At the 2007 WWDC, Steve Jobs announced the immediate availability of Beta 3 of Apple’s web browser, Safari on Windows as well as Mac. David Maynor from Errata Security posted the first vulnerability found in Safari before it was even mentioned in Jobs’ keynote. BetaNews has a good article entitled ‘Day One’ for Safari for Windows Becomes Zero-Day Nightmare. Apple’s Web site touts, “Apple engineers designed Safari to be secure from day one.” As Larholm explained on his blog, that may very well be correct: Its engineers obviously designed Safari to take advantage of security protocols in the OS X operating system, as evidenced by function calls to those protocols Larholm located inside the source code for the Windows version[…]

Just got word that one of yesterday’s patch Tuesday flaws was a critical vulnerability in CAPICOM. We have been big CAPICOM advocates as it enables IE to do some great PKI stuff, and now it is time to get it patched. We’re going to be alerting customers as soon as we get good lists of who is using it, but in the meantime, check out the link above and update yourself if you think you might have installed CAPICOM or used a website that uses it.

Several people are writing about the once-not free-now-free encryption tool SecureZip. Don’t be fooled by the talk of digital certificates however. The free version doesn’t let you use anything more than passwords to encrypt files (albeit with 256 bit AES) – it’s really just Winzip encryption. The layout of the software is also a bit confusing, the word signatures is thrown around and no warnings are given if you create a SecureZip file that isn’t encrypted. (Files are not encrypted by default). You can read the review or find out how easy it is to crack Winzip passwords.

The first commercial product that enhances password security by analyzing the way they are typed is being rolled out. They are calling it bio-security, though I don’t know where the “bio” comes from. A US company is aiming to reduce the risk of identity theft by introducing ‘bio-security’ to passwords, meaning that users would have to type their user name and password with consistent speed in order to be logged in. The technology, which measures the time for which keys are held down, as well as the length between strokes, takes advantage of the fact that most computer users evolve a method of typing which is both consistent and idiosyncratic – especially for words used frequently such as a user[…]

As reported by NBC4 : A Turbo Tax customer herself, the woman attempted to access some past filings and the route she took online opened returns for several others with the same last name but different first initials. She was able to access tax returns for Turbo Tax customers she never met in different parts of the country. On her screen, she found everything needed for electronic filing from bank account to routing digits and Social Security numbers. OK, so if some innocent woman accidentally stumbled upon this, what is the likelihood that the real bad guys haven’t just seen it, but exploited it too? If I were a paying customer of TurboTax Online, I would immediately demand they remove[…]

Operating system patches get all of the attention when it comes to vulnerabilities – but outdated applications running on your machine can be just as dangerous. I came across File Hippo [via Lifehacker ] that checks to see what needs updating and provides the links to do so (Windows only). Corporate users may want to check their policies before using, but home users it might be a good idea to run it once a week. Mac users can add App Update – which does the same thing as File Hippo – to their dashboards.