The bug was disclosed on February 19th, and a patch was released on March 10th. That’s not really an impressive turnaround time, especially for a remote code execution vulnerability. Where Adobe’s patch release gets interesting, though, is the fact that the update is, as of today, still only available for version 9 of both Reader and Acrobat, and then only on Windows. A patch is forthcoming for versions 7 and 8, which are also affected by the same vulnerability, with Adobe claiming March 18th as a release date, as well as a stunningly far off release date of Marth 25th for Acrobat 9 on Unix.
Category: rants
Many people have been praising Mozilla’s Firefox 3 ever since pre-beta. I can easily throw myself onto that band wagon, but there is one feature that has been causing a little commotion, and I again can easily agree with the commotion. Firefox 3 (FF3) limits usable, encrypted (SSL) web sites to those that have an approved digital certificate from an authorized vendor of Mozilla’s choosing, making it so you have to pay to be recognized. What’s the big deal? When you visit an encrypted site in FF3, and that site uses a self-signed or simply unapproved certificate, FF3 doesn’t immediately show the page. Instead, you are greeted with what, at first glance, would seem to be an error page. In[…]
I really like my mac. It usually is pretty secure. However, Apple just patched their copy of BIND yesterday. I just got the software update request today. This is almost a month since Kaminsky’s coordinated release of the DNS patch. I wonder why Apple was the recalcitrant one that waited so long? Could it be because the exploit was finally in the wild and was on longer just proof of concept? Could it be that the patch was more critical on servers rather than desktops, and desktops are Apple’s mainstay? Whatever the reason for Apple’s late release, it has made me think about Apple’s security practices. As far as I know, Apple doesn’t have a “patch Tuesday”, and the DNS[…]
In my last article [link] I outlined a few of the hardships we are facing with the constant uprising of technology and how it’s affecting our privacy and security. Hopefully I can shed some light on it, and reassure you that not all hope is lost.
I hate being advertised to. I can’t watch cable TV (which I already pay for), listen to the radio (even subscription satellite radio has ads now), goof off on the internet, play a video game, drive in my car, read a magazine, buy groceries, or check my e-mail/snail mail/answering machine without being bombarded by coupons, billboards, commercials, in-game ads, Google AdWords, spam, telemarketing, and third class junk mail. The sad fact is, advertising is everywhere. Opinions and research vary widely on the question of how many advertisements Americans see during a typical day, with estimates ranging from a few hundred to a few thousand. (via Google Answers) So, it’s no surprise that the advertisement industry is always trying to come[…]
The following will be a two part post on the current state of security. It will mostly be a self opinionated rant. But I’ll try to make some insightful comments. If you’ve followed the media for any amount of time lately you’ve heard countless stories about data leaks, data breaches, identity theft, all those uber scary things that keep you up at night.