 2006
Friday, January 20, 2006
Update: Inside the WMF Backdoor [Mark's Systinternals Blog]
Some of the latest info:
Mark received several requests to look into the WMF vulnerability and he believes it is merely bad design, not a deliberate backdoor. Steve Gibson has released another security now podcast which apparently "close[s] the backdoor" on the WMF vulnerability, but I haven't listened yet, so go check it out, there are a variety of ways to access the podcast listed, from audio to text to PDF.
--MissM
Mark received several requests to look into the WMF vulnerability and he believes it is merely bad design, not a deliberate backdoor. Steve Gibson has released another security now podcast which apparently "close[s] the backdoor" on the WMF vulnerability, but I haven't listened yet, so go check it out, there are a variety of ways to access the podcast listed, from audio to text to PDF.
--MissM
Thursday, January 19, 2006
Gonzales v Google: the study methodology is flawed
The text below was sent to Joel McElvain at the Department of Justice:
Sir,
I have read and considered your motion to force Google to comply. May I humbly suggest that you may win the battle and lose the war. I have no stake in this dispute, but I do know a few things about computer technology. Yes, you will find me with a Google search.
Assuming you get the data requested from Google and its competitors, what kind of picture can you paint with the data obtained for the Supreme Court? The answer is not enough that is useful in setting United States law and policy. Internet search providers such as Google have search servers spread throughout the world, largely to handle queries in local geographies. The search engines must comply with local laws such as Arabic bans on indecency, China's ban on "democracy" and France's ban on Nazi memorabilia auctions.
For various reasons, Internet data that is searchable and available in one part of the world may not be available in or accessible from the United States, and vice versa. Therefore, it appears to me that a random set of data from Google's query servers around the world cannot say whether the query made in, say, China can also return the same results if made from the United States -- and therefore be controlled by U.S. law. Your subpoena will drag in worldwide data without identifying the query limits of the source data server.
As a citizen, I am interested in seeing that the Supreme Court's remand re COPA is met with a study that is accurate and defensible as it relates to U.S. law and citizens. I fail to see how the methodology implied in the Google motion is going to achieve a "national" set of data when a "world" net is being cast.
Regards,
Peter S. Kastner
Sir,
I have read and considered your motion to force Google to comply. May I humbly suggest that you may win the battle and lose the war. I have no stake in this dispute, but I do know a few things about computer technology. Yes, you will find me with a Google search.
Assuming you get the data requested from Google and its competitors, what kind of picture can you paint with the data obtained for the Supreme Court? The answer is not enough that is useful in setting United States law and policy. Internet search providers such as Google have search servers spread throughout the world, largely to handle queries in local geographies. The search engines must comply with local laws such as Arabic bans on indecency, China's ban on "democracy" and France's ban on Nazi memorabilia auctions.
For various reasons, Internet data that is searchable and available in one part of the world may not be available in or accessible from the United States, and vice versa. Therefore, it appears to me that a random set of data from Google's query servers around the world cannot say whether the query made in, say, China can also return the same results if made from the United States -- and therefore be controlled by U.S. law. Your subpoena will drag in worldwide data without identifying the query limits of the source data server.
As a citizen, I am interested in seeing that the Supreme Court's remand re COPA is met with a study that is accurate and defensible as it relates to U.S. law and citizens. I fail to see how the methodology implied in the Google motion is going to achieve a "national" set of data when a "world" net is being cast.
Regards,
Peter S. Kastner
Wednesday, January 18, 2006
New Linux license takes aim at DRM and Hollywood | CNET News.com
"At a two-day event here to launch the General Public License version 3, which governs use of countless free and open-source programs, Moglen said the license includes anti-DRM provisions that could put it in conflict with movie studios and even digital video recorder maker TiVo"
Next XP Service Pack is Far in the Future
Apparently Microsoft has much less interest in service packs for XP than they do in releasing Vista. While that is understandable, it seems to indicate they are not terribly concerned with problems that exist in XP now.
Here is Microsoft's roadmap for service packs.
I frequently get the idea that Microsoft simply does not have enough people to deal with all the updates and upgrades they need to be putting out. With all their billions, one would think they could and would hire enough good people to do what they and their customers need done.
Jack
Here is Microsoft's roadmap for service packs.
I frequently get the idea that Microsoft simply does not have enough people to deal with all the updates and upgrades they need to be putting out. With all their billions, one would think they could and would hire enough good people to do what they and their customers need done.
Jack
Tuesday, January 17, 2006
Researcher: Sony BMG "rootkit" still widespread
As we have hinted during the show; the damage and flap over Sony/BMG's behavior is far from over. This Security Focus article makes that perfectly clear.
Be afraid;
Jack
Be afraid;
Jack
Sunday, January 15, 2006
OnComputers Radio show Podcast 01-15-06
This is the On Computers Radio show podcast for 01-15-06. If you prefer, you can download the same file here via ftp.
Saturday, January 14, 2006
Speaking of Trustworthy computing....
The link in the title goes to the latest Security Now podcast with Leo Laporte and Steve Gibson. Steve releases his current information about the WMF Vulnerability. He says that the WMF exploit was a deliberate backdoor, by somebody at Microsoft, and there's no way that it was unknown. One does have to go to a website that could take advantage of the exploit though.
He came to this conclusion while trying to determine if 95, 98 and WinME were vulnerable or not to the wmf exploit, and had to come up with a file that would test the exploit in the earlier Operating Systems. Steve gets into a bit of an arcane discussion re: bits of data in wmf files, when all of a sudden he says it had to be deliberate. That woke me up! It'll be very interesting to see what happens on this issue, in the next week or so.
--MissM
P.S. At first, I assumed that the MS patch had been forced on his machine, since this was so public (referring to Jack's post below).
P.P.S. I assume the fix, fixed the exploit, er backdoor?
UPDATE: 'Windows backdoor' theory causes kerfuffle |CNET News.com
Further UPDATE: Microsoft Security Response Center Blog! : Looking at the WMF issue, how did it get there?
He came to this conclusion while trying to determine if 95, 98 and WinME were vulnerable or not to the wmf exploit, and had to come up with a file that would test the exploit in the earlier Operating Systems. Steve gets into a bit of an arcane discussion re: bits of data in wmf files, when all of a sudden he says it had to be deliberate. That woke me up! It'll be very interesting to see what happens on this issue, in the next week or so.
--MissM
P.S. At first, I assumed that the MS patch had been forced on his machine, since this was so public (referring to Jack's post below).
P.P.S. I assume the fix, fixed the exploit, er backdoor?
UPDATE: 'Windows backdoor' theory causes kerfuffle |CNET News.com
Further UPDATE: Microsoft Security Response Center Blog! : Looking at the WMF issue, how did it get there?
PCWorld.com - Symantec, Kaspersky Criticized for Cloaking Software
More companies are using Root-Kits now!Mark Russinovich, chief software architect with systems software company Winternals Software, says that the techniques used by Symantec's Norton SystemWorks and Kaspersky's Anti-Virus products are rootkits, a term usually reserved for the techniques that malicious software uses to avoid detection on an infected PC.
Friday, January 13, 2006
Anti-Spyware Coalition Risk Model Description
The link above is not to the Anti Spyware Coalition's home page, but to their definition of "risk modelling" in relation to these programs.
I have no idea whether the ASC can actually make a difference and to be perfectly honest, I have my doubts. No matter that; they're trying to do well by users and that must be applauded.
Check it out. Send them feedback if you think you can be of help. Anything is worth a shot to make this plague upon users better.
JacK
I have no idea whether the ASC can actually make a difference and to be perfectly honest, I have my doubts. No matter that; they're trying to do well by users and that must be applauded.
Check it out. Send them feedback if you think you can be of help. Anything is worth a shot to make this plague upon users better.
JacK
A Time to Patch
The link is to an article on The Washington Post's web site. In it, Brian Krebs examines the timeliness of Microsoft' patching of security vulnerabilities. According to Krebs, it is not a pretty picture.
It seems MS assigns priority to patches based on how much the public knows of them. Those that have gotten publicity get higher priority in Redmond than those that don't. And regardless of publicity, Kreb's analysis shows MS is actually slowing down in it's responses to vulnerabilities.
Isn't Trustworthy Computing grand?
Jack
It seems MS assigns priority to patches based on how much the public knows of them. Those that have gotten publicity get higher priority in Redmond than those that don't. And regardless of publicity, Kreb's analysis shows MS is actually slowing down in it's responses to vulnerabilities.
Isn't Trustworthy Computing grand?
Jack
Microsoft patches without permission
I had no idea this was the case and have heard no reports of it until this blurb made it to my attention.
Apparently; even as MS played down the severity of the WMF vulnerability to us, they were taking it so seriously that they chose to over-ride the patch installation settings on machine to install this patch the instant it was received, rather than waiting for the administrator to do the deal. The subsequent reboot must have thrown a wrench into at least some operations.
So; we see Microsoft saying one thing about a security problem and acting in such a way as to convince me they knew differently all the while. So much for Trustworthy Computing".
Jack
Apparently; even as MS played down the severity of the WMF vulnerability to us, they were taking it so seriously that they chose to over-ride the patch installation settings on machine to install this patch the instant it was received, rather than waiting for the administrator to do the deal. The subsequent reboot must have thrown a wrench into at least some operations.
So; we see Microsoft saying one thing about a security problem and acting in such a way as to convince me they knew differently all the while. So much for Trustworthy Computing".
Jack
A Reasonable Discussion of Digital Rights Management
Victor Yodaiken has written an article posted at Groklaw about problems associated with widespread DRM. I recommend this highly, though the author does have a viewpoint of his own, he tries really hard to express only technical problems and not get into philosophy or law.
Yodaiken accepts that pervasive DRM is coming and concentrates on which problems have to be solved before DRM becomes a danger to users or their data.
The same author has written "DRM Out of Control" at Linuxdevices.com.
Jack
Yodaiken accepts that pervasive DRM is coming and concentrates on which problems have to be solved before DRM becomes a danger to users or their data.
The same author has written "DRM Out of Control" at Linuxdevices.com.
Jack
Microsoft Support Lifecycle
Updated today, according to ISC. Online support for XP Pro [my flavor of XP] until 2011, a full list of links by product, handy resource.
--MissM
--MissM
F-Secure : News from the Lab
To add to Jack's post about Symantec's RootKitAccording to F-Secure Norton's Rootkit was part of a well documented feature, its related to recovering deleted files. Evil program writers could have hidden there, but apparently none had done it yet, as I read it, and now it can't be exploited, according to Mikko at F-Secure.
--MissM
--MissM
Thursday, January 12, 2006
Linux is Not Windows
A VERY good opinion article on why Windows users find using most Linux distros does not mimic the Windows experience. If you've ever had any interest in trying Linux, or of converting your operations to it, this will clarify both the issues and what you are getting yourself into.
Jack
Jack
Mark's Sysinternals Blog
Mark Russinovich is the person who discovered Sony's XCP rootkit. His current blog entry is an almost sickening account of misleading spyware/adware popups that sell dodgy anti-spyware apps. Ben Edelman has other documentation of the same sort of thing.
If you need a refresher course in what we are up against in terms of spyware/adware, this is it.
Jack
If you need a refresher course in what we are up against in terms of spyware/adware, this is it.
Jack
More RootKit Madness
This time it's Symantic. One would think a vendor of security products would know not to do stuff like this, but evidently they included a rootkit function in Norton SystemWorks.
This is downright disgusting.
Jack
This is downright disgusting.
Jack
Wednesday, January 11, 2006
New Wi-Fi standard back on track
The link is to a story on CNet's News.com.
Peter and I alluded to the fact that some hardware for 802.11n is already on the market, such as AirLink's "MIMO" parts. These are built to the company's best guess as to what the "n" standard will be, not to the standard itself. This has the potential of causing interoperability problems to kit made to the actual standard.
This new spirit of cooperation is essential to speeding codification and adoption of the standard. When that is done, all products will (in theory) interoperate smoothly as we can spend our money on kit with confidence it will work in all or most situations.
Jack
Peter and I alluded to the fact that some hardware for 802.11n is already on the market, such as AirLink's "MIMO" parts. These are built to the company's best guess as to what the "n" standard will be, not to the standard itself. This has the potential of causing interoperability problems to kit made to the actual standard.
This new spirit of cooperation is essential to speeding codification and adoption of the standard. When that is done, all products will (in theory) interoperate smoothly as we can spend our money on kit with confidence it will work in all or most situations.
Jack
Should Apple Open Up?
The link above will take you to a current article in Business Week's web site. I got the link from my friend, Waleed al-Shobakky, who is attending university in Qatar.
Though Apple is almost completely without a commercail presence anywhere except the US and western Europe, the company garners a lot of attention in the rest of the world. Almost an amazing amount of attention.
I don't think Apple should open up any part of their digital entertainment operations. However; I do think they are missing a lot of income by not selling OS X for x86 as a standalone product. Actually, I would see that as a grand move to drive their digital entertainment market forward, besides generating a boatload of profits.
Doing so could conceiveably drive Apple's market share of operating systems above 10% and 20% is not beyond possiblity. Rather than the iPod generating operating system and hardware sales, I could see operating system sales generating a much more widespread presence in digital entertainment, which is where the real money is.
Apple does not have to attempt supporting the vast majority of hardware, as Windows does. They only have to support a small subset of x86 stuff. They can line up strategic partners for this and support no other products. That's doable without great development costs to drain their profits.
If they don't do this, and relatively soon, I think they'll be missing a chance to really grab the maket and lead it, despite their minority share.
Jack
Though Apple is almost completely without a commercail presence anywhere except the US and western Europe, the company garners a lot of attention in the rest of the world. Almost an amazing amount of attention.
I don't think Apple should open up any part of their digital entertainment operations. However; I do think they are missing a lot of income by not selling OS X for x86 as a standalone product. Actually, I would see that as a grand move to drive their digital entertainment market forward, besides generating a boatload of profits.
Doing so could conceiveably drive Apple's market share of operating systems above 10% and 20% is not beyond possiblity. Rather than the iPod generating operating system and hardware sales, I could see operating system sales generating a much more widespread presence in digital entertainment, which is where the real money is.
Apple does not have to attempt supporting the vast majority of hardware, as Windows does. They only have to support a small subset of x86 stuff. They can line up strategic partners for this and support no other products. That's doable without great development costs to drain their profits.
If they don't do this, and relatively soon, I think they'll be missing a chance to really grab the maket and lead it, despite their minority share.
Jack
Subscribe to:
Posts (Atom)