Despite the fact that corporate interest is growing in Macs, they haven’t been able to penetrate the market. There’s just one problem. “Apple will tell you that they are focused on [the commercial business market], but at the end of the day, it’s not a big priority for them,” says David Daoud, an analyst at IDC. A big reason Macs are getting this kind of attention is due to people’s perception that they are more secure. Even the US military has begun using them. He points out that Apple’s X Serve servers, which are gradually becoming more commonplace in Army data centers, are proving their mettle. “Those are some of the most attacked computers there are. But the attacks used[…]
Category: software
The CERIAS Weblog has a post entitled Looking for Trustworthy Alternatives to PDF I commented on the article but wanted to share my comments here as well. Then, it became clear that PDFs adopted mixed loyalties and were disloyal to the computer owner by locking features down and phoning home. Locking features down and phoning home, are not functions of the PDF standard, but rather of the Adobe Reader. There are other reader programs out there which do not lock features, phone home, nor support javascript or downloads of ads. There is a decent list of PDF alternatives here. Last year Adobe forced Microsoft to pull PDF creation support from Office 2007 under the threat of a lawsuit while asking[…]
A buffer overflow has been found in Oracle 10g and a patch won’t be released until mid-January. An attack requires authentication to the database, but assuming that, a successful exploit could execute code remotely. Proof-of-concept exploit code was posted on the Internet last Friday. The best way to prevent this attack is tight network controls and monitoring database logs for unusual activity and logins.
As posted first in Les Jordan’s Life Sciences Developers and Architects blog, you can now download the SAFE Signing Interface for Office 2007 from http://www.codeplex.com/safe. The project is the result of a collaboration between Gemini Security Solutions and Microsoft, and the result provides a fully SAFE-compliant digital signature interface. It’s open source, so you are welcome to download the code, enhance it as you wish, and (hopefully) share your changes back to Codeplex. To learn more about SAFE, go to http://www.safe-biopharma.org.
The Windows Vista Security blog has a great post entitled FAQ: Why can’t I bypass the UAC prompt? which provides good answers to the common questions around User Account Control. It also gives some insight on why Microsoft made the design decisions that they did. We expect that in ordinary day-to-day usage, users should rarely, if ever, see elevation prompts, since most should rarely, if ever, have to perform administrative tasks – and never in a well-managed enterprise. Elevation prompts are to be expected when setting up a new system or installing new software. Beyond that, they should be infrequent enough that they catch your attention when they occur, and not simply trigger a reflexive approval response. UAC is a[…]
The Windows Vista Security Blog had a post today about vulnerability theater: If the vulnerability requires that a user ignore numerous warnings and carries on regardless then the O/S is doing what it’s told to do! Let’s be reasonable: If a user is warned by Outlook that the email looks like spam but clicks on the link anyway, then is warned by IE that the website looks suspicious but continues to navigate to it anyway, if they then ignore the Defender warning that the mortgage calculator they just downloaded is spyware, then, frankly, the O/S is doing what the user intends that it do! Personally, I don’t think too many people get too excited about the Windows vulnerabilities that are[…]