Skip to content

CyberSecurity Institute

Security News Curated from across the world

Menu
Menu

Category: News

Mac OS X security myth exposed

Posted on June 25, 2004December 30, 2021 by admini

The stats, based on a database of security advisories for more than 3,500 products during 2003 and 2004 sheds light on the real security of enterprise applications and operating systems, according to the firm.

One thing the hard figures have shown is that OS X’s reputation as a relatively secure operating system is unwarranted, Secunia said.

This year and last year Secunia tallied 36 advisories on security issues with the software, many of them allowing attackers to remotely take over the system — comparable to figures on operating systems such as Windows XP Professional and Red Hat Enterprise Server.

“Secunia is now displaying security statistics that will open many eyes, and for some it might be very disturbing news,” said Secunia chief executive Niels Henrik Rasmussen.

A few other organizations maintain comparable lists, including the Open Source Vulnerability Database (OSVDB) and the Common Vulnerabilities and Exposures (CVE) database, which provides common names for publicly known vulnerabilities.

Windows XP Professional saw 46 advisories in 2003-2004, with 48 percent of vulnerabilities allowing remote attacks and 46 percent enabling system access, Secunia said.

Suse Linux Enterprise Server (SLES) 8 had 48 advisories in the same period, with 58 percent of the holes exploitable remotely and 37 percent enabling system access.

A recent Forrester Research Inc. study comparing Windows and Linux vendor response times on security flaws was heavily criticized for its conclusion that Linux vendors took longer to release patches.

http://www.computerworld.com.au/index.php/id;1870365808;fp;16;fpid;0

Read more

Wi-Fi Security Spec Ratified

Posted on June 24, 2004December 30, 2021 by admini

Proponents of the standard said that the 802.11i specification could have an immediate impact on VPN infrastructure, which could be relegated to a lesser role inside a corporate network.

The standard was ratified on 24th June at an IEEE standards committee meeting in Piscataway, N.J. The 802.11i standard adds a needed layer of security to Wi-Fi, which has become widespread both in the consumer and corporate spaces.

Early attempts at security, such as WEP (Wired Equivalent Privacy), provided some basic security but were derided as too easy to crack.

“Intel is ecstatic,” said Robin Ritch, director of security industry marketing for Intel Corp. in Santa Clara, Calif., who said all of the company’s Centrino chip sets, including the older models, are compliant with the specification.

As expected, vendors are already rolling out firmware enabling 802.11-compliant security protocols, although the software won’t officially be pushed to customers until September, when the Wi-Fi Alliance is expected to begin interoperability testing to make sure devices can talk to one another, Ritch said. Devices compliant with the 802.11i spec will likely be certified as compliant with WPA2, the second generation of Wi-Fi Protected Access, she said.

802.11i’s encryption protocols are based on the AES (Advanced Encryption Standard) and meet the limited encryption requirements for the Federal Information Processing Standard 140-2 specification for the protection of sensitive information.

The new standard will add Layer 2 security to a Wi-Fi card, sufficient for wireless access inside a corporate network, Ritch said.

In the early days of Wi-Fi, Intel recommended users connect to a VPN while roaming wirelessly, even when inside their corporate network.

The security provided by 802.11i is sufficient enough that IT managers can eliminate VPNs except when workers are connecting remotely, such as at a hotel, Ritch said.

Intel’s own IT staff plans to relax its security restrictions, she said, eliminating the use of internal VPNs while employees are inside their own network.

Chris Bolinger, manager of the Field and Partner Marketing team in the Wireless Networking Business Unit of Cisco Systems, Inc., Santa Clara, Calif., said it is natural that some customers will want to migrate away from VPNs to standards-based solutions such as 802.11i. However, many customers will also stay with WPA unless they’re given a compelling reason to move to AES, he said. “We’ve always tried to provide solutions to meet customer demand in the wireless LAN space,” Bolinger said.

The performance penalty users will pay for turning on the additional 802.11i functionality is unknown. In tests of Intel’s Grantsdale/Intel 915 chip set, for example, turning on high-definition audio features integrated into the chip set required a significant amount of CPU power, according to a recent ExtremeTech review. Intel spokesman Mark Miller said Intel had not tested the effects of the new 802.11i firmware on battery life to his knowledge, but he estimated that the effects would be “negligible” on the battery life of a Centrino-based notebook.

http://www.eweek.com/article2/0,1759,1616979,00.asp

Read more

The Network Strikes Back: Experts Worry About Tech Retaliation

Posted on June 21, 2004December 30, 2021 by admini

Symbiot Security says its new Intelligent Security Infrastructure Management Systems not only defends networks but lets them fight back, too.

Though the notion of striking back against “bad guys” may satisfy primal urges, most security experts question whether retaliation will actually halt cyberattacks. Ideas about going on the offensive against Internet attackers “have been bounced around for a while,” said senior analyst Jesse Dougherty of the security firm Sophos. Hackers, worms and data attacks are costing companies dearly, and open the door to identity theft and the loss of intellectual property.

The offering, known as iSIMS, comes amid growing frustration over computer intruders. In documents on the Austin, Texas, company’s Web site, Symbiot advocates a gradual escalation of action based on the best information available and the customer’s preference. A position paper attributed to Symbiot’s executives and posted on its Web site broadly outlines the counter-strike philosophy.

“On the Rules of Engagement for Information Warfare” says computer intrusions deserve a response in kind – including “asymmetric” countermeasures that can include flooding the attacking computers with data, rendering them Internet-blind, and other measures to neutralize the problem.

The responses mirrored the content of Symbiot’s Web site, which describes the 18-employee company as “emerging as a leader” in security infrastructure management. For instance, if a hacker takes advantage of vulnerabilities on multiple PCs to relay the assault through them, then the victim can trace it by exploiting the same vulnerabilities as the initial act.

In the past, some attempts to fight fire with fire have misfired. “We’ve seen worms that have had major impact like causing delays in airline schedules, shutting down ATM machines, 911 systems and so on,” said Dorothy Denning, a professor of defense analysis at the Naval Postgraduate School.

More info: http://www.crn.com/showArticle.jhtml?articleID=22101131

Read more

June News

Posted on June 20, 2004December 30, 2021 by admini

From_the_desk_of_Paul_-_06152004.pdf

Read more

Senate debates cybercrime treaty

Posted on June 18, 2004December 30, 2021 by admini

Richard Lugar, R-Ind., said at a hearing Thursday that the Council of Europe’s cybercrime treaty should be ratified quickly because it “will help the United States continue to play a leadership role in international law enforcement and will advance the security of Americans at home and abroad.” Lugar is the chairman of the Senate Foreign Relations Committee.

The treaty would require participating nations to update their laws to reflect computer crimes such as unauthorized intrusions into networks, the release of worms and viruses, and copyright infringement. The measure, which has been ratified by Albania, Croatia, Estonia, Hungary, Lithuania and Romania, also includes arrangements for mutual assistance and extradition among participating nations.

If ratified by the Senate, the treaty would “enhance the United States’ ability to receive, as well as render, international cooperation in preventing, investigating and prosecuting computer-related crime,” Samuel Witten, a legal adviser at the U.S. State Department, said when he testified Thursday.

“Such international cooperation is vitally important to our efforts to defend against cyberattacks and generally improve global cybersecurity.” An addition to the treaty would require nations to imprison anyone guilty of “insulting publicly, through a computer system” certain groups of people based on characteristics such as race or ethnic origin, a requirement that could make it a crime to e-mail jokes about Polish people or question whether the Holocaust occurred.

The Department of Justice has said that it would be unconstitutional for the United States to sign that addition because of the First Amendment’s guarantee of freedom of expression. Because of that objection, the Senate is not considering the addition, but other nations ratifying the treaty are expected to adopt both documents. Still, some civil liberties groups have criticized the portion of the treaty that is moving through the Senate.

The Electronic Privacy Information Center on Thursday sent a letter to the Foreign Relations Committee saying it should not be ratified because it would “would create invasive investigative techniques while failing to provide meaningful privacy and civil liberties safeguards.”

More info: http://news.com.com/Senate+debates+cybercrime+treaty/2100-1028_3-5238865.html

Read more

Shortage of computer security experts hampers agencies

Posted on June 10, 2004December 30, 2021 by admini

“There is an incredibly shrinking pool of IT security professionals in government,” said Jack Johnson, chief security officer at the Homeland Security Department. Johnson is working on developing the Homeland Security Information Network, which he said would be at Defense Department “secret level” by year’s end. He also said Homeland Security is looking to redesign personnel security to prevent internal cyber attacks.

“The sharing amongst bad guys is growing,” he said at a SecureE-Biz.net conference. “The sharing amongst the good guys on procurement, technology and approach needs to grow at an equal or greater rate.

The president last year signed a law authorizing a significant increase in cyber-security R&D funding, but it was not requested in the fiscal 2005 White House budget proposal.

Thomas O’Keefe, deputy director of the Federal Aviation Administration office of information systems security, said more research and development, and more collaboration among researchers and industry, is needed on cybersecurity. The air-traffic network is completely separate from the Internet, as well as other aspects of the FAA network, making it impossible for viruses to spread from those sources, he said.

More info: http://www.govexec.com/dailyfed/0604/061004tdpm2.htm

Read more

Posts pagination

  • Previous
  • 1
  • …
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • …
  • 145
  • Next

Recent Posts

  • Security Operations Weekly — July 19, 2026
  • Security Operations Weekly — July 19, 2026 — Interactive Topic Map
  • DevSecOps Weekly — July 19, 2026

Archives

  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • November 2025
  • April 2024
  • September 2023
  • August 2023
  • July 2023
  • June 2023
  • April 2023
  • March 2023
  • February 2022
  • January 2022
  • December 2021
  • September 2020
  • October 2019
  • August 2019
  • July 2019
  • December 2018
  • April 2018
  • December 2016
  • September 2016
  • August 2016
  • July 2016
  • April 2015
  • March 2015
  • August 2014
  • March 2014
  • August 2013
  • July 2013
  • June 2013
  • May 2013
  • April 2013
  • March 2013
  • February 2013
  • January 2013
  • October 2012
  • September 2012
  • August 2012
  • February 2012
  • October 2011
  • August 2011
  • June 2011
  • May 2011
  • April 2011
  • February 2011
  • January 2011
  • December 2010
  • November 2010
  • October 2010
  • August 2010
  • July 2010
  • June 2010
  • May 2010
  • April 2010
  • March 2010
  • February 2010
  • January 2010
  • December 2009
  • November 2009
  • October 2009
  • September 2009
  • June 2009
  • May 2009
  • March 2009
  • February 2009
  • January 2009
  • December 2008
  • November 2008
  • October 2008
  • September 2008
  • August 2008
  • July 2008
  • June 2008
  • May 2008
  • April 2008
  • March 2008
  • February 2008
  • January 2008
  • December 2007
  • November 2007
  • October 2007
  • September 2007
  • August 2007
  • July 2007
  • June 2007
  • May 2007
  • April 2007
  • March 2007
  • February 2007
  • January 2007
  • December 2006
  • November 2006
  • October 2006
  • September 2006
  • August 2006
  • July 2006
  • June 2006
  • May 2006
  • April 2006
  • March 2006
  • February 2006
  • January 2006
  • December 2005
  • November 2005
  • October 2005
  • September 2005
  • August 2005
  • July 2005
  • June 2005
  • May 2005
  • April 2005
  • March 2005
  • February 2005
  • January 2005
  • December 2004
  • November 2004
  • October 2004
  • September 2004
  • August 2004
  • July 2004
  • June 2004
  • May 2004
  • April 2004
  • March 2004
  • February 2004
  • January 2004
  • December 2003
  • November 2003
  • October 2003
  • September 2003

Categories

  • AI-ML
  • AI-Ops
  • Augment / Virtual Reality
  • Blogging
  • Cloud
  • DR/Crisis Response/Crisis Management
  • Editorial
  • Financial
  • Make You Smile
  • Malware
  • Mobility
  • Motor Industry
  • News
  • OTT Video
  • Pending Review
  • Personal
  • Product
  • Regulations
  • Secure
  • Security Industry News
  • Security Operations
  • Statistics
  • Threat Intel
  • Trends
  • Uncategorized
  • Warnings
  • WebSite News
  • Zero Trust

Meta

  • Log in
  • Entries feed
  • Comments feed
  • WordPress.org
© 2026 CyberSecurity Institute | Powered by Superbs Personal Blog theme