Spiga

Scaling back Web browser security expectations


Today, the browser has become one of the most critical and most used pieces of software on everyone's computer,consequently, it has become the focus of attack by the hackers and viruses.Despite the best efforts of the computer security industry, the number of flaws continues to grow; new ones have already been found in Microsoft Internet Explorer 7, and Firefox is coming under increasing scrutiny by industry experts and attackers. Browser vendors are faced with the impossible task of writing flawless code while hackers only have to spot one error in order to find an attack vector. The emergence of the "exploits-as-a-service" business, where malware is sold to organized crime, has helped to increase the cries for better Web browsers and Web browser security.So how would the ideal browser differ from what we have today? Microsoft has certainly eased its software repair process via automatically installed Internet updates, and the introduction of a software "sandbox" will help limit damage even if a malicious program is able to subvert the operation of IE 7. But what more is required? Web browser security is an ongoing issue because a browser cannot distinguish between malicious and non-malicious content. The critical question is, at what point should the browser defer to the user's decision to allow particular content, versus blocking it regardless? With current browsers, the initial settings make many security decisions automatically on behalf of the user. However, we all know how annoying it is when Outlook, for example, decides for us which attachments we can and cannot open. At the other extreme, it is very disconcerting when a desktop firewall asks for your decision on every incoming probe or request. There are so many, productivity collapses and click fatigue sets in.
We need to change our perception of the Internet and accept that there is an element of risk when we use it, since it's unlikely that browsers will ever be able to make all our security decisions for us or protect us from every danger, known and unknown,there will always be some coding flaws that don't get spotted.

Microsoft Warns Of 4 "Critical" Security Holes


FOUR "Critical" Security Holes
SAN FRANCISCO:- On Tuesday, Microsoft Corporation warned of four security flaws in its software that it categorized as "critical" that could allow attackers to gain control of a user's computer.Microsoft, whose Windows operating system runs some 95 percent of the world's computers, issued the patches as part of its monthly security bulletin.The world's biggest software maker defines a flaw as "critical" when it could allow a damaging Internet worm to replicate without the user's doing anything to the machine.The company said the "critical" patches fixed three holes in its Windows operating system and another in its Content Management Server product. Microsoft also issued another security update for Windows it rated at the lower threat level of "important."ADVERTISEMENT (article continues below)The fixes come a little more than a week after it released a patch outside of the regular monthly update to plug a security hole related to an animated cursor that hackers had used to launch attacks after users clicked on links to malicious Web sites. The company has been working to improve the security and reliability of its software as more and more malicious software target weaknesses in Windows and other Microsoft software.
The latest patches can be downloaded at http://www.microsoft.com/security.

Free Antivirus Download Roots Out Rootkits


Rootkits are becoming more dangerous in comparison to earlier malware because they are often overlooked by conventional antivirus systems. They execute by embedding applications within the operating system, so it is important to correctly distinguish between malicious rootkits and legitimately hidden processes.Rootkits, a specific malware type which hides in other applications or in a computer's operating system kernel, allow malicious applications to collect passwords and sensitive data from the infected computer without user knowledge. This collected personal information can be used to create spam from the infected computer as well as other criminal activities.Larry Bridwell, vice president of Global Security Strategies for Grisoft explain"Rootkits are computer code that attempt to hide their actions and processes, making the job of detecting the code and the harmful processes very difficult,". "AVG Anti-Rootkit is developed to detect and destroy rootkits effectively, without bothering users with false alarms." Even if an antivirus program detected intrusions in files on the hard drive after scanning every file, it cannot completely remove the altered files. Once the user reboots the computer, the rootkit recreates the necessary files."Rootkits fool these antivirus applications and change the kernel so they can operate at ring 0 as hidden files. When a traditional antivirus scan is performed, they find nothing," said Carlson.
One Thinking Of Removal
Grisoft decided to release the free rootkit download now rather than waiting. The company plans to offer a paid version of the rootkit technology in the fall as part of the release of its version 8.0 security suite. "We didn't want to hold up getting this protection into the hands of 50 million people relying on our free security products," Carlson explained

Secure Your Wireless Network

No one can intercepts your Wi-Fi traffic,just Follow a few easy steps.

The first line of defense for your Wi-Fi network is Encryption, which encodes the data transmitted between PC and wireless router. Unfortunately, most routers ship with encryption turned off, and many users don't turn it on, leaving themselves completely exposed. If you haven't already, enable your router's encryption, and use the strongest form supported by your network. The Wireless Protected Access (WPA) protocol and more recent WPA2 have supplanted the older and less-secure Wireless Encryption Protocol (WEP).
Go with WPA or WPA2 if at all possible, since WEP is relatively easy to crack. (You have to use the same form on all devices on your network; you can't mix WEP and WPA.) The keys used by WPA and WPA2 change dynamically, which make them nearly impossible to hack. Use a strong password for your encryption key, such as a combination of letters and numbers of 14 characters or more.Make sure you change the default network name and password on your router. Doing so will make it much more difficult for hackers to break into your router and commandeer its settings.
FIREWALL
The firewall built into your router prevents hackers on the Internet from getting access to your PC. But it does nothing to stop people in range of your Wi-Fi signal from getting onto your network--and with the latest high-performance equipment, your Wi-Fi signal could reach clear down the block. Without encryption and other protective measures, anyone can use readily available tools to see all your Wi-Fi traffic.
Secure notebook at public Wi-Fi hotspots
Make sure it's a legitimate hotspot, Nefarious types have been known to set up pirate routers with familiar SSID names like "wayport" or "t-mobile," and then use them to capture unsuspecting users' log-on information and other private data. Verify that your PC's software firewall is turned on, and that Windows' file-sharing feature is off; it's off by default in Windows XP with Service Pack 2. To check this setting, open Control Panel and choose Windows Firewall (you may have to click Security Center first in XP or Security in Vista). In XP, select the Exceptions tab, and look in the Programs and Services to make sure "File and Printer Sharing" is unchecked. In Vista, click Change settings, then select the Exceptions tab and follow the instructions for XP. Never send bank passwords, credit card numbers, confidential e-mail, or other sensitive data unless you're sure you're on a secure site: Look for the lock icon in the bottom-right corner of your browser, as well as a URL in the address bar that begins with https. Such sites build in their own encryption. Always turn your Wi-Fi radio off when you're not at a hotspot: Hackers can use it to create peer-to-peer Wi-Fi connections with your computer and access it directly.

Unsafe computer users:Prosecute

victims of computer viruses should be prosecuted.

In todays world,Internet is playing a vital role in everyone's life and that unprotected computers are at risk from computer viruses, trojans, rootkits, spyware, adware, and malware in general. Security software is everywhere.An estimated 90 percent of all email is spam. That's nine out of 10 phone calls you receive coming from telemarketers, or 54 minutes of every one-hour television show taken up by commercials. What would you do about that?Antivirus and firewall software is so widely available that it is a complete mystery why anyone would not have it. Since most software either upgrades itself or prompts the user to install upgrades, there is no reason not to have the latest and most secure versions. Responsible computer users know not to click on strange attachments in emails from mysterious senders but antivirus software has become so dummy-proof that it will intercept viruses from attachments users click on anyway (assuming the antivirus software is up-to-date, that is).

What should be the punishment that fits the crime, you ask? Long and Hard prison time is tempting, but the prisons are already overcrowded with criminals far less disruptive to society than spammers. Revoking Internet access goes without saying. Perhaps a more appropriate punishment would be on the scale of that given to the mythological Sisyphus. But instead of having to roll a stone to the top of a hill only to have it roll back down again for all of eternity, let the spambot owners be damned to cleaning out an inbox only to have it filled back up with spam over and over and over again.
Do you think all this can stop it??????



Banks Tighten Web Security

Banks tighten Web security to help keep thieves out of accounts

Banks has tighten the web security to help keep thieves out of accounts.The Community bank has been the target of so-called "phishing" e-mails in which crooks posing as the bank promise a $50 reward to people willing to answer a five-question survey. To receive the bogus reward, participants are instructed to type in their online access ID, password, debit card number and other confidential data.At the same time, a computerized telephone campaign run by anonymous thieves was contacting people in West Bend - on the likely chance it would connect with West Bend Savings Bank customers - to falsely warn of fraudulent activity in their account and ask them to call a special number to verify private financial information."They will want you to give your credit or debit card number, and if you do that, they will ask for your PIN; or for a credit card, ask for the three numbers on the back," said Rick Larson, the bank's chief operating officer. "The moment you do that, they are going on a spending spree."The good news is that as frustrating as it sometimes is for banks to protect consumers from Internet and telephone predators, they are achieving some success at keeping them out of consumers' online bank accounts.Under pressure from regulators, banks and credit unions have been making it more difficult for thieves to gain access to online bank accounts. That's important because about 40% of U.S. households now do some banking over the Internet, according to Celent, a Boston-based technology research firm.