Monday, June 22, 2009

Could Opera 10 Be Banned in Corporations?

The new version of Opera, version 10, will include a web server as part of a platform called Unite. Opera is touting it for home users who want to be able to publish content but don’t know how to configure their firewalls or are getting blocked by ISP’s. This also means that anyone on your corporate network could setup a web server to serve up files from your network (sound scary? It should.)

Security researchers say this could be a perfect opportunity for botmasters to use the browser as a command and control channel. Not only that but Opera users could unknowingly give access to critical system files as well. The platform uses a group of extensions to the widget system Opera uses to provide enhanced functionality to the browser. While Opera warns developers of the risks, it is up to the developer in the end to decide how careful they are going to be. It also places a significant responsibility on the end user to determine what parts of Unite and the other Opera widgets could give up control to the less honest people on the web.

Other researchers are also warning that it could spur malware authors to write specifically for the Opera browser. As it passes through the Beta phase I’m sure we’ll see more about this and likely some POC code.

Sunbelt Software
Network World – “Could Opera be a Botmaster’s Best Friend
Geeks are Sexy - “Opera Unite – should be “Untie”?”
Opera Software – Opera Unite

Wednesday, June 10, 2009

Accidental Google Hack

Google is a great source of information both good and not so good. Be careful what you post on forums, discussion groups, etc. This is a very interesting blog post:

http://synjunkie.blogspot.com/2009/06/accidental-google-hack.html

“Oh dear...within seconds Bob found a password. Surely it was old and probably not active anymore?”

Friday, June 5, 2009

Checklist a Day: Residential Wireless Audit

If you aren’t sure if your home wireless network is secure (or you don’t think it should be) you should read this document. It takes very little time and will make sure your personal information is secure.

Home Network Audit

Microsoft and Adobe to Issue Patches Tuesday June 9

Adobe is releasing a round of patches Tuesday June 9 that will cover Acrobat 7.x – 9.x for Windows and OS X.

Also on Tuesday Microsoft is releasing 10 patches to cover vulnerabilities in Windows, Excel, and IE.

Get ready to do some heavy testing on Tuesday.

Friday, May 29, 2009

Much Anticipated Cyber Policy Review Out Today

I haven’t had a chance to read it but here is the Cyber Policy Review doc released today by the White House.

http://www.whitehouse.gov/assets/documents/Cyberspace_Policy_Review_final.pdf

Near Term Action Plan
1.
Appoint a cybersecurity policy official responsible for coordinating the Nation’s cybersecurity policies and activities; establish a strong NSC directorate, under the direction of the cybersecurity policy official dual-hatted to the NSC and the NEC, to coordinate interagency development of cybersecurity-related strategy and policy.
2.
Prepare for the President’s approval an updated national strategy to secure the information and communications infrastructure. This strategy should include continued evaluation of CNCI activities and, where appropriate, build on its successes.
3.
Designate cybersecurity as one of the President’s key management priorities and establish performance metrics.
4.
Designate a privacy and civil liberties official to the NSC cybersecurity directorate.
5.
Convene appropriate interagency mechanisms to conduct interagency-cleared legal analyses of priority cybersecurity-related issues identified during the policy-development process and formulate coherent unified policy guidance that clarifies roles, responsibilities, and the application of agency authorities for cybersecurity-related activities across the Federal government.
6.
Initiate a national public awareness and education campaign to promote cybersecurity.
7.
Develop U.S. Government positions for an international cybersecurity policy framework and strengthen our international partnerships to create initiatives that address the full range of activities, policies, and opportunities associated with cybersecurity.
8.
Prepare a cybersecurity incident response plan; initiate a dialog to enhance public-private partnerships with an eye toward streamlining, aligning, and providing resources to optimize their contribution and engagement
9.
In collaboration with other EOP entities, develop a framework for research and development strategies that focus on game-changing technologies that have the potential to enhance the security, reliability, resilience, and trustworthiness of digital infrastructure; provide the research community access to event data to facilitate developing tools, testing theories, and identifying workable solutions.
10.
Build a cybersecurity-based identity management vision and strategy that addresses privacy and civil liberties interests, leveraging privacy-enhancing technologies for the Nation.

Thursday, May 21, 2009

cyberDefense Competition Preps Students

This looks like a great competition and it's nice to see kids getting this kind of education.

http://current.com/items/90072618_cyberdefense-competition-preps-students-for-real-world-information-assurance.htm

Wednesday, May 13, 2009

Will Windows 7 Overcome Anti-Virus Fear and Loathing?

Will Windows 7 Overcome Anti-Virus Fear and Loathing?:
"But beyond that obvious complaint, over and over, I find that security suites are the buggiest, most troublesome applications on my systems. I’ve spent innumerable hours nursing these “solutions” along, working around them, fixing them, reinstalling them."

I have had very similar feelings to the author with regard to anti-virus software. I haven't yet had a chance to install the Windows 7 RC, however I've been impressed with Microsoft's effort on securing Vista and Windows 7. Unfortunately, as with UAC, you can't always do everything you want. However I think one of the biggest leaps in security with these versions of Windows has been the unprivileged user.

I would never advocate running without anti-virus software, though as it is a necessary part of a defense-in-depth strategy for either home or business use. Maybe someday anti-virus vendors will put as much effort into streamlining and cleaning up their applications as Microsoft has to making their OS more secure out of the box. Maybe...