January 21, 2005 4:04 PM PST

This week in security

Security is often a complex undertaking, especially when you find your ability to control it wrenched from your hands. An Internet service provider in New York learned that first hand last week, when its domain name and e-mail were apparently hijacked.

A Panix.com representative said that ownership of the domain had been moved to a company in Australia, that the domain name server (DNS) records had been moved to the United Kingdom, and that the company's e-mail had been redirected to a company in Canada. E-mail to the domain was being directed to the false site and "should be considered lost or compromised," the ISP said.

Your desktop may not be much safer. The data protection feature in Microsoft Word and Excel documents has a major flaw that could allow snoopers to decode password-protected files, a security researcher has warned.

In the world of cryptographers, encryption schemes that encode more than one message using the same key are seen as flawed. That's because a comparison of the information in the encrypted messages can significantly shorten the search for the correct key to unlock the messages.

The Office flaw is the latest issue that Microsoft has had with implementing encryption in its products. Security researchers have taken the company to task repeatedly in the past for the weak passwords in previous versions of the Windows operating system.

Meanwhile, Apple Computer was wrestling with its own reports of flaws. A source-code audit of the open-source operating system from which Apple borrowed much of the code for Mac OS X revealed four vulnerabilities of varying severity in Apple's software, a security company said.

The flaws in the Darwin OS affect Mac OS X version 10.3--code-named Panther--and are caused by memory errors in the kernel, according to an advisory released by ImmunitySec, the security company that found the flaws. The flaws include a bug in Mac OS X's SearchFS function, several kernel memory overflows and a logic bug in the AT command, which is used to schedule tasks by the operating system.

See more CNET content tagged:
domain name server, flaw, Apple Computer, Apple Mac OS, Internet Service Provider

Powered by Jive Software
advertisement

Latest tech news headlines

RSS Feeds

Add headlines from CNET News to your homepage or feedreader.

More feeds available in our RSS feed index.

advertisement

Inside CNET News

Scroll Left Scroll Right
  • Nanotech: The Circuits Blog

    Intel ships low-power chips for servers

    New server chips from processor giant draw as little as 12.5 watts per core.

  • Gallery

    Photos: Top 10 reviews of the week

    Here are CNET Reviews' 10 favorite items from the past week, including the TiVo HD XL, Sony Cyber-shot DSC-H50, and the Dish Network's newest digital TV converter box.

  • News - Apple

    Apple watchers spot 'iPod Nano' pix, iTunes hints

    The rumor mill has long been predicting a longer, leaner new version of the iPod Nano, and now it's conjuring up some pictures.

  • Coop's Corner

    Chris Shipley 1, Internet lynch mob 0

    Demo's impresario goes public with a tart and smartly written riposte to the shoot-from-the-lip crowd.

  • Video

    Katie Couric reflects on first Webcast

    The political conventions are over and so are CBS Evening News anchor Katie Couric's first series of Webcasts. CNET's Kara Tsuboi sat down with Couric on the final night of the Republican National Convention to discuss what she liked about Webcasting, some of her most memorable guests, and whether TV news will still be around by the next round of conventions.

  • Webware

    Google upgrades Gmail for IE 6 users

    The online e-mail application is faster for those using the 7-year-old browser and gets features already available to more modern browsers, Google said.

  • Video

    YouTube plays party politics

    During the presidential campaigning four years ago, YouTube didn't even exist. Now it's a tool candidates must master to get their message across. CNET's Kara Tsuboi stops by the YouTube upload booths at the Democratic and Republican conventions to find out why Google's video site has such a big presence in Denver and St. Paul, Minn.

  • News - Gaming and Culture

    Are Demo and TechCrunch50 fragmenting their audiences?

    With both events scheduled to start Monday, many press, as well as venture capitalists and others are having to choose which one to attend.

  • News - Cutting Edge

    Execs predict next Google-like tech

    On eve of company's 10-year anniversary, researchers and business pundits speculate about what technologies might someday have as much impact as Google.

  • Gallery

    Images: The art of 'Spore' prototypes

    Will Wright and his Maxis team worked on dozens of prototypes to test the elements of their soon-to-be-released evolution game. Here's a sampling.

  • Crave

    Fry's Electronics leaks more slim Zune details

    Features include a 'Device Cloud,' customizable music channels, and free games.

  • Green Tech

    TI does energy efficiency on a chip

    Its line of Piccolo microcontrollers can reduce power consumption significantly of home appliances, hybrid cars, LED lighting, and even solar panels.