I noticed that my front door was slightly ajar just now, especially as I was going to go take a nap after playing some Civilization IV. Must pay more attention!
Born, like other comic book characters, out of an otherwise trivial but life-changing animal bite, the Rabid Librarian seeks out strange, useless facts, raves about real and perceived injustices, and seeks to meet her greatest challenge of all--her own life.
Translate
Showing posts with label Security. Show all posts
Showing posts with label Security. Show all posts
Thursday, March 10, 2016
Thursday, May 01, 2014
I don't use Internet Explorer at home
but I updated anyway just on the off-chance I have to use it for some reason. And I'll update my friend's computer as soon as I can. Hopefully work will do the same.
Microsoft issuing fix for IE zero day today
Microsoft issuing fix for IE zero day today
At 10 AM Pacific time on Thursday, Microsoft will release an update to address the zero day vulnerability recently disclosed in all versions of Internet Explorer. The advance notification of the update lists Windows XP as among the affected platforms, indicating that it will be among the platforms patched, in spite of its support period ending weeks ago.
Adrienne Hall, General Manager, Microsoft Trustworthy Computing stated "[T]he security of our products is something we take incredibly seriously. When we saw the first reports about this vulnerability we decided to fix it, fix it fast, and fix it for all our customers."
Users with Automatic Updates enabled do not have to do anything, although running Windows Update will apply the fix immediately.
Wednesday, May 18, 2011
Quick response there, Google
99% of Android phones leak secret account credentials
My phone uses Android 2.2, so it was vulnerable. So far I haven't used it over wi-fi networks, so I should be okay, but in the interim I turned off wi-fi access to my phone.
The vast majority of devices running Google's Android operating system are vulnerable to attacks that allow adversaries to steal the digital credentials used to access calendars, contacts, and other sensitive data stored on the search giant's servers, university researchers have warned.Google rolls out fix for Android security threat
The weakness stems from the improper implementation of an authentication protocol known as ClientLogin in Android versions 2.3.3 and earlier, the researchers from Germany's University of Ulm said. After a user submits valid credentials for Google Calendar, Contacts and possibly other accounts, the programming interface retrieves an authentication token that is sent in cleartext. Because the authToken can be used for up to 14 days in any subsequent requests on the service, attackers can exploit them to gain unauthorized access to accounts.
Google has plugged a security hole that exposed the vast majority of Android phone users' calendars and contacts when they accessed those services over unsecured networks.
"Today we're starting to roll out a fix which addresses a potential security flaw that could, under certain circumstances, allow a third party access to data available in calendar and contacts," a company spokesman wrote in an email. "This fix requires no action from users and will roll out globally over the next few days."
My phone uses Android 2.2, so it was vulnerable. So far I haven't used it over wi-fi networks, so I should be okay, but in the interim I turned off wi-fi access to my phone.
Subscribe to:
Posts (Atom)