Security - Infoworld http://www.infoworld.com/t/2094 en Adobe launches sandboxed Flash Player for Firefox, hopes for fewer exploits http://www.infoworld.com/d/applications/adobe-launches-sandboxed-flash-player-firefox-hopes-fewer-exploits-185824?source=rss_security <!--paging_filter--><p>Adobe has released a <a href="http://labs.adobe.com/downloads/flashplatformruntimes_incubator.html" target="_blank">beta version</a> of Flash Player for Firefox, which has better protection against vulnerability exploits because of a new sandboxed architecture.</p> Applications Security Adobe Flash Vulnerability Assessment Security Mon, 06 Feb 2012 23:36:06 +0000 admin 185824 at http://www.infoworld.com Microsoft team discovers malicious cookie-forwarding scheme http://www.infoworld.com/d/security/microsoft-team-discovers-malicious-cookie-forwarding-scheme-185618?source=rss_security <!--paging_filter--><p><a href="http://www.networkworld.com/subnets/microsoft/" target="_blank">Microsoft</a> researchers checking how easy it is to identify users by analyzing commonly collected Web-log data incidentally discovered a cookie-forwarding scheme that can be used to aid session hijacking.</p> Security Security Thu, 02 Feb 2012 20:08:42 +0000 admin 185618 at http://www.infoworld.com Symantec recants Android malware claims http://www.infoworld.com/d/security/symantec-recants-android-malware-claims-185546?source=rss_security <!--paging_filter--><p>Symantec has backtracked from assertions last week that 13 Android apps distributed by Google's Android Market were malicious, and now says that the code in question comes from an aggressive ad network that provides revenue to the smartphone programs.</p> Mobile Technology Security Android Mobile Security Security Wed, 01 Feb 2012 21:47:12 +0000 admin 185546 at http://www.infoworld.com Symantec drops don't-use advice, gives pcAnywhere all-clear http://www.infoworld.com/d/security/symantec-drops-dont-use-advice-gives-pcanywhere-all-clear-185452?source=rss_security <!--paging_filter--><p>Symantec has retracted its don't-use-pcAnywhere recommendation to owners of the remote access software.</p> <p>Last week, the company took the highly unusual step of telling pcAnywhere users to disable the program based on a 2006 source code leak and this month's claims by members of Anonymous that they were mining the stolen code for vulnerabilities.</p> Security Symantec Security Wed, 01 Feb 2012 00:21:19 +0000 admin 185452 at http://www.infoworld.com Book review: 'Liars and Outliers: Enabling the Trust that Society Needs to Thrive' http://www.infoworld.com/d/security/book-review-liars-and-outliers-enabling-the-trust-society-needs-thrive-185355?source=rss_security <!--paging_filter--><p>I've always considered anything written by Bruce Schneier to be part of my ongoing education about IT security. Like Warren Buffet of the financial world, Schneier has a special talent for simplifying complex IT concepts by stripping away the fat. Each book is like its own little graduate course on whichever subject he happens to be discussing.</p> Security Security Tue, 31 Jan 2012 11:00:00 +0000 Roger A. Grimes 185355 at http://www.infoworld.com Many pcAnywhere systems still sitting ducks http://www.infoworld.com/d/security/many-pcanywhere-systems-still-sitting-ducks-185358?source=rss_security <!--paging_filter--><div style="position: relative; width: 243px; background: #ffffff no-repeat center top; float: right; height: 182px; padding: 8px;"><img src="http://www.infoworld.com/sites/infoworld.com/files/media/image/IFW_Hacking3.jpg" alt="Many pcAnywhere systems still sitting ducks" width="243" height="182" align="right" /></div><p>Despite warnings from security software maker Symantec not to connect its pcAnywhere remote-access software to the Internet, more than 140,000 computers appear to remain configured to allow direct connections from the Internet, thereby putting them at risk.</p> Security Symantec Endpoint Protection Hacking Network Security Vulnerability Assessment Security Tue, 31 Jan 2012 11:00:00 +0000 Eric Knorr 185358 at http://www.infoworld.com Even the best patching programs probably miss this http://www.infoworld.com/d/security/even-the-best-patching-programs-probably-miss-185324?source=rss_security <!--paging_filter--><p>We like to think our data center configuration and patch management practices are pretty businesslike and solid, right? Well, in at least one very important aspect, almost all of us are essentially asleep at the wheel, folks.</p> <p>Sure, most data centers have honed their patch management over the years. Most actually do a pretty good job at getting operating system and application server patches deployed in a timely manner. The majority even have an emergency process for getting critical patches installed even faster than the normal process.</p> Security Patch Management Security Mon, 30 Jan 2012 20:46:00 +0000 admin 185324 at http://www.infoworld.com Facebook scammers redirect victims through Amazon's cloud http://www.infoworld.com/d/security/facebook-scammers-redirect-victims-through-amazons-cloud-185209?source=rss_security <!--paging_filter--><p>Facebook scammers have started redirecting victims through Amazon's cloud in order to bypass malicious URL filters, according to security researchers from antivirus vendor F-Secure.</p> <p>One Facebook survey scam <a href="http://www.f-secure.com/weblog/archives/00002304.html" target="_blank">recently analyzed</a> by F-Secure uses malicious browser extensions to hijack Facebook accounts and post spam messages on their walls.</p> Security Facebook Social Networking Security Fri, 27 Jan 2012 20:26:02 +0000 admin 185209 at http://www.infoworld.com Security alert: Why compliance and privacy matter http://www.infoworld.com/d/security/security-alert-why-compliance-and-privacy-matter-184828?source=rss_security <!--paging_filter--><p>One bit of IT security dogma that's gone unquestioned over the years is the notion that every technology belongs to one of three pillars: confidentiality, integrity, and availability, also <a href="http://www.infoworld.com/d/security-central/are-you-ready-big-one-115">known by the abbreviation CIA</a>. Traditionally, a security team is doing its job if it manages to protect the technologies that fall into those three buckets.</p> Security Federal Regulations Internet Privacy Security Tue, 24 Jan 2012 11:00:00 +0000 Roger A. Grimes 184828 at http://www.infoworld.com The Oracle flaw: Clarifications and more information http://www.infoworld.com/d/security/the-oracle-flaw-clarifications-and-more-information-184775?source=rss_security <!--paging_filter--><p>Since InfoWorld published "<a href="http://www.infoworld.com/d/security/fundamental-oracle-flaw-revealed-184163-0">Fundamental Oracle flaw revealed</a>" on Jan. 17, we've received abundant feedback from Oracle users and consulted with Oracle representatives, who went through the story point by point, offering <a href="http://www.infoworld.com/d/security/fundamental-oracle-flaw-revealed-184163-0">clarifications and additional details</a>, including information about the patches that address the flaw.</p> Data Management Security Oracle Database Administration Data Security Data Management Security Mon, 23 Jan 2012 16:54:33 +0000 Eric Knorr 184775 at http://www.infoworld.com Will a $6.7 million cyber heist spur a move toward fixing the Internet? http://www.infoworld.com/t/security/will-67-million-cyber-heist-spur-move-toward-fixing-the-internet-184354?source=rss_security <div style="padding: 8px; background: none no-repeat scroll center top #ffffff; position: relative; float: right; width: 243px; height: 182px;"><img src="http://www.infoworld.com/sites/infoworld.com/files/media/image/Security_lock_2_hp.jpg" alt="Will a $6.7 million cyber heist spur a move toward fixing the Internet?" width="243" height="182" align="right" /></div> <p>A remarkably lucrative $6.7 million cyber bank heist of South Africa's state-owned Postbank provides an outstanding case study of just why 2011 was <a href="http://www.infoworld.com/d/security/2011-was-the-year-the-cyber-criminal- Security Cyber Crime Security Tue, 17 Jan 2012 23:50:25 +0000 InfoWorld Tech Watch 184354 at http://www.infoworld.com Calling all Oracle customers http://www.infoworld.com/t/data-management/calling-all-oracle-customers-184103?source=rss_security <!--paging_filter--><p>When&nbsp;I first heard from an anonymous source&nbsp;about a flaw in the Oracle database, I was skeptical. I'm well versed in the endless cycle of bugs and patches that surrounds the software industry. But this was different. Unless&nbsp;that source was blowing smoke, this was a vulnerability at the heart of the industry's most widely used and trusted enterprise database product.</p> Data Management Oracle DBMS Data Management Security Tue, 17 Jan 2012 11:00:00 +0000 Eric Knorr 184103 at http://www.infoworld.com Cyber crime in 2025: New threats mingle with old risks http://www.infoworld.com/d/security/cyber-crime-in-2025-new-threats-mingle-old-risks-184152?source=rss_security <!--paging_filter--><p>With the new year upon us, I'm pulling out my crystal ball to predict the computer security threats of tomorrow -- and I don't mean 2012. I'm looking ahead to 2022 or 2032. Over the next couple of decades, technology will surely continue to evolve, and if the past is any guide, we can expect that <a href="http://www.infoworld.com/d/security-central/how-malicious-hackers-attack-447">today's security problems</a> -- buffer overflows, misconfigurations, poor authentication implementations, and data malformation -- won't much change; they'll just move to the latest gadgets.</p> Security Security Tue, 17 Jan 2012 11:00:00 +0000 Roger A. Grimes 184152 at http://www.infoworld.com Update: Fundamental Oracle flaw revealed http://www.infoworld.com/d/security/fundamental-oracle-flaw-revealed-184163-0?source=rss_security <!--paging_filter--><p><em>(Editor's note:<strong> </strong>This story has been updated to include clarifications and additional information, which appear in italics. </em><em>For the latest developments, s</em><em>ee the follow-on story "<a href="http://www.infoworld.com/d/security/the-oracle-flaw-clarifications-and-more-information-184775">The Oracle flaw: Clarifications and more information</a>.")</em></p> Applications Data Management Security Oracle Database Administration Data Security Patch Management Data Management Security Tue, 17 Jan 2012 11:00:00 +0000 Eric Knorr 184163 at http://www.infoworld.com Symantec uses scareware sales tactics, lawsuit charges http://www.infoworld.com/d/the-industry-standard/symantec-uses-scareware-sales-tactics-lawsuit-charges-183999?source=rss_security <!--paging_filter--><p>A Washington man on Tuesday sued Symantec in federal court, accusing it of using the same tactics as fake "scareware" software to sell its PC cleanup utilities.</p> <p>Symantec said the lawsuit was without merit, and promised to defend its practices.</p> <p><strong>[ Keep up on the day's tech news headlines with InfoWorld's <a href="newsletters/subscribe?showlist=infoworld_todays_headlines_wrap_up&amp;source=ifwelg_fssr">Today's Headlines: Wrap Up newsletter</a>. ]</strong></p> Security The Industry Standard Symantec Security Technology Business Thu, 12 Jan 2012 20:02:57 +0000 Pete Babb 183999 at http://www.infoworld.com Companies prove careless when enlisting data recovery services http://www.infoworld.com/t/security/companies-prove-careless-when-enlisting-data-recovery-services-183816?source=rss_security <div style="padding: 8px; background: none no-repeat scroll center top #ffffff; position: relative; float: right; width: 243px; height: 182px;"><img src="http://www.infoworld.com/sites/infoworld.com/files/media/image/Security_lock_2_hp.jpg" alt="Companies prove careless when enlisting data recovery services" width="243" height="182" align="right" /></div> <p>Even the most vigilant IT security department could invest countless hours and dollars into <a href="http://www.infoworld.com/d/security/prepare-advanced-persistent-threats-or-risk-being-the-next-rsa-180">defending its company's data trove Data Loss Prevention Data Security Security Wed, 11 Jan 2012 11:00:00 +0000 InfoWorld Tech Watch 183816 at http://www.infoworld.com Virtual-security appliances winning users over traditional messaging-security software http://www.infoworld.com/d/security/virtual-security-appliances-winning-users-over-traditional-messaging-security-software-183722?source=rss_security <!--paging_filter--><p>There's no question enterprises want messaging <a href="http://www.networkworld.com/topics/security.html" target="_blank">security</a> -- the market for products and services worldwide reached almost $3.2 billion last year, up from $2.7 billion in 2010, and will grow to $4.78 billion in 2015, according to research firm IDC. But a fundamental shift is occurring that foresees businesses favoring <a href="http://www.networkworld.com/reviews/2011/030711-virtualization-security-test.html" target="_blank">virtual-security appliances</a> over more traditional messaging security software.</p> Applications Security Security Tue, 10 Jan 2012 16:54:55 +0000 admin 183722 at http://www.infoworld.com Security headlines you'll never read http://www.infoworld.com/d/security/security-headlines-youll-never-read-182533?source=rss_security <p>Whenever I read another article about how <a href="http://www.infoworld.com/d/security/after-hack-rsa-offers-replace-secureid-tokens-360">Company X</a> or <a href="http://www.huffingtonpost.com/2011/09/26/harvard-website-hacked_n_981842.html" target="_blank">University Y</a> or <a href="http://www.infoworld.com/t/data-security/us-military-drones-catch-virus-175385">Governmental Organization Z</a> was "recently" hacked -- usually "by the Chinese" -- I can't help but chuckle. Security Data Loss Prevention Data Security Hacking Security Tue, 27 Dec 2011 11:00:00 +0000 Roger A. Grimes 182533 at http://www.infoworld.com FTC fishes for info on facial recognition http://www.infoworld.com/d/security/ftc-fishes-info-facial-recognition-182645?source=rss_security <!--paging_filter--><p>A federal agency charged with protecting consumer rights is gathering information on the new uses of facial recognition in contexts such as social networks, digital signs, and mobile apps, and it's <a href="http://www.ftc.gov/opa/2011/12/facefacts.shtm">asking the public for help</a>.</p> Security Security Mon, 26 Dec 2011 17:03:50 +0000 admin 182645 at http://www.infoworld.com Windows 8 picture password is 'Fisher-Price toy,' says father of 2-factor authentication http://www.infoworld.com/d/security/windows-8-picture-password-fisher-price-toy-says-father-2-factor-authentication-182538?source=rss_security <!--paging_filter--><p>The <a href="http://www.networkworld.com/community/node/79442" target="_blank">Windows 8 feature</a> that logs users in if they touch certain points in a photo in the right order might be fun, but it's not very good security, according to the inventor of RSA's SecurID token.</p> <p>"I think it's cute," says Kenneth Weiss, who now runs a three-factor authentication business called <a href="http://www.networkworld.com/news/2011/062911-kenneth-weiss-securid.html" target="_blank">Universal Secure Registry</a>. "I don't think it's serious security."</p> Microsoft Windows Security Windows 8 Microsoft Windows Security Thu, 22 Dec 2011 23:22:01 +0000 admin 182538 at http://www.infoworld.com