ie8 fix
Game time

Security & Privacy

Homeland Security: The reality show

Queue the music: the U.S. Department of Homeland Security is about to get its own reality show.

On Thursday, ABC announced a mid-season replacement show called "Homeland Security USA." From Arnold Shapiro, the Emmy-winning producer of such documentaries as Scared Straight," the network said the series will give viewers an unprecedented look at the work of the men and women at the DHS "while they use the newest technology to safeguard our country and enforce our law."

The 13 hour-long episodes were shot entirely on location throughout the United States.

ABC says the producers … Read more

CheckFree customers redirected to Ukraine site

Customers of CheckFree.com, an online bill paying site, were quietly redirected to servers in Ukraine early Tuesday morning, according to several reports.

Representatives of CheckFree told WashingtonPost.com that customers were redirected to a blank log-in page that attempted to install malware on the visiting PC. The company said it regained control at 5 a.m. EST Tuesday, so only customers using the site overnight were likely affected.

Mike Haro, senior security analyst at Sophos told CNET News, "The fact that they used a blank page to download a Trojan (not exactly subtle) says to me one of … Read more

Microsoft and RSA partner on Data Loss Prevention

Microsoft and EMC's RSA on Thursday announced an expanded technology partnership around digital rights management in the enterprise.

There are two parts to the announcement, said Douglas Leland, general manager of the Identity and Security Business Group at Microsoft. One, Microsoft will build RSA's Data Loss Prevention (DLP) prevention classification into the Microsoft IT platform and future information protection products.

The other part of the announcement, said Leland, is that RSA will in turn integrate Microsoft's Active Directory Right Management System (RMS) into its DLP product. "This makes RSA's DLP solution identity-aware."

Microsoft and … Read more

Worm uses familiar brands to lure people

On Tuesday security vendor WebSense issued an alert warning that holiday coupon e-mails from familiar companies may be malicious code in disguise, in this case a mass-mailing e-mail worm.

The warning cites one spoofed McDonald's e-mail that claims to present their latest discount menu, and asks the recipient to print out the attached coupon. A similar mailing pretending to be from Coca-Cola asks recipients to print out details about their new online game, and also offers recipients a chance to win Coca-Cola drinks for life. Websense says the attached zip file contains files named either coupon.exe or promotion.… Read more

SonicWall server glitch leaves networks unprotected

Updated 3:36 p.m. PST with SonicWall comment.

An outage at SonicWall's licensing server disabled subscription-based security services for customers for at least several hours on Tuesday, according to the company and an angry customer.

Beginning around 2 a.m. PST, "some SonicWall products contacting a particular SonicWall licensing server began receiving erroneous responses," the company said in an e-mail notice to customers sent around 5:40 p.m. PST on Tuesday.

"You are receiving this mail because our monitoring systems indicate that your SonicWall product(s) may have been affected. This may have caused … Read more

Whither Cisco MARS?

Cisco System's Security Monitoring for Threat Identification, Mitigation, and Compliance (aka MARS) product is the company's offering for security and compliance management, competing with the likes of ArcSight, RSA Security, and Symantec. The MARS product came via Cisco's acquisition of Protego for $65 million in December 2004.

Through 2005 and 2006, Cisco pushed this product into end-user accounts through an aggressive scorched-earth effort. Cisco intended to get the product out into the market quickly, establish a base, and then continually add product enhancements over time. This seems to be where the strategy hit a speed bump.

The … Read more

Apple deletes Mac antivirus suggestion

Updated 7:45 p.m. PST with expert comment, at 7:20 p.m. PST with context on previous coverage, and at 7:08 p.m. PST with background.

Apple removed an old item from its support site late Tuesday that urged Mac customers to use multiple antivirus utilities and now says the Mac is safe "out of the box."

"We have removed the KnowledgeBase article because it was old and inaccurate," Apple spokesperson Bill Evans said.

"The Mac is designed with built-in technologies that provide protection against malicious software and security threats right out … Read more

Vietnamese security firm: Your face is easy to fake

Updated at 1:14 p.m. PST Friday, December 5 with comment from Lenovo.

Editor's note: CNET editor and Crave contributor Dong Ngo is spending the month of December in his homeland of Vietnam and plans to file occasional dispatches chronicling his impressions of how technology has permeated the culture there. Click here for more of Dong's stories from abroad.

HANOI, Vietnam--Regardless of what some people seem to think, we Asians do not all look the same. But according to the current face recognition algorithm used in laptops, our faces are all about as flat as a piece of paper.

That's according to BKIS, the Vietnamese Internetwork Security Center that makes the antivirus software I mentioned in a blog post Monday. At a press conference here Tuesday, the company demonstrated vulnerabilities in laptops' face recognition-based authentication mechanisms that let anyone log in to a computer easily with a "special" photo of the legit owner, even at the highest authentication level.

Using your face as the password to log in to a computer--an alternative to the fingerprint method or the traditional username and password--marks a new trend found in laptops from Lenovo, Asus, and Toshiba. As far as I know, only these three vendors currently offer this technology in their laptops. These computers come with a built-in Webcam that's used to capture and analyze faces.

I've been impressed by this new way to log in and have found it to be so much more convenient than the fingerprint reader of my Dell XPS 1330. The finger scanner is a pain when my finger is wet or dirty. Unfortunately, on Tuesday I discovered that this new and exciting technology may not be such an effective security measure.

I participated in a demonstration on a Lenovo Y430, running Windows Vista, and here's how it panned out:… Read more

Apple suggests Mac users install antivirus software

Updated 10:50 a.m. PST December 2 to correct that Apple previously recommended antivirus software to Mac users, and at 1:50 p.m. PST with call back from Apple and link to 2002 Apple anti-virus item. A follow-up blog will be posted that goes into more detail about the coverage.

Apple is recommending that Mac users install antivirus software.

But don't read this as an admission that the Mac operating system is suddenly insecure. It's more a recognition that Mac users are vulnerable to Web application exploits, which have replaced operating system vulnerabilities as the bigger threat to computer users.

On November 21 Apple updated a technical note on its Support Web site that says: "Apple encourages the widespread use of multiple antivirus utilities so that virus programmers have more than one application to circumvent, thus making the whole virus writing process more difficult."

The item offers three software suggestions: Intego VirusBarrier X5 and Symantec Norton Anti-Virus 11 for Macintosh, both available from the Apple Online Store, and McAfee VirusScan for Mac.

MacDailyNews unearthed the same note posted by Apple in June 2007 and published it on Tuesday,a long with a link to a March 2002 note from Apple urging people to use an anti-virus program.

Apple representatives did not respond to e-mails seeking comment on Monday, but did return a call on Tuesday. A spokesman said he would look into the matter.

Brian Krebs, who first reported on the Apple antivirus recommendation Monday in his Security Fix blog at The Washington Post, said an Apple store employee told him he didn't need antivirus software when he purchased a MacBook three months ago.

Read more

Europe to get cybercrime alert system

Europe is getting a cybercrime alert system as part of a European Union drive to fight online criminals.

According to plans, European law enforcement body Europol will receive 300,000 euros ($386,430) to build an alert system that pools reports of cybercrime, such as online identification and financial theft, from across the 27 member states.

Police will launch more remote searches of suspects' hard drives over the Internet, as well as cyberpatrols to spot and track illegal activity, under the strategy adopted by the European Union's council of ministers Thursday.

The strategy, a blueprint for fighting cybercrime in … Read more

ie8 fix