ie8 fix

Privacy & data protection

Google's JotSpot exposes user data

Updated at 10 p.m. PT with comments from Google.

A researcher has found that Google's JotSpot service, which allows people to collaborate on online documents, exposes user names and e-mail addresses to anyone on the Internet, but Google says the problem is due to administrator users not making the settings private.

As a result, sensitive user data is indexed by Google's crawler and made accessible on the Web, said Ben Edelman, a Harvard Business School professor and security researcher.

"This is not a security issue," a Google spokesman said in an e-mail. "The information … Read more

Banking security on a USB stick

IBM was set to unveil on Wednesday a prototype USB device designed to protect people doing online banking from having their data stolen or compromised.

The device, which looks like a memory stick with an integrated display, creates a secure channel to a bank's online transaction server. The connection bypasses the user's PC, which could be infected with viruses and other malware that make sending financial information over the Internet unsafe.

The user can log on and validate transactions using the device's display and a smart card can be inserted into the device, providing an added layer … Read more

Microsoft, Yahoo team up against lottery hoax e-mails

You know all those hoax e-mails that arrive in your in box saying that you've won a lottery? You don't click on them, obviously, but many people do, enough to prompt Microsoft and Yahoo to form a coalition to warn consumers about the scam.

Microsoft, Yahoo, Western Union, and The African Development Bank are partnering to educate Internet users about the dangers of falling prey to the fake lottery winner e-mails.

In such scams, victims are told that they have won a lottery, often in a foreign country, and are then asked to provide their personal and financial … Read more

Microsoft issues 'critical' patch outside normal cycle

Microsoft will issue a patch for a "critical" security flaw in Windows, the company said Thursday. The patch comes outside of its normal monthly patching cycle due to the severity of the issue.

The vulnerability can result in a remote code execution, in which malicious attackers could take control of a user's computer to launch code.

According to Microsoft's bulletin, the vulnerability is found in Windows 2000 with Service Pack 4, Windows XP, Windows Server 2003, Windows Vista, and Windows Server 2008.

Microsoft will hold a Webcast at 1 p.m. PDT to address the issue. … Read more

English-speakers more at risk of identity fraud

People in English-speaking countries are targeted for identity fraud at twice the rate of many Europeans, according to a new study released by PayPal on Wednesday.

Ten percent of online shoppers in the U.S., the U.K. and Canada--not-surprisingly, places with high percentages of e-commerce transactions--reported being victims of identity fraud, compared with only 5 percent in France, Germany and Spain, the study conducted by Ipsos found.

The Germans had the lowest rate of identity fraud of the countries, with 3 percent reporting problems.

Meanwhile, the Germans were also found to be more cautious with their passwords. Only about … Read more

Microcosm of a massive security problem

A few weeks ago, I gave a presentation to a number of companies about the future of endpoint security. During this presentation, I had the opportunity to ask these folks a number of questions about their IT infrastructure and their plans for it.

There were only about 20 organizations represented, so this was far from a statistically significant research project. Nevertheless, there were some interesting trends:

1. Only one of the organizations was upgrading its endpoint to Vista. It turns out that the one company is a Microsoft business partner so it has to do so. Others said they have … Read more

Google, eBay up, but indexes down

Despite a down day for the broader markets Friday, a handful of tech stocks swam against the tide, posting modest single-digit gains.

Google, Symantec, and eBay were just some of the tech companies to finish the day in the black. The CNET Tech Index was down a modest 1.59 points to end the day at 1,185.55.

Google closed up 5.53 percent to $372.54 a share, which comes as little surprise considering the tech titan posted stronger-than-expected third-quarter earnings results on Thursday. And on Friday, a number of analysts released largely positive comments on the quarter, … Read more

Note to McCain, Obama: Don't forget information security

Regardless of whether you favor Barack Obama or John McCain, you have to admit that the next president will inherit a monumental mess.

Each candidate has been scrambling to explain how he plans to right the financial ship, reign in growing health-care costs, improve education, and balance the budget. Yikes!

As if this wasn't enough, the new president and Congress also have an obligation to figure out how to proceed with a strategic plan for IT and information security.

Now I understand that economic, social, and national security issues should have precedence, but the fact is that the federal … Read more

Virus prompts Asus to recall Japanese Eee Box PCs

You click OK on a message while surfing the Internet and suddenly your computer is full of malicious software and viruses. That's bad. What could be worse worse, however, is when your brand new computer comes preloaded with malicious software.

Tuesday, according to ChinaTechNews.com, Asus announced a recall of it's Asus Eee Box PCs that it had sold in Japan because it was shipped with a virus.

The computers had a file called recycled.exe, residing on the D drive. Once executed, the file would copy itself to other drives, including USB drives, and install malicious software … Read more

Network security makes a quantum leap

The world's largest quantum encrypted network has been unveiled in Vienna, Austria, providing a glimpse of how data could be securely transmitted in the future.

The network is the result of more than four years of work, with 41 organizations from 12 countries working to integrate quantum cryptography into a modern business network.

The project has been overseen by the European Union-sponsored SECOQC (Development of a Global Network for Secure Communication Based on Quantum Cryptography).

Quantum cryptography is a technique of sending information in a way that makes it impossible for people to intercept without corrupting the information in … Read more