Wednesday, May 12, 2010

Canada blindly following MPAA and implementing US Style DMCA



Canadian Coalition for Electronic Rights � Send A Letter To Ottawa To Stop The Canadian DMCA

The US Digital Millennium Copyright Act is perhaps one of the most hated pieces of legislation known to man. And Canada is blindly following in their footsteps. Last fall (2009) Canadian government held public hearings on this issue and by far majority of Canadians are against such draconian restrictions to fair-use and consumption of digital content. However lobby groups like MPAA have so much power and control over publicly elected officials (through their wallets) we as consumers don't stand a chance. The EU (European Union) caved and passed similar legislation in 2001. Now the EU is pressuring Canada to do the same.

When will these lobby groups realize hanging on to old business models is backwards thinking. Age of couch potato TV viewing are gone, consumers want choice how and when to consume. Moving forward digital media is where its at, if they opened their eyes and looked around they'd see that. MPAA should speak with their customers not take them to court. New technologies and devices like Apple's iPAD are perfect examples digital consumption of media is the future.

Canadians still have a fighting chance the Canadian Coalition for Electronic Rights is fighting for us consumers. They've created a site where Canadian constituents can send a letter to their MP's voicing their concern over Canadian DMCA changes. Process takes 30 seconds; simply choose your MP, add your contact info and a letter is emailed to Prime Minister Harper, the opposition leaders and a number of other cabinet members. Here is the link

If you enjoy digital media and don't want a US style DMCA please send an email to your MP using above link.

Thanks

Monday, March 29, 2010

Microsoft Wireless Keyboards (New Security Risk)

Microsoft Wireless Keyboards Fall! (New Security Risk)


Well it was bound to happen. Just a matter of time before someone created a proof of concept in attacking wireless devices like keyboards. Too bad companies like Microsoft believe such devices are safe and use such crappy encryption techniques. Like this article mentions XOR is a crappy encryption algorithm and Microsoft should not be using it. There are plenty of public encryption algorithms out there which are much..much stronger.

On the flip side its a good thing Security researchers are proving such attacks. Better good guys then bad guys :-) I'm sure we'll see more on this down the road. As hackers move from mainstream attack vectors to new pastures we'll no doubt have new security countermeasures to stop such hardware attacks. But step 1 is better encryption of data stream between device and receiver.

Monday, March 8, 2010

Energizer Battery Charger Contains Remote Access Backdoor

Energizer Battery Charger Contains Remote Access Backdoor | threatpost

This is not the first time a seemingly innocent consumer product contained a trojan. Just another example of a company not doing their due diligence. Instead Energizer probably contracted the lowest bidder to create some add-on piece of software for their consumer product. In this case Energizer's USB battery charger product. I understand the concept of outsourcing however when you're placing your reputation and Energizer has a big one you should ensure you're entrusting it to a reputable vendor. Ultimately Energizer executives are responsible for this embarrassing situation. They should have done their homework. Perhaps the lawsuits that come out of this situation will make them realize the error of their ways. Only time will tell. C'mon corporate America smarten up.

Top 10 Most Vulnerable Apps of 2009

Here is a link: Top 10 Most Vulnerable Apps of 2009 | threatpost

With recent Flash, iPhone/iPad tug of war between Apple and Adobe I'm certainly not surprised why Apple and Steve Jobs have taken their respective position given the findings of this report. It certainly reaffirms what Steve Jobs has recently said that Flash is a buggy resource intensive piece of software. I've been around the block and certainly knew Flash, Shockwave and Adobe Reader require countless updates but did not believe for one minute it would be the #1,2 and 3rd most vulnerable piece of software in 2009.


It certainly doesn't help Adobe in their fight for Flash remaining vital and dominant in the future. With HTML5, it seems Flash may become irrelevant sooner rather than later. We've already had converts like Virgin America drop Flash support in favour of HTML5. With results like these I think Adobe should be doing a lot more to fix their reputation and improve overall security. Is Adobe another Microsoft before their software security initiative a few years ago? Perhaps only time will tell.

The other surprising fact of this report was Quicktime and Safari making the list at number 4 and 5. I've never really liked Quicktime, I've always preferred VLC so I'm not heart broken. But ever since switching to Mac I've really enjoyed Safari. I like its interface, performance and integration into OS X. However lately I've been rethinking my Safari strategy in light of multiple confirmations by security researchers of its short comings. Such things worry me and believe it or not I'm testing Google Chrome. I've been using it for a couple of weeks, so far so good. I won't say there have been no problems but general browsing is really good. And the fact Google Chrome was the only browser not compromised at the 2009 CanSecWest Security Conference helps me accept it as a good and safe alternative to Safari.

I think a turf war between Apple and Adobe is here and inevitable as both fight for dominance over mobile Internet content. What comes of it only time will tell. But certainly both companies have to do a better job in securing their products and guarding their customers.

Wednesday, March 3, 2010

New M86 Security Labs Report Finds 60% of Malicious URLs Pass Unnoticed Through Anti-Virus Scanners and URL Filtering: M86 Security

New M86 Security Labs Report Finds 60% of Malicious URLs Pass Unnoticed Through Anti-Virus Scanners and URL Filtering: M86 Security

I'm really not surprised by these findings. The number one and biggest problem with any security software like you're typical Internet Security Suite is it's a 'Reactive' technology. This means its always behind the curve never in front of it. This means the best you can hope for in terms of detection rates is 98-99% but never with 100% certainty.

Whenever I talk with users and explain this fact they are always shocked. Why is this so surprising to people? Vulnerabilities exist because code is written by humans; therefore you will always have mistakes in code creating the smallest openings for exploitation. Security software is written by humans therefore it will never be perfect and because its a reactive technology it will never catch the latest and greatest zero day exploit.

However security software vendors can help by implementing one small change. Stop marketing their tools as the best and only tool for a safe and secure Internet experience because such marketing hype creates a false sense of security leading everyday users to believe they can do no wrong. Such false sense of security makes people complacent and not think about security. I wish government would wake up and force vendors to disclose such details. We have labeling laws for everything else why don't we have it for software or security appliances. Users should know what they're getting up front before they're taken in by all the hype and spin.

In fact I don't believe things will change anytime soon but only get worse. That is until users wake up from la-la land and become aware their actions have consequences. Ultimately the security fight will not get any better until users take responsibility for their actions and actually think about email, attachments, web sites and general computer best practices.

Until that day security software will fall farther behind and a new sucker will be born every nanosecond. We've all been taught lessons by our parents 'don't talk to strangers' type stuff. Why is it so hard for people to learn similar lessons when it comes to computers and Internet safety?

Tuesday, February 23, 2010

CA Internet Security Suite Win32/ASuspect False Positive

Win32/ASuspect is the latest message users of CA Internet Security Suite are seeing beginning last night February 22nd 2010.

CA is reporting wuweb.dll as a Win32/ASuspect Trojan and automatically placing it in quarantine. This file is part of Windows Update process which is now failing to execute.

I support several customers using CA Internet Security Suite and all have reported seeing this error message. I've done some checking on the web and CA Support forums have lit up like a christmas tree. However because I'm a cautious man I submitted a copy of quarantined wuweb.dll to virustotal.com and as expected results came back clean.

Looks like we have another case of CA False Positive. I'm sure CA will fix this quickly by pushing out new signatures however what worries me is the frequency because CA had a case of false positive last year in 2009 and secondly I'm not seeing much about this on their website. As a good corporate citizen I think CA should be informing their customers about such problems quickly. Consultants such as myself get these frantic phone calls from clients; then we spend our valuable time investigating such matters only to find its a false positive. It would save me much headache if CA could post a message to their Forum or website.

Come on CA I expect better from you.

Monday, February 22, 2010

Google BUZZ ~ Why are people over reacting?


Google once the darling of the online community has recently fallen out of favour. It's at the forefront of a huge backlash over its newly introduced social media service BUZZ.

What I don't understand is why are people over reacting? I mean come on folks what did you think was going to happen with the obscene amount of personal information Google is sitting on at this moment. Google is a for profit corporation; it's not in this for charity reasons. Someone has to pay for all these free services you've taken for granted. Before Gmail there was Hotmail and Yahoo Mail which at one point or another were paid services that is if you wanted a decent amount of storage space for your email. Then along came Google giving everyone 1Gig of FREE storage. At the time this was a bold and unprecedented move. But did you really think this was all for nothing. Come on what kind of fairy tale do you live in? Nothing is FREE. So get over it and move on.

Google has spent millions on their hardware infrastructure and giving it away free for years. At some point they have to figure out how to pay for all this investment. Well BUZZ is just the beginning, this fairytale you've been living is coming to an end. When someone gives you something free with the left hand its only a matter of time before they'll be reaching out with their right hand looking for payment.

Google has an obscene amount of information stored. We've all been happily giving all sorts of personal data to Google and now that they're trying to use it we absolutely freak out. If you don't like it don't use Gmail. Go back to using a local email client like you did in the 90's.

Besides take a minute and review how much personal information people are freely giving away to Facebook and other similar services. If you're happy to give it away to Facebook why are you freaking out if Google uses something you've given away long ago when you signed up for Gmail or Google Docs? If you don't like it stop using their services, it's your choice.