January 26, 2009

Is it safe to watch the news at work?

A readers discovers a worrisome truth about CNN's video plug-in

The inauguration apparently brought with it a host of security worries. Everyone heard about the Secret Service's troubles securing D.C. against the millions who wanted to be there for a moment of history. And the security hang-ups over Obama's BlackBerry have been well-reported. But one of Gripe Line's own experienced a lesser-known security issue with one of the tools used to broadcast that event.

"I am a regular viewer of CCN news video feed," writes David. "I came across a new plug-in being offered through video feeds on their site. The plug-in is the Octoshape Grid Adobe Flash Plug-in. Since this is CNN, I clicked to install it. I also took the time to Google the plug-in to make sure it was legit and proceeded with the install. I also read the licensing agreement before continuing with the install. I am very happy I did read that agreement. It turns out that this piece of software is peer-to-peer. It is dangerous in the extreme for businesses to allow peer-to-peer tools on their systems and I was shocked that an organization like CNN would offer this as a seemingly harmless and innocuous enhancement to their video viewing experience. I've included an excerpt of the license agreement below."

Accordingly, you hereby grant permission for Octoshape and other end users of the Software to utilize and share the processor and bandwidth of your personal computer system for the limited purpose of facilitating the communication between you and other end users of the Software, including Octoshape.

David continues, "I feel that the dangers of this kind of software in a corporate environment are too numerous and well-known for me to list here. I have never been a fan of peer-to-peer software for what I feel are the obvious and inherent security risks. Using Windows is bad enough without installing additional risk vectors."

David concludes that his main gripe is not the fact that this software is peer-to-peer. His gripe is that CNN failed to inform him of this fact. As David points out, "You have to read the license agreement to realize what you are actually installing and -- in reality -- who does that?"

David raises a good point. And I fear it is one that will resurface again and again as media outlets aim to deliver streaming video to huge audiences at political and sports events. Personally, I enjoyed watching the inauguration on CNN Live with all my Facebook friends. I apparently (without reading the EULA) installed this plug-in to do it.

additional resources
White Paper - How to Improve Delivery of Advanced Web Applications

White Paper

Virtual Workforce: The Key to Expanding The Business While Cutting Costs

Get the independent advice and expertise you need to support a virtual workforce.

Go inside:
The three-step approach to making a virtual workforce a reality.
The four flavors of client virtualization technologies.
The three key initiatives that solve IT challenges.
Download now »
White Paper: Successfully Secure Your Wireless LAN With Wi-Fi firewalls.

White Paper

Addressing Linux Threats Leveraging Fewer Resources

The increase in Linux popularity has increased the frequency and sophistication of malware attacks. Read this 2 page white paper now to learn how you can protect your Linux environment with real-time protection that is certified by all major Linux vendors.

Download now »
White Paper - The 2009 Handbook of Application Delivery

White Paper

The 2009 Handbook of Application Delivery

Ensuring acceptable application delivery will become even more difficult over the next few years. As a result, IT organizations need to ensure that the approach that they take to resolving the current application delivery challenges can scale to support the emerging challenges. This handbook elaborates on the key tasks associated with planning, optimization, management and control and provides decision criteria to help IT organizations choose appropriate solutions.

Download now »
White Paper - Is Your Backup System Outdated?

White Paper

Mid-range Storage Considerations

A common misconception is that mid-range storage requirements are dramatically different than that of a larger enterprise. Mid-range storage users may require less capacity, but they have similar functionality and management requirements. This ESG paper examines mid-range storage needs and reviews a new solution that adjusts size while retaining value, performance and functionality.

Download now »

Sign up to receive Business Resource Alerts

Subscribe to the Today's Headlines: First Look Newsletter

Find out what will be news for the day, with our first-thing-in-the-morning briefing.

©1994-2010 Infoworld, Inc.