ie8 fix

Security

Meet Larry, Firefox's friendly passport officer

I recently spoke with Johnathan Nightingale, Mozilla's "Human Shield," the man who designed the security interface within Firefox 3. One of the big changes is how Firefox communicates the authenticity of a given site. Located on the left hand side of the address bar is a tiny icon associated with the site. Sites using Extended Verification Secure Socket Layers (EV SSL) go an additional step.

Nightingale explains: "If you go to PayPal.com, for instance, that will expand out and it'll say PayPal Inc USA because PayPal is a site that presents this enhanced identity … Read more

Suites are the safe, simple route to PC security

When the free trial of the security software that shipped with my Vista PC expired, I decided to uninstall it and give the free versions of competing antivirus and firewall programs a try. For some reason, this caused my Internet connection to drop intermittently.

When I uninstalled the new programs and ponied up for the full version of the security suite, the network outages ceased. I never did figure out why my system didn't take to the new security apps, but the hassles I avoided by taking the suite approach to security justified the cost of the program.

The … Read more

Security Bites 103: Capitalizing on botnets

IronPort's Pat Peterson joins Robert Vamosi this week to talk about how online criminals make money using botnets.

Listen now: Download today's podcast

How do online criminals make money off of botnets? Previously, we've explored how parts of the Storm worm botnet may have been rented out to others. No matter who owns the botnet, the traffic is usually the same: spam. But what kind of spam?

IronPort Systems, a divison of Cisco, released a report this week (registration required) that identified some of the specific spam messages being used. Not surprising is the pharmaceutical spam. But … Read more

Firefox 3 won't have 'private browsing'

Correction at 7:50 a.m. PDT: The spelling of Johnathan Nightingale has been fixed.

At least one security feature won't make it into the final release of Firefox 3 on June 17, Mozilla confirmed again Thursday.

The feature, Private Browsing, would have disabled all caching, cookie downloads, history records, and form data used during the current session. In essence, you could surf the Web and leave no fingerprints.

"It basically said to the browser: I would like what I'm about to do to not be logged anywhere," said Johnathan Nightingale, Mozilla's "human shield,&… Read more

Firefox 3 to set download record on June 17?

Correction on June 13: The spelling of Johnathan Nightingale has been fixed.

On Wednesday, Mozilla announced next Tuesday, June 17, as "Download Day" for Firefox 3. The company also released Firefox 3 release candidate 3 as a final step toward full release.

With Firefox 3, Mozilla is attempting to set a Guinness Book of World Records for the largest number of software downloads within a 24-hour period. There is currently no Guinness Book record for that accomplishment.

Firefox 3 includes a new rendering engine, so pages load faster. It also uses fewer system resources, addressing a complaint in … Read more

Newly released Opera 9.5 bundles more protection

Opera 9.5, code-named Kestrel, on Thursday became available for download for Windows and Mac.

The new version of the browser, whose release candidate was released earlier this week, is a security-enhanced version of Opera 9. It includes antiphishing protection from Netcraft and malware protection from Haute Secure, as well as support for Extended Validation Secure Sockets Layer (EV SSL).

The browser also has a new "eurotechno" look and feel, a QuickFind address bar feature, better synchronization with its mobile cousin, and a Speed Dial feature for visually bookmarking nine of your favorite sites.

Scandinavia-based Opera Software still … Read more

Reports examine causes, victims of data breaches

On Wednesday, Verizon Business released a four-year study concluding that 9 out of 10 corporate data breaches could have been prevented, had appropriate security measures been taken. The Verizon report includes the results of more than 500 forensic investigations, including three of the largest data breaches ever reported.

Meanwhile, the Identity Theft Resource Center released its 2007 report on identity theft, offering comparisons to data it's collected over the last five years.

Verizon found that 73 percent of the data breaches were the result of outside sources, with only 18 percent from insider threats. Of the outside sources, 39 … Read more

Firefox 3 gets a third release candidate

Updated at 12:30 p.m. PDT on Wednesday with links to the newly debuted release candidate.

If you were planning to host a Firefox 3 launch party this week, keep that bubbly on ice a bit longer.

Mozilla on Wednesday released Firefox 3 Release Candidate 3. Windows and Linux users won't likely feel a thing; the new browser is considered stable on those platforms.

The extra release candidate addresses some lingering issues on the Mac OS X operating system. The changes are internal.

The previous test version, Firefox 3 Release Candidate 2, can also be downloaded for Windows, … Read more

Microsoft patches 10 flaws with seven bulletins

Microsoft on Tuesday released its June 2008 security bulletin, which includes three critical, three important, and one moderate patch.

Of the critical, one is for the Bluetooth stack in Windows XP and Windows Vista, one is for DirectX, and another is a cumulative update to Internet Explorer. The one moderate bulletin covers a flaw in the speech recognition feature in Windows 2000, XP, and Windows Vista. Of the important bulletins, one concerns Active Directory and another Pragmatic General Multicast (PGM). All Microsoft security patches for both Windows and Office software are available via Microsoft Update or via the individual bulletins … Read more

IMDB victim of denial-of-service attack

On Friday, Internet movie database IMDB fell victim to a sustained distributed denial-of-service (DDoS) attack that coincided with Amazon.com being offline, says one researcher.

Soups Ranjan, a senior member of the technical staff of network protection and management company Narus, said in a blog that he found evidence that at least one of the IP addresses used by IMDB fell under a sustained DDoS attack between 10:30 a.m. and 1:30 p.m. PDT Friday.

"My attempt to load the IMDB page via a direct connection to the Web server under attack (http://72.21.206.… Read more