Monday, March 29, 2010

Microsoft Wireless Keyboards (New Security Risk)

Microsoft Wireless Keyboards Fall! (New Security Risk)


Well it was bound to happen. Just a matter of time before someone created a proof of concept in attacking wireless devices like keyboards. Too bad companies like Microsoft believe such devices are safe and use such crappy encryption techniques. Like this article mentions XOR is a crappy encryption algorithm and Microsoft should not be using it. There are plenty of public encryption algorithms out there which are much..much stronger.

On the flip side its a good thing Security researchers are proving such attacks. Better good guys then bad guys :-) I'm sure we'll see more on this down the road. As hackers move from mainstream attack vectors to new pastures we'll no doubt have new security countermeasures to stop such hardware attacks. But step 1 is better encryption of data stream between device and receiver.

Monday, March 8, 2010

Energizer Battery Charger Contains Remote Access Backdoor

Energizer Battery Charger Contains Remote Access Backdoor | threatpost

This is not the first time a seemingly innocent consumer product contained a trojan. Just another example of a company not doing their due diligence. Instead Energizer probably contracted the lowest bidder to create some add-on piece of software for their consumer product. In this case Energizer's USB battery charger product. I understand the concept of outsourcing however when you're placing your reputation and Energizer has a big one you should ensure you're entrusting it to a reputable vendor. Ultimately Energizer executives are responsible for this embarrassing situation. They should have done their homework. Perhaps the lawsuits that come out of this situation will make them realize the error of their ways. Only time will tell. C'mon corporate America smarten up.

Top 10 Most Vulnerable Apps of 2009

Here is a link: Top 10 Most Vulnerable Apps of 2009 | threatpost

With recent Flash, iPhone/iPad tug of war between Apple and Adobe I'm certainly not surprised why Apple and Steve Jobs have taken their respective position given the findings of this report. It certainly reaffirms what Steve Jobs has recently said that Flash is a buggy resource intensive piece of software. I've been around the block and certainly knew Flash, Shockwave and Adobe Reader require countless updates but did not believe for one minute it would be the #1,2 and 3rd most vulnerable piece of software in 2009.


It certainly doesn't help Adobe in their fight for Flash remaining vital and dominant in the future. With HTML5, it seems Flash may become irrelevant sooner rather than later. We've already had converts like Virgin America drop Flash support in favour of HTML5. With results like these I think Adobe should be doing a lot more to fix their reputation and improve overall security. Is Adobe another Microsoft before their software security initiative a few years ago? Perhaps only time will tell.

The other surprising fact of this report was Quicktime and Safari making the list at number 4 and 5. I've never really liked Quicktime, I've always preferred VLC so I'm not heart broken. But ever since switching to Mac I've really enjoyed Safari. I like its interface, performance and integration into OS X. However lately I've been rethinking my Safari strategy in light of multiple confirmations by security researchers of its short comings. Such things worry me and believe it or not I'm testing Google Chrome. I've been using it for a couple of weeks, so far so good. I won't say there have been no problems but general browsing is really good. And the fact Google Chrome was the only browser not compromised at the 2009 CanSecWest Security Conference helps me accept it as a good and safe alternative to Safari.

I think a turf war between Apple and Adobe is here and inevitable as both fight for dominance over mobile Internet content. What comes of it only time will tell. But certainly both companies have to do a better job in securing their products and guarding their customers.

Wednesday, March 3, 2010

New M86 Security Labs Report Finds 60% of Malicious URLs Pass Unnoticed Through Anti-Virus Scanners and URL Filtering: M86 Security

New M86 Security Labs Report Finds 60% of Malicious URLs Pass Unnoticed Through Anti-Virus Scanners and URL Filtering: M86 Security

I'm really not surprised by these findings. The number one and biggest problem with any security software like you're typical Internet Security Suite is it's a 'Reactive' technology. This means its always behind the curve never in front of it. This means the best you can hope for in terms of detection rates is 98-99% but never with 100% certainty.

Whenever I talk with users and explain this fact they are always shocked. Why is this so surprising to people? Vulnerabilities exist because code is written by humans; therefore you will always have mistakes in code creating the smallest openings for exploitation. Security software is written by humans therefore it will never be perfect and because its a reactive technology it will never catch the latest and greatest zero day exploit.

However security software vendors can help by implementing one small change. Stop marketing their tools as the best and only tool for a safe and secure Internet experience because such marketing hype creates a false sense of security leading everyday users to believe they can do no wrong. Such false sense of security makes people complacent and not think about security. I wish government would wake up and force vendors to disclose such details. We have labeling laws for everything else why don't we have it for software or security appliances. Users should know what they're getting up front before they're taken in by all the hype and spin.

In fact I don't believe things will change anytime soon but only get worse. That is until users wake up from la-la land and become aware their actions have consequences. Ultimately the security fight will not get any better until users take responsibility for their actions and actually think about email, attachments, web sites and general computer best practices.

Until that day security software will fall farther behind and a new sucker will be born every nanosecond. We've all been taught lessons by our parents 'don't talk to strangers' type stuff. Why is it so hard for people to learn similar lessons when it comes to computers and Internet safety?

Tuesday, February 23, 2010

CA Internet Security Suite Win32/ASuspect False Positive

Win32/ASuspect is the latest message users of CA Internet Security Suite are seeing beginning last night February 22nd 2010.

CA is reporting wuweb.dll as a Win32/ASuspect Trojan and automatically placing it in quarantine. This file is part of Windows Update process which is now failing to execute.

I support several customers using CA Internet Security Suite and all have reported seeing this error message. I've done some checking on the web and CA Support forums have lit up like a christmas tree. However because I'm a cautious man I submitted a copy of quarantined wuweb.dll to virustotal.com and as expected results came back clean.

Looks like we have another case of CA False Positive. I'm sure CA will fix this quickly by pushing out new signatures however what worries me is the frequency because CA had a case of false positive last year in 2009 and secondly I'm not seeing much about this on their website. As a good corporate citizen I think CA should be informing their customers about such problems quickly. Consultants such as myself get these frantic phone calls from clients; then we spend our valuable time investigating such matters only to find its a false positive. It would save me much headache if CA could post a message to their Forum or website.

Come on CA I expect better from you.

Monday, February 22, 2010

Google BUZZ ~ Why are people over reacting?


Google once the darling of the online community has recently fallen out of favour. It's at the forefront of a huge backlash over its newly introduced social media service BUZZ.

What I don't understand is why are people over reacting? I mean come on folks what did you think was going to happen with the obscene amount of personal information Google is sitting on at this moment. Google is a for profit corporation; it's not in this for charity reasons. Someone has to pay for all these free services you've taken for granted. Before Gmail there was Hotmail and Yahoo Mail which at one point or another were paid services that is if you wanted a decent amount of storage space for your email. Then along came Google giving everyone 1Gig of FREE storage. At the time this was a bold and unprecedented move. But did you really think this was all for nothing. Come on what kind of fairy tale do you live in? Nothing is FREE. So get over it and move on.

Google has spent millions on their hardware infrastructure and giving it away free for years. At some point they have to figure out how to pay for all this investment. Well BUZZ is just the beginning, this fairytale you've been living is coming to an end. When someone gives you something free with the left hand its only a matter of time before they'll be reaching out with their right hand looking for payment.

Google has an obscene amount of information stored. We've all been happily giving all sorts of personal data to Google and now that they're trying to use it we absolutely freak out. If you don't like it don't use Gmail. Go back to using a local email client like you did in the 90's.

Besides take a minute and review how much personal information people are freely giving away to Facebook and other similar services. If you're happy to give it away to Facebook why are you freaking out if Google uses something you've given away long ago when you signed up for Gmail or Google Docs? If you don't like it stop using their services, it's your choice.

Tuesday, November 24, 2009

A Great Manager should be Human

Over the years I've had my share of snakes and weasels looking for the next great score or political angle to play. They spent more time scheming, planning political tactics then actual productive work. If they devoted a fraction of this energy to productive business goals the term 'overtime' would be extinct. Speaking of extinct I've had my share of stubborn dumb-ass mules (when I say ass I'm referring to a four legged animal not human body part) who are absolutely clueless yet stubbornly argue their position why a project or idea should be implemented their way despite their way having more holes then the Titanic. This breed should have died out long ago from the corporate world; yet they've managed to proliferate and multiply like rabbits. Then of course you've got your elephants that have been there since the last ice age. They seem to know everything and everyone yet are completely unmovable if change is required because we all know times change and business models must evolve or die. But these elephants continue to run the show like its 1855 and their favorite justification why things should not change "We've always done it this way and its worked well thus far". Somehow everyone realizes business model must change but ultimately leave things status-quo because no one is willing to take down the elephant. Then of course you have your hawks who watch you with these piercing eyes from across the room micro managing your every move in the cubicle maze you call home eight hours a day. Why delegate if you're going to criticize my work and do it your way in the end, might as well do it yourself and don't waste my time. Speaking of status-quo the chameleon is best at this game. A manager that is never there especially when a tough decision must be made or physically not there; they manage to disappear leaving you on your own. Of course the other great chameleon talent is to change their color with the latest flavor of the week idea how to improve morale productivity or what have you. If someone comes up with a crazy idea they're the first to jump on it and push you like crazy only to change next week. Ultimately the disappearing chameleon gets all the credit for your hard work. Then of course you have your Lion; king of the office jungle that thinks they run the whole show or at least act like they do. The lion will devour and eliminate all to ensure their place on top of the office food chain remains in tact. They will motivate weasels and snakes under their control to enact sabotage and ensure projects and ideas they don't approve fail. They recruit hawks from other departments to be their eyes and ears to ensure their own agenda moves ahead with little thought for what is best for the company. Then of course there is us; the lonely tiny ant tirelessly working at all hours including weekends if necessary never recognized, for its efforts in keeping the office jungle clean. Simply stepped on or brushed aside for convenience. The corporate world is a jungle and if I could wish for a great boss I'd want them to be simply human.