Category Archives: Internet Security
China’s cybersecurity law grants government ‘unprecedented’ control over foreign tech – The Register
China's new cybersecurity law will enable its government to discover potential security vulnerabilities of any company doing business in the country, threat intelligence firm Recorded Future warns.
The law grants the China Information Technology Evaluation Center (CNITSEC), an office in the Ministry of State Security (MSS), the power to request source code and other intellectual property of tech suppliers operating in the country. Information gleaned might easily be exploited by CNITSEC in furtherance of its intelligence operations, Recorded Future claims.
Priscilla Moriuchi, director of strategic threat development at the firm, reckons the measures place companies between a rock and a hard place. Vendors either have to give up their proprietary technology and IP, or lose out on one of the world's biggest and most important markets.
A white paper by Recorded Future, published Thursday, looks at the law's impact as well as offering practical advice on how firms might navigate the rules while trading in China. Recorded Future's cautionary take follows previous criticism that the law posed compliance difficulties to foreign companies because it imposed what's been described as onerous, vague, and broad new legal requirements.
Bill Hagestad, a former US Marine Corps lieutenant colonel turned cyber conflict author and researcher, told El Reg that China's tough new regulations come from a mindset moulded by "haunting memories" of when the Eight-Nation Alliance invaded and attempted to colonise China in the early 1900s.
"As a result of this foreign effrontery, China lives daily with the shame of having almost been ruled by foreign devils," Hagestad explained. "This historical basis is the foundation for the People's Republic of China's New Internet Security Law.
"The digital geography of the Middle Kingdom is now sacrosanct and will not be violated as was China's geography physically during the beginning of the 19th century."
The impact on foreign businesses has been severalfold, according to Hagestad.
"IBM has acquiesced building servers for Larkspur to serve (no pun intended) the Chinese banking industry; Apple has removed nefarious VPN applications from its app store to appease the Communist boys and girls in Beijing... ALL foreign companies must submit to data inspections, and most importantly, if there is Chinese data it can never leave the Middle Kingdom."
Sponsored: The Joy and Pain of Buying IT - Have Your Say
Excerpt from:
China's cybersecurity law grants government 'unprecedented' control over foreign tech - The Register
Cloud-based CAE HPC Partnership Focuses on Speed and Security of Data Transfer – ENGINEERING.com
The collaboration between Rescale and Equinix provides a scalable HPC solution. (Image courtesy of Rescale)
Engineers and managers also are concerned that trade secrets, proprietary designs and other intellectual property (IP) may be exposed to outsiders, particularly when data is communicated over the public Internet. Cloud-based high-performance computing (HPC) solutions often communicate data over the Internet to provide convenient global accessibility, but this communication network can result in undesired exposure of data, private information and competitive information. While high computational capacity is needed, viable computing solutions must provide sufficient security to protect user designs, information and privacy.
The recent alliance between Rescale, an HPC environment simulation and analysis tool suites provider, and Equinix solves the security issues and significantly improves HPC capability. The platforms provided through this collaboration allow users to enhance computational capability without risking IP, privacy and security.
The Equinix platform provides access to multiple cloud computing resources through a common interface (Image courtesy of Equinix.)
This collaboration offers a holistic approach to improving performance for computationally intensive engineering simulation and analysis. Users can integrate their own equipment with the cloud computing resources or draw on them as needed. The net result is a higher performance and cost-efficient HPC solution.
For more information visit the Rescale and Equinix websites.
Go here to read the rest:
Cloud-based CAE HPC Partnership Focuses on Speed and Security of Data Transfer - ENGINEERING.com
Symantec CEO Sees Broad-Based Internet Security Threats – Bloomberg
Bloomberg | Symantec CEO Sees Broad-Based Internet Security Threats Bloomberg Greg Clark, Symantec chief executive officer, discusses the company's research on ransomware attacks. He speaks with Bloomberg's Emily Chang on "Bloomberg Technology." (Source: Bloomberg) ... |
See original here:
Symantec CEO Sees Broad-Based Internet Security Threats - Bloomberg
Expert warns sexting is seen as normal by many young people – Evening Echo Cork
SEXUALLY explicit messages, photographs and images sent back and forth between young people is considered normal modern day flirting, according to internet security expert Avril Ronan.
Ms Ronan, who is head of internet security at Trend Micro, said the phenomenon called sexting is now viewed as normal and this new culture is putting pressure on teens to share such images.
I am not saying it is acceptable, but I am saying kids these days see it as modern day flirting.
Receiving naked images of an under 18-year-old is considered a child pornography crime under Irish legislation, however, according to Mr Ronan, there is an epidemic of young people engaged in such activity.
Sexting under the age of 18 is considered a professional distribution of child sexual abuse material, but kids dont know that, she said.
Ms Ronan said it was important to educate children on the legal guidelines surrounding the use of the internet and mobile phone applications.
Kids are smart and savvy all they need is the information and they will be wiser of it, she added.
The internet expert said the trend is putting a lot of young people in a compromising position and also under a lot of pressure.
It puts a lot of pressure on people and again how much of a violation of your privacy and your safety and your security it can be when you post images of yourself or others in compromising situations online.
In some situations, the images can lead to cyber bullying in schools and in communities.
You get exposed to cyber bullying as a result of it, Ms Ronan said.
The internet safety expert advised people to think twice before posting an intimate image online or sending a sexually explicit message or photograph to another individual as in some cases it can lead to blackmail called sextortion.
If you are a target of cyber bullying already you become automatically a potential victim or client for a predator to approach and befriend and build a trusting relationship with and then leads to sexual coercion which is when they blackmail you for money they may get you to take naked photographs of yourself, video yourself naked.
Ms Ronan encouraged young people to take care online and be savvy with the messages they send to others.
You may think you are in a trusting relationship and it turns out that they are not who they say they were and then they may ask you for money or they are going to potentially expose you to everyone in your broader community.
See the article here:
Expert warns sexting is seen as normal by many young people - Evening Echo Cork
Internet Explorer – Wikipedia
Internet ExplorerOriginal author(s)Thomas ReardonDeveloper(s)MicrosoftInitial releaseAugust16, 1995; 22 years ago(1995-08-16)Last release(s)Windows11.0.45 (11.0.9600.10586.0) (August8, 2017; 21 days ago(2017-08-08)) [][1]Mac5.2.3 (June16, 2003; 14 years ago(2003-06-16)) []Unix5.01 SP1 (2001; 16years ago(2001)) []Development statusDiscontinued but still maintained[2]Written inC++[3]Operating systemWindows, Mac OS X, Solaris, HP-UXIncluded withWindows 95 OSR1 and laterWindows NT 4 and laterMac OS 8.1 through Mac OS X 10.2Xbox 360Xbox OneEnginesTrident, ChakraPlatformIA-32, x64, ARMv7, IA-64, MIPS, Alpha, PowerPC, 68k, SPARC, PA-RISCAvailable in95 languages[4]TypeWeb browserFeed readerLicenseProprietary, requires a Windows license[5]Websitemicrosoft.com/ieStandard(s)HTML5, CSS3, WOFF, SVG, RSS, Atom, JPEG XRInternet Explorer versions:
Internet Explorer[a] (formerly Microsoft Internet Explorer[b] and Windows Internet Explorer,[c] commonly abbreviated IE or MSIE) is a series of graphical web browsers developed by Microsoft and included in the Microsoft Windows line of operating systems, starting in 1995. It was first released as part of the add-on package Plus! for Windows 95 that year. Later versions were available as free downloads, or in service packs, and included in the original equipment manufacturer (OEM) service releases of Windows 95 and later versions of Windows. The browser is discontinued, but still maintained.[2]
Internet Explorer was one of the most widely used web browsers, attaining a peak of about 95% usage share during 2002 and 2003.[6] This came after Microsoft used bundling to win the first browser war against Netscape, which was the dominant browser in the 1990s. Its usage share has since declined with the launch of Firefox (2004) and Google Chrome (2008), and with the growing popularity of operating systems such as macOS, Linux, iOS and Android that do not run Internet Explorer. Estimates for Internet Explorer's overall market share range from 3.91% to 16.84% or by StatCounter's numbers ranked 3rd, just after Firefox (or even as low as 5th when counting all platforms[7]), as of June 2017[update] (browser market share is notoriously difficult to calculate). Microsoft spent over US$100 million per year on Internet Explorer in the late 1990s,[8] with over 1,000 people working on it by 1999.[9][10]
Versions of Internet Explorer for other operating systems have also been produced, including an Xbox 360 version called Internet Explorer for Xbox and for platforms Microsoft no longer supports: Internet Explorer for Mac and Internet Explorer for UNIX (Solaris and HP-UX), and an embedded OEM version called Pocket Internet Explorer, later rebranded Internet Explorer Mobile made for Windows Phone, Windows CE, and previously, based on Internet Explorer 7 for Windows Mobile.
On March 17, 2015, Microsoft announced that Microsoft Edge would replace Internet Explorer as the default browser on its Windows 10 devices. This effectively makes Internet Explorer 11 the last release. Internet Explorer, however, remains on Windows 10 primarily for enterprise purposes.[11] Starting January 12, 2016, only Internet Explorer 11 is supported.[12][13] Support varies based on the operating system's technical capabilities and its support lifecycle.[14]
The browser has been scrutinized throughout its development for use of third-party technology (such as the source code of Spyglass Mosaic, used without royalty in early versions) and security and privacy vulnerabilities, and the United States and the European Union have alleged that integration of Internet Explorer with Windows has been to the detriment of fair browser competition.
The Internet Explorer project was started in the summer of 1994 by Thomas Reardon, who, according to the Massachusetts Institute of Technology Review of 2003,[15] used source code from Spyglass, Inc. Mosaic, which was an early commercial web browser with formal ties to the pioneering National Center for Supercomputing Applications (NCSA) Mosaic browser.[16][17] In late 1994, Microsoft licensed Spyglass Mosaic for a quarterly fee plus a percentage of Microsoft's non-Windows revenues for the software.[17] Although bearing a name similar to NCSA Mosaic, Spyglass Mosaic had used the NCSA Mosaic source code sparingly.[18] Microsoft was sued by Synet Inc. in 1996, over the trademark infringement.[19]
The first version of Internet Explorer, Microsoft Internet Explorer (later referred to as Internet Explorer 1) made its debut on August 16, 1995. It was a reworked version of Spyglass Mosaic, which Microsoft licensed from Spyglass Inc., like many other companies initiating browser development.[16][17] It was installed as part of the Internet Jumpstart Kit in Microsoft Plus! for Windows 95 and Plus!.[20] The Internet Explorer team began with about six people in early development.[18][21] Internet Explorer 1.5 was released several months later for Windows NT and added support for basic table rendering. By including it free of charge on their operating system, they did not have to pay royalties to Spyglass Inc, resulting in a lawsuit and a US$8 million settlement on January 22, 1997.[16][22]
Internet Explorer 9 was released on March 14, 2011.[23] Development for Internet Explorer 9 began shortly after the release of Internet Explorer 8.[24] Microsoft first announced Internet Explorer 9 at PDC 2009, and spoke mainly about how it takes advantage of hardware acceleration in DirectX to improve the performance of web applications and quality of web typography. At MIX 10, Microsoft showed and publicly released the first Platform Preview for Internet Explorer 9, a frame for IE9's engine not containing any UI of the browser. Leading up to the release of the final browser, Microsoft released updated platform previews, each featuring improved JavaScript compiling (32-bit version), improved scores on the Acid3 test, as well as additional HTML5 standards support, approximately every 6 weeks. Ultimately, eight platform previews were released. The first public beta was released at a special event in San Francisco, which was themed around "the beauty of the web". The release candidate was released on February 10, 2011, and featured improved performance, refinements to the UI, and further standards support. The final version was released during the South by Southwest (SXSW) Interactive conference in Austin, Texas, on March 14, 2011.[23]
Internet Explorer 9 is only supported on Windows 7, Windows Server 2008, and Windows Server 2008 R2,[25] and was supported on Windows Vista SP2. It supports several CSS 3 properties (including border-radius, box-shadow, etc.), and embedded ICC v2 or v4 colour profiles support via Windows Color System. The 32-bit version has faster JavaScript performance, this being due to a new JavaScript engine called "Chakra".[26] It also features hardware accelerated graphics rendering using Direct2D, hardware-accelerated text rendering using DirectWrite, hardware-accelerated video rendering using Media Foundation, imaging support provided by Windows Imaging Component, and high fidelity printing powered by the XPS print pipeline.[27] IE9 also supports the HTML5 video and audio tags and the Web Open Font Format.[28] Internet Explorer 9 initially scored 95/100 on the Acid3 test, but has scored 100/100 since the test was updated in September 2011.[29]
Internet Explorer was to be omitted from Windows 7 and Windows Server 2008 R2 in Europe, but Microsoft ultimately included it, with a browser option screen allowing users to select any of several web browsers (including Internet Explorer).[30][31][32][33][34]
Internet Explorer is now available on Xbox 360 with Kinect support, as of October 2012.[35]
Internet Explorer 10 became generally available on October 26, 2012, alongside Windows 8 and Windows Server 2012, but is by now supported on Windows Server 2012, while Windows Server 2012 R2 only supports Internet Explorer 11. It became available for Windows 7 on February 26, 2013.[36] Microsoft announced Internet Explorer 10 in April 2011, at MIX 11 in Las Vegas, releasing the first Platform Preview at the same time. At the show, it was said that Internet Explorer 10 was about 3 weeks in development.[37] This release further improves upon standards support, including HTML5 Drag & Drop and CSS3 gradients. Internet Explorer 10 drops support for Windows Vista and will only run on Windows 7 Service Pack 1 and later.[38] Internet Explorer 10 Release Preview was also released on the Windows 8 Release Preview platform.
Internet Explorer 11 is featured in a Windows 8.1 update which was released on October 17, 2013. It includes an incomplete mechanism for syncing tabs. It is a major update to its developer tools,[39][40] enhanced scaling for high DPI screens,[41]HTML5 prerender and prefetch,[42]hardware-accelerated JPEG decoding,[43]closed captioning, HTML5 full screen,[44] and is the first Internet Explorer to support WebGL[45][46][47] and Google's protocol SPDY (starting at v3).[48] This version of IE has features dedicated to Windows 8.1, including cryptography (WebCrypto),[39]adaptive bitrate streaming (Media Source Extensions)[49] and Encrypted Media Extensions.[44]
Internet Explorer 11 was made available for Windows 7 users to download on November 7, 2013, with Automatic Updates in the following weeks.[50]
Internet Explorer 11's user agent string now identifies the agent as "Trident" (the underlying layout engine) instead of "MSIE". It also announces compatibility with Gecko (the layout engine of Firefox).
Microsoft claimed that Internet Explorer 11, running the WebKit SunSpider JavaScript Benchmark, was the fastest browser as of October 15, 2013.[51]
Microsoft Edge, officially unveiled on January 21, 2015, has replaced Internet Explorer as the default browser on Windows 10. Internet Explorer is still installed in Windows 10 in order to maintain compatibility with older websites and intranet sites that require ActiveX and other Microsoft legacy web technologies.[52][53][54]
According to Microsoft, development of new features for Internet Explorer has ceased. However, it will continue to be maintained as part of the support policy for the versions of Windows with which it is included.[2]
Internet Explorer has been designed to view a broad range of web pages and provide certain features within the operating system, including Microsoft Update. During the heyday of the browser wars, Internet Explorer superseded Netscape only when it caught up technologically to support the progressive features of the time.[55][bettersourceneeded]
Internet Explorer, using the Trident layout engine:
Internet Explorer uses DOCTYPE sniffing to choose between standards mode and a "quirks mode" in which it deliberately mimicks nonstandard behaviours of old versions of MSIE for HTML and CSS rendering on screen (Internet Explorer always uses standards mode for printing). It also provides its own dialect of ECMAScript called JScript.
Internet Explorer was criticised by Tim Berners-Lee for its limited support for SVG which is promoted by W3C.[59]
Internet Explorer has introduced an array of proprietary extensions to many of the standards, including HTML, CSS, and the DOM. This has resulted in a number of web pages that appear broken in standards-compliant web browsers and has introduced the need for a "quirks mode" to allow for rendering improper elements meant for Internet Explorer in these other browsers.
Internet Explorer has introduced a number of extensions to the DOM that have been adopted by other browsers. These include the innerHTML property, which provides access to the HTML string within an element[citation needed]; the XMLHttpRequest object, which allows the sending of HTTP request and receiving of HTTP response, and may be used to perform AJAX; and the designMode attribute of the contentDocument object, which enables rich text editing of HTML documents[citation needed] . Some of these functionalities were not possible until the introduction of the W3C DOM methods. Its Ruby character extension to HTML is also accepted as a module in W3C XHTML 1.1, though it is not found in all versions of W3C HTML.
Microsoft submitted several other features of IE for consideration by the W3C for standardization. These include the 'behaviour' CSS property, which connects the HTML elements with JScript behaviours (known as HTML Components, HTC); HTML+TIME profile, which adds timing and media synchronization support to HTML documents (similar to the W3C XHTML+SMIL), and the VML vector graphics file format. However, all were rejected, at least in their original forms; VML was subsequently combined with PGML (proposed by Adobe and Sun), resulting in the W3C-approved SVG format, one of the few vector image formats being used on the web, which IE did not support until version 9.[60]
Other non-standard behaviours include: support for vertical text, but in a syntax different from W3C CSS3 candidate recommendation, support for a variety of image effects[61] and page transitions, which are not found in W3C CSS, support for obfuscated script code, in particular JScript.Encode.[62] Support for embedding EOT fonts in web pages.[63]
Support for favicons was first added in Internet Explorer 5.[64] Internet Explorer supports favicons in PNG, static GIF and native Windows icon formats. In Windows Vista and later, Internet Explorer can display native Windows icons that have embedded PNG files.[65][66]
Internet Explorer makes use of the accessibility framework provided in Windows. Internet Explorer is also a user interface for FTP, with operations similar to that of Windows Explorer. Pop-up blocking and tabbed browsing were added respectively in Internet Explorer 6 and Internet Explorer 7. Tabbed browsing can also be added to older versions by installing MSN Search Toolbar or Yahoo Toolbar.
Internet Explorer caches visited content in the Temporary Internet Files folder to allow quicker access (or offline access) to previously visited pages. The content is indexed in a database file, known as Index.dat. Multiple Index.dat files exist which index different contentvisited content, web feeds, visited URLs, cookies, etc.[67]
Prior to IE7, clearing the cache used to clear the index but the files themselves were not reliably removed, posing a potential security and privacy risk. In IE7 and later, when the cache is cleared, the cache files are more reliably removed, and the index.dat file is overwritten with null bytes.
Caching has been improved in IE9.[68]
Internet Explorer is fully configurable using Group Policy. Administrators of Windows Server domains (for domain-joined computers) or the local computer can apply and enforce a variety of settings on computers that affect the user interface (such as disabling menu items and individual configuration options), as well as underlying security features such as downloading of files, zone configuration, per-site settings, ActiveX control behaviour and others. Policy settings can be configured for each user and for each machine. Internet Explorer also supports Integrated Windows Authentication.
Internet Explorer uses a componentized architecture built on the Component Object Model (COM) technology. It consists of several major components, each of which is contained in a separate Dynamic-link library (DLL) and exposes a set of COM programming interfaces hosted by the Internet Explorer main executable, iexplore.exe:[69]
Internet Explorer does not include any native scripting functionality. Rather, MSHTML.dll exposes an API that permits a programmer to develop a scripting environment to be plugged-in and to access the DOM tree. Internet Explorer 8 includes the bindings for the Active Scripting engine, which is a part of Microsoft Windows and allows any language implemented as an Active Scripting module to be used for client-side scripting. By default, only the JScript and VBScript modules are provided; third party implementations like ScreamingMonkey (for ECMAScript 4 support) can also be used. Microsoft also makes available the Microsoft Silverlight runtime (not supported in Windows RT) that allows CLI languages, including DLR-based dynamic languages like IronPython and IronRuby, to be used for client-side scripting.
Internet Explorer 8 introduces some major architectural changes, called Loosely Coupled IE (LCIE). LCIE separates the main window process (frame process) from the processes hosting the different web applications in different tabs (tab processes). A frame process can create multiple tab processes, each of which can be of a different integrity level; each tab process can host multiple web sites. The processes use asynchronous Inter-Process Communication to synchronize themselves. Generally, there will be a single frame process for all web sites. In Windows Vista with Protected Mode turned on, however, opening privileged content (such as local HTML pages) will create a new tab process as it will not be constrained by Protected Mode.[71]
Internet Explorer exposes a set of Component Object Model (COM) interfaces that allows add-ons to extend the functionality of the browser.[69] Extensibility is divided into two types: Browser extensibility and content extensibility. Browser extensibility involves adding context menu entries, toolbars, menu items or Browser Helper Objects (BHO). BHOs are used to extend the feature set of the browser, whereas the other extensibility options are used to expose that feature in the user interface. Content extensibility adds support for non-native content formats.[69] It allows Internet Explorer to handle new file formats and new protocols, e.g. WebM or SPDY.[69] In addition, web pages can integrate widgets known as ActiveX controls which run on Windows only but have vast potentials to extend the content capabilities; Adobe Flash Player and Microsoft Silverlight are examples.[69] Add-ons can be installed either locally, or directly by a web site.
Since malicious add-ons can compromise the security of a system, Internet Explorer implements several safeguards. Internet Explorer 6 with Service Pack 2 and later feature an Add-on Manager for enabling or disabling individual add-ons, complemented by a "No Add-Ons" mode. Starting with Windows Vista, Internet Explorer and its BHOs run with restricted privileges and are isolated from the rest of the system. Internet Explorer 9 introduced a new component Add-on Performance Advisor. Add-on Performance Advisor shows a notification when one or more of installed add-ons exceed a pre-set performance threshold. The notification appears in the Notification Bar when the user launches the browser. Windows 8 and Windows RT introduce a Metro-style version of Internet Explorer that is entirely sandboxed and does not run add-ons at all.[72] In addition, Windows RT cannot download or install ActiveX controls at all; although existing ones bundled with Windows RT still run in the traditional version of Internet Explorer.[72]
Internet Explorer itself can be hosted by other applications via a set of COM interfaces. This can be used to embed the browser functionality inside a computer program or create Internet Explorer shells.[69]
Internet Explorer uses a zone-based security framework that groups sites based on certain conditions, including whether it is an Internet- or intranet-based site as well as a user-editable whitelist. Security restrictions are applied per zone; all the sites in a zone are subject to the restrictions.
Internet Explorer 6 SP2 onwards uses the Attachment Execution Service of Microsoft Windows to mark executable files downloaded from the Internet as being potentially unsafe. Accessing files marked as such will prompt the user to make an explicit trust decision to execute the file, as executables originating from the Internet can be potentially unsafe. This helps in preventing accidental installation of malware.
Internet Explorer 7 introduced the phishing filter, that restricts access to phishing sites unless the user overrides the decision. With version 8, it also blocks access to sites known to host malware. Downloads are also checked to see if they are known to be malware-infected.
In Windows Vista, Internet Explorer by default runs in what is called Protected Mode, where the privileges of the browser itself are severely restrictedit cannot make any system-wide changes. One can optionally turn this mode off but this is not recommended. This also effectively restricts the privileges of any add-ons. As a result, even if the browser or any add-on is compromised, the damage the security breach can cause is limited.
Patches and updates to the browser are released periodically and made available through the Windows Update service, as well as through Automatic Updates. Although security patches continue to be released for a range of platforms, most feature additions and security infrastructure improvements are only made available on operating systems which are in Microsoft's mainstream support phase.
On December 16, 2008, Trend Micro recommended users switch to rival browsers until an emergency IE patch was released to fix a potential security risk which "could allow outside users to take control of a person's computer and steal their passwords". Microsoft representatives countered this recommendation, claiming that "0.02% of internet sites" were affected by the flaw.
On December 17, 2008, a fix to the security problem above became available, with the release of the Security Update for Internet Explorer KB960714, which is available from Microsoft Windows Update's webpage. Microsoft has said that this update fixes the security risk found by Trend Micro the previous day.[73][74]
In 2011, a report by Accuvant, funded by Google, rated the security (based on sandboxing) of Internet Explorer worse than Google Chrome but better than Mozilla Firefox.[75][76]
Internet Explorer has been subjected to many security vulnerabilities and concerns: much of the spyware, adware, and computer viruses across the Internet are made possible by exploitable bugs and flaws in the security architecture of Internet Explorer, sometimes requiring nothing more than viewing of a malicious web page in order to install themselves. This is known as a "drive-by install". There are also attempts to trick the user into installing malicious software by misrepresenting the software's true purpose in the description section of an ActiveX security alert.
A number of security flaws affecting IE originated not in the browser itself, but ActiveX-based add-ons used by it. Because the add-ons have the same privilege as IE, the flaws can be as critical as browser flaws. This has led to the ActiveX-based architecture being criticized for being fault-prone. By 2005, some experts maintained that the dangers of ActiveX have been overstated and there were safeguards in place.[77] In 2006, new techniques using automated testing found more than a hundred vulnerabilities in standard Microsoft ActiveX components.[78] Security features introduced in Internet Explorer 7 mitigated some of these vulnerabilities.
Internet Explorer in 2008, had a number of published security vulnerabilities. According to research done by security research firm Secunia, Microsoft did not respond as quickly as its competitors in fixing security holes and making patches available.[79] The firm also reported 366 vulnerabilities in ActiveX controls, an increase from the prior year.
According to an October 2010 report in The Register, researcher Chris Evans had detected a known security vulnerability which, then dating back to 2008, had not been fixed for at least 600 days.[80] Microsoft says that it had known about this vulnerability but it was of very low severity as the victim web site must be configured in a special way for this attack to be feasible at all.[81]
In December 2010, researchers were able to bypass the "Protected Mode" feature in Internet Explorer.[82]
No info
In an advisory on January 14, 2010, Microsoft said that attackers targeting Google and other U.S. companies used software that exploits a security hole, which had already been patched, in Internet Explorer. The vulnerability affected Internet Explorer 6 on Windows XP and Server 2003, IE6 SP1 on Windows 2000 SP4, IE7 on Windows Vista, XP, Server 2008 and Server 2003, and IE8 on Windows 7, Vista, XP, Server 2003, and Server 2008 (R2).[84]
The German government warned users against using Internet Explorer and recommended switching to an alternative web browser, due to the major security hole described above that was exploited in Internet Explorer.[85] The Australian and French Government issued a similar warning a few days later.[86][87][88][89]
On April 26, 2014, Microsoft issued a security advisory relating to CVE-2014-1776 (use-after-free vulnerability in Microsoft Internet Explorer 6 through 11[90]), a vulnerability that could allow "remote code execution" in Internet Explorer versions 6 to 11.[91] On April 28, 2014, the United States Department of Homeland Security's United States Computer Emergency Readiness Team (US-CERT) released an advisory stating that the vulnerability could result in "the complete compromise" of an affected system.[92] US-CERT recommended reviewing Microsoft's suggestions to mitigate an attack or using an alternate browser until the bug is fixed.[93][94] The UK National Computer Emergency Response Team (CERT-UK) published an advisory announcing similar concerns and for users to take the additional step of ensuring their antivirus software is up-to-date.[95]Symantec, a cyber security firm, confirmed that "the vulnerability crashes Internet Explorer on Windows XP".[96] The vulnerability was resolved on May 1, 2014, with a security update.[97]
The adoption rate of Internet Explorer seems to be closely related to that of Microsoft Windows, as it is the default web browser that comes with Windows. Since the integration of Internet Explorer 2.0 with Windows 95 OSR 1 in 1996, and especially after version 4.0's release in 1997, the adoption was greatly accelerated: from below 20% in 1996, to about 40% in 1998, and over 80% in 2000. This made Microsoft the winner in the infamous 'first browser war' against Netscape. Netscape Navigator was the dominant browser during 1995 and until 1997, but rapidly lost share to IE starting in 1998, and eventually slipped behind in 1999. The integration of IE with Windows led to a lawsuit by AOL, Netscape's owner, accusing Microsoft of unfair competition. The infamous case was eventually won by AOL but by then it was too late, as Internet Explorer had already become the dominant browser.
Internet Explorer peaked during 2002 and 2003, with about 95% share. Its first notable competitor after beating Netscape was Firefox from Mozilla, which itself was an offshoot from Netscape.
Firefox 1.0 had surpassed Internet Explorer 5 in early 2005, with Firefox 1.0 at roughly 8 percent market share.[98]
Approximate usage over time based on various usage share counters averaged for the year overall, or for the fourth quarter, or for the last month in the year depending on availability of reference.[99][100][101][102][103][104]
According to StatCounter Internet Explorer's marketshare fell below 50% in September 2010.[105] In May 2012, it was announced that Google Chrome overtook Internet Explorer as the most used browser worldwide.
Browser Helper Objects are also used by many search engine companies and third parties for creating add-ons that access their services, such as search engine toolbars. Because of the use of COM, it is possible to embed web-browsing functionality in third-party applications. Hence, there are a number of Internet Explorer shells, and a number of content-centric applications like RealPlayer also use Internet Explorer's web browsing module for viewing web pages within the applications.
While a major upgrade of Internet Explorer can be uninstalled in a traditional way if the user has saved the original application files for installation, the matter of uninstalling the version of the browser that has shipped with an operating system remains a controversial one.
The idea of removing a stock install of Internet Explorer from a Windows system was proposed during the United States v. Microsoft Corp. case. One of Microsoft's arguments during the trial was that removing Internet Explorer from Windows may result in system instability. Indeed, programs that depend on libraries installed by IE, including Windows help and support system, fail to function without IE. Before Windows Vista, it was not possible to run Windows Update without IE because the service used ActiveX technology, which no other web browser supports.
The popularity of Internet Explorer has led to the appearance of malware abusing its name. On January 28, 2011, a fake Internet Explorer browser calling itself "Internet Explorer Emergency Mode" appeared. It closely resembles the real Internet Explorer, but has fewer buttons and no search bar. If a user launches any other browser such as Google Chrome, Mozilla Firefox, Opera, Safari or the real Internet Explorer, this browser will pop-up instead. It also displays a fake error message, claiming that the computer is infected with malware and Internet Explorer has entered Emergency Mode. It blocks access to legitimate sites such as Google if infected users try to access them.[106][107]
Read this article:
Internet Explorer - Wikipedia
DUO to increase student internet security – The Crimson While
The University of Alabama is set to begin running a new authentication system designed to better protect students online. The program, known as DUO, is a two-factor authentication system that goes beyond the current system set up on MyBama and Crimson Email.
DUO not only requires students to enter their email and password, but also requires another form of authentication with something a student may have, such as another device or passcode.
"By requiring DUO for all University of Alabama students, we can better protect sensitive student data, precious research data and ultimately the UA community, said Dr. Kevin Whitaker, executive VP and provost. Two-factor authentication is quickly becoming the new standard in data protection.
The resolution to implement DUO was passed by the Student Government Association in the fall semester of last year and will be required by all students on Oct. 2 of this year.
Interested students can activate their DUO account before then by visiting duo.ua.eduand will enable the authentication system both MyBama and Crimson Email. Students must follow the online screen prompts and download the DUO mobile app to completely set up your account. For more information, contact the Office of Information Technology at 205-348-5555 or itsd@ua.edu.
See the original post here:
DUO to increase student internet security - The Crimson While
Your essential guide to internet security – IT PRO
The internet is a fickle beast. On the one hand, we now have access to the sum total of human knowledge (and human opinion) at our fingertips across an incredible range of devices. On the other, it's opened us up to a whole new world of crime, where scammers are waiting seemingly around every corner.
But just because a threat is out there, doesn't mean you must inevitably be vulnerable to it.
Here are some simple steps to ensure both you and your business remain safe on the internet.
Running internet security software on your endpoints (computers, mobile devices, tablets, etc) is the simplest place to start.
Most of the well known antivirus firms, have dedicated internet security products for both individuals and SMBs. They include features such as warning you if a page isn't secure, which is particularly important if you're going to be entering sensitive personal data, or if a page is trying to redirect you, as well as protection against malware downloads, including ransomware.
This type of software should ideally be used in conjunction with other on-device anti-malware programs.
When it comes to internet security, the proverb "better safe than sorry" is very much applicable. Genuine looking messages can be laden with hidden traps, like documents or PDFs containing malicious payloads or links to infected websites a technique commonly known as phishing.
If you receive an email from the finance department asking to "double check this invoice", for example, don't be afraid to reply asking for more details about the invoice before you open the attachment. Even better, if you use an instant message platform, such as Skype for Business, Slack or Yammer in your company, contact the sender directly there to double check.
Similarly, if the email comes from a supplier or customer and includes an attachment or link, it's better to call them up for clarification or details than to blindly click the link out of a sense of typical British "don't make a fuss" sentiment.
Be warned that scammers may also target you by phone. Remember that your bank will never make an unsolicited call and ask for your security details - if in doubt, hang up and call back. If the call is from "Microsoft support", hang up immediately.
Any of these types of attempted scam should be reported to the IT department as soon as possible.
Education is a key component of the internet security process for businesses. The IT department should be keeping users up to date with the latest policies and best practices and encouraging individuals to come forward with any questions or concerns.
You can see if these messages are sinking in by bringing in companies that specialise in penetration testing and running phishing drills, for example. This can help identify areas of weakness that need to be addressed.
Finally, make sure you keep yourself up to date with the latest security news and best practices from reliable sources.
Main image credit: Bigstock
Originally posted here:
Your essential guide to internet security - IT PRO
Online threats lead to real-world harm, say security experts – CNBC
A lot of these attacks include malware that's written to gather information on people, companies, governments and other entities. Once uncovered, this information can be used to threaten or harm people in the real world.
Even the mere threat of harm in the real world as a result of online behavior is enough to have an impact.
For example, Google employees who had their names published by right-wing provocateur Milo Yiannopoulos feared harassment after they posted comments critical of fired company engineer James Damore on an internal chat service. The so-called doxxing activity caused Google CEO Sundar Pichai to cancel a company-wide meeting to discuss Damore's firing.
"Things that happen online, like doxxing, have effects in the real world," says Alex Stamos, chief security officer for Google's chief rival, Facebook, at the same forum.
"It becomes a safety issue" in the real world for those who don't have a way to protect their information online, said Stamos.
"We track dozens and dozens of different types of harm" attempted on Facebook users, says Stamos, who also said Facebook turns off more than 1 million accounts per day over fraud, spam and hate speech.
While online attacks against large companies such as Sony and Target -- or celebrities like Jennifer Lawrence -- garner the most media attention, attacks against individuals are becoming increasingly common and damaging, according to Stamos.
"Things have shifted a lot away from attacks against large enterprises and large, well-protected organizations toward attacks against unprotected individuals who are aligned with them," Stamos said last week in San Francisco.
As an example, he pointed to the hack of emails sent by the campaign of Democratic presidential candidate Hillary Clinton last year, which were lifted from the laptop of the campaign's chairman, John Podesta.
"The internet is real life and real life is the internet," says the EFF's Galperin.
See more here:
Online threats lead to real-world harm, say security experts - CNBC
Net neutered: When ISPs like Comcast crash the cloud – ZDNet
(Image: ZDNet)
While doing some research on public cloud-based backup to blob storage solutions, I decided to tinker with the possibility of using Azure not just as my backup target but as a replacement for my main file server sitting under my desk.
I had already gone through the process of eliminating all my rack mount systems from my house that were taking up space and consuming too much electricity. These were being used for test purposes and it was easy to replace them with IaaS VMs in Azure.
Using public cloud as your file server, though, that's a bit different. It's actually quite easy to do as a small business; the Azure file service makes it easy to turn on SMB/CIFS file sharing with any storage account.
It doesn't consume compute, just storage costs, but it acts just like any other file server or NAS device on-premises.
And if your business uses business-class broadband, such as an MPLS connection to a Tier-1 telco, it works great. But if you are a SOHO-based business and are using consumer-class broadband, not so much.
It's got nothing to do with Azure's technology -- that part works great. The problem has to do with what providers like Comcast are doing with access controls on their networks.
When I was setting up my Azure file services, I discovered that I could not map a drive from Windows to the file storage. At first, I thought I had something in my firewall set wrong.
Nope. Even with my PC set to ANY/ANY exclusions coming from that MAC address, I still couldn't connect to it.
After some trial and error and some basic geek forensics, I determined that one of the ports that the SMB protocol uses -- TCP 445 -- was being blocked upstream. So I called my broadband company, Blue Stream, which maintains the local cable infrastructure in the town where I live in South Florida.
Nope, no ports being blocked there.
But do you know where lots of ports are being blocked? Comcast, which is Blue Stream's upstream bandwidth provider.
Comcast presumably blocks port 445 because it is used by the WannaCry malware to spread between systems. However, it's also the port Microsoft Active Directory uses.
So, if you use Comcast, but want to develop and test file services on Azure, you're going to have to establish a VPN connection, which kind of defeats the purpose of being able to access your file services from any mobile device.
Comcast is not the only provider that blocks certain ports. AT&T does, as do others.
I understand ISPs wanting to be proactive about security, but blocking ports that essentially disable functionality on major cloud services is unacceptable.
I feel... Comcastrated.
Now, Microsoft could fix this problem by making protocol changes to SMB -- by having it communicate over alternate ports and being able to configure that in Azure. But that means making changes to the Windows OS communications protocol stack and pushing that out to tens of millions of systems.
It also would mean changes in the SMB/CIFS standard as well, and that would need to be rolled out to SAMBA and anything else that needs that protocol including all sorts of NAS devices that run on Linux and other derivative OSes.
SMB is just one protocol. There are others that are needed for so many other apps. We can't change or replace all of them every time a new piece of malware comes out.
What we need is a better solution for monitoring network traffic and acting on threats at the residential level rather than blocking ports wholesale.
Ideally, it would be great to be able to provide a deep packet inspection device to every home, but this type of technology is typically deployed at enterprises and it starts at around $1,000 an appliance and can cost upward of thousands of dollars a year for the subscription, depending on the vendor.
First, there's no reason why the industry cannot develop a packet inspection and intrusion detection/web application gateway using open source components and then deploy it in a multi-tenant fashion at the provider at the edge of the network, with some sort of an app that the home broadband customer can use to secure their traffic in an easy, wizard-like, self-service fashion.
Log threats going in and out, get notifications on strange activity, all that good stuff.
Perhaps provide unified threat management and deep packet inspection as a value-added service. Managed internet security for residential customers and small business.
As more and more of our services go cloud-based, particularly with the proliferation of Internet of Things devices that need to have constant connectivity, we are going to need to find a better way to deal with the issues of proactive monitoring and acting on internet traffic coming from the home, versus ham-fisted and draconian methods such as port blocking that diminish the value of the broadband connectivity in the first place.
This isn't just an issue of net neutrality; it's the only way we are going to be able to seamlessly move to the cloud, long term. The price of entry should not have to be a direct Tier-1 leased line, with an enterprise class service-level agreement and a private virtual circuit to the cloud provider.
Cloud services should be accessible to everyone. It is possible to be both safe and open, but it will require a re-thinking of how providers allow access to those pipes.
Original post:
Net neutered: When ISPs like Comcast crash the cloud - ZDNet
Upgrade your internet security with Private Internet Access VPN … – Popular Science
Both private companies and governments use the web to track our activity every day. What's more, the problem is getting worseso you might want to think about protecting yourself. Private Internet Access VPN makes you totally anonymous online and helps you access great geo-blocked content. You can currently get two years of service for $59.95 via the Popular Science Shop.
All the big online platforms spy on their usersthat's how Facebook knows what products you have viewed on Amazon. If you would prefer a little privacy, you need a VPN. Private Internet Access routes your web traffic through masking servers, meaning no-one can trace your IP address or physical location. Aside from privacy, this means you can access overseas streaming sites and protect yourself from cyber criminals.
This VPN offers unlimited bandwidth and impressive speed, thanks to a network of 3,310 servers in 25 countries. You can protect up to five devices simultaneously, with one-click installers for PC, Mac, Linux, Android and iOS. Private Internet Access also blocks ads and malware, keeping you safe online.
You can grab a two-year subscription now for $59.95, saving 63 percent on the regular price ($166).
Go here to read the rest:
Upgrade your internet security with Private Internet Access VPN ... - Popular Science