Duffy's Rant Netcast » Tech Stuff http://duffysrant.com News and comment from the south suburbs of Chicago Mon, 26 Jul 2010 14:49:40 +0000 en hourly 1 http://wordpress.org/?v=3.0 ©Duffy duffy@duffysrant.com (Duffy) duffy@duffysrant.com(Duffy) 1440 News and comment from the south suburbs of Chicago Duffy Duffy duffy@duffysrant.com No no http://duffysrant.com/wp-content/plugins/podpress/images/as3452_144.jpg Duffy's Rant Netcast http://duffysrant.com 144 144 Gotta question http://duffysrant.com/2010/07/14/gotta-question/ http://duffysrant.com/2010/07/14/gotta-question/#comments Wed, 14 Jul 2010 23:57:27 +0000 Duffy http://duffysrant.com/2010/07/14/gotta-question/ I’m using a USB app suite (liberkey)right now but don’t have the plugin for Flash because it’s a library computer.  Anyone manage to get flash working?

]]>
http://duffysrant.com/2010/07/14/gotta-question/feed/ 0
More on the FCC item http://duffysrant.com/2010/07/14/more-on-the-fcc-item/ http://duffysrant.com/2010/07/14/more-on-the-fcc-item/#comments Wed, 14 Jul 2010 23:55:43 +0000 Duffy http://duffysrant.com/2010/07/14/more-on-the-fcc-item/ Here’s more info on the FCC obscenity rule getting quashed by the Federal Court:

<a href=”http://www.dvorak.org/blog/2010/07/13/court-tosses-fcc-naughty-language-policy-about-f_n-time/”>More on FCC</a>

]]>
http://duffysrant.com/2010/07/14/more-on-the-fcc-item/feed/ 0
SP2 Updates to end this week! http://duffysrant.com/2010/07/12/sp2-updates-to-end-this-week/ http://duffysrant.com/2010/07/12/sp2-updates-to-end-this-week/#comments Mon, 12 Jul 2010 15:27:35 +0000 Duffy http://duffysrant.com/2010/07/12/sp2-updates-to-end-this-week/ Okay, you guys. You know who you are…the ones who haven’t bothered to install service Pack 3 on the XP computer. This is fair warning: THERE WILL BE NO MORE UPDATES OF ANY KIND FOR XP USERS WHO HAVEN’T UPDATED THEIR SYSTEMS TO SERVICE PACK 3!!!!!!

Here’s the link to the USA Today article:

Microsoft Windows XP Service Pack 2 updates to stop this week – USATODAY.com

]]>
http://duffysrant.com/2010/07/12/sp2-updates-to-end-this-week/feed/ 0
Hey you, using the campus network to get music http://duffysrant.com/2010/07/01/hey-you-using-the-campus-network-to-get-music/ http://duffysrant.com/2010/07/01/hey-you-using-the-campus-network-to-get-music/#comments Thu, 01 Jul 2010 22:37:04 +0000 Duffy http://duffysrant.com/2010/07/01/hey-you-using-the-campus-network-to-get-music/ Think REAL hard about that.  New rules went into effect today that will definitely affect you!

New file sharing rules kick in today

]]>
http://duffysrant.com/2010/07/01/hey-you-using-the-campus-network-to-get-music/feed/ 0
Now what! PDF files vulnerable to in the wild exploits http://duffysrant.com/2010/06/29/now-what-pdf-files-vulnerable-to-in-the-wild-exploits/ http://duffysrant.com/2010/06/29/now-what-pdf-files-vulnerable-to-in-the-wild-exploits/#comments Tue, 29 Jun 2010 20:47:32 +0000 Duffy http://duffysrant.com/2010/06/29/now-what-pdf-files-vulnerable-to-in-the-wild-exploits/ From the SANS Newsletter:

 –Unpatched PDF Flaw is Being Actively Exploited
(June 28, 2010)
An unpatched hole in the PDF format is being actively exploited.
Attackers are sending malicious messages that appear to come from
company system administrators and have subject headings regarding
mailbox setting changes.  The messages claim the attachments contain
instructions for updating email settings.  The attachments instead
infect users’ computers with malware known as Auraax or Emold.  The
attack exploits PDF viewers’ “/Launch” functions to infect computers.
http://www.computerworld.com/s/article/9176088/Major_malware_campaign_abuses_unfixed_PDF_flaw?taxonomyId=208

 

[Editor's Note (Northcutt): Is there an alternative to a .pdf? It was
supposed to be a printable image of what you saw on the screen. At least
that was the idea 15 years ago. It should not need "launch" functions
to do that. Do you remember five or six years ago, you weren't supposed
to send an excel spreadsheet or a word document because they might
contain malware, you were supposed to send a .pdf. Guess that has
changed! If anyone has a suggestion for a replacement for .pdfs that
works on linux, Apple and Microsoft and has almost no features beyond
imaging of the document, please drop me a note (stephen@sans.edu).]

AND, hot the heels of this:

 –Adobe to Release Reader and Acrobat Security Updates Two Weeks Ahead
   of Schedule
(June 24 & 25, 2010)
Adobe will release security updates for Reader and Acrobat on Tuesday,
June 29, two weeks ahead of the company’s regularly scheduled
quarterly security update.  The updates address a critical
vulnerability in Flash that is being actively exploited.  Adobe
released a fix for the issue in Flash Player on June 10.  Because of
the accelerated patch release, Adobe will not be issuing updates on
July 13, 2010.  The affected software includes Adobe Reader 9.3.2 and
earlier for Windows, Mac and UNIX, and Adobe Acrobat 9.3.2 and earlier
for Windows and Mac.
http://www.h-online.com/security/news/item/Adobe-brings-forward-security-update-for-Reader-1029200.html

 

http://www.theregister.co.uk/2010/06/25/adobe_pdf_flash_security_update/

 

http://www.adobe.com/support/security/bulletins/apsb10-15.html

 

Now, this does not surprise me.  Finally, it looks like Adobe is doing what it should have been doing all along.

And from the world of Google:

 –Updated Chrome Incorporates Latest Version of Flash Player
(June 25 & 27, 2010)
Google has released an update for its Chrome browser to address five
security flaws, three rated critical.  Chrome version 5.0.375.86 also
incorporates the built-in Flash Player.  Flash support was integrated
in Chrome in the beta phase, but Google waited for Flash Player 10.1 to
integrate it in the stable version of Chrome 5.  The updated version of
the browser is available for Mac, Linux and Windows.
http://www.pcworld.com/article/199933/google_chrome_integrates_flash.html?tk=hp_new

 

http://www.h-online.com/security/news/item/Chrome-update-fixes-vulnerabilities-and-activates-Flash-support-1029314.html

 

http://googlechromereleases.blogspot.com/2010/06/stable-channel-update_24.html

 

]]>
http://duffysrant.com/2010/06/29/now-what-pdf-files-vulnerable-to-in-the-wild-exploits/feed/ 0
New version of firefox released http://duffysrant.com/2010/06/26/new-version-of-firefox-released/ http://duffysrant.com/2010/06/26/new-version-of-firefox-released/#comments Sat, 26 Jun 2010 15:40:46 +0000 Duffy http://duffysrant.com/2010/06/26/new-version-of-firefox-released/
Here’s another item from the SANS Newsbytes newsletter.  I’ve gotten the new version that was set up for Portable Apps and I still am not happy.
Firefox takes a LONG time to load and it’s slower than molasses in winter at times.  I’m disappointed because I love Firefox but this version….I dunno.


 –Firefox Update Incorporates Crash Protection
(June 22 & 23, 2010)
On Tuesday, June 22, Mozilla released updates for Firefox versions 3.5
and 3.6 to address nine vulnerabilities, six of which are rated
critical.  Firefox 3.6.4 also incorporates crash protection.  If users
running the latest version of Firefox experience a plug-in freeze or
crash, users can refresh the page instead of having to restart the
browser.  The current version of the feature allows users to recover
from Flash Player, QuickTime and Silverlight plug-in crashes for users
running Windows and Linux.  Mozilla plans to expand the crash protection
to other plug-ins and operating systems.
http://www.h-online.com/security/news/item/Firefox-3-6-4-adds-crash-protection-fixes-vulnerabilities-Update-1027586.html

 

http://www.computerworld.com/s/article/9178408/Mozilla_patches_9_Firefox_bugs_adds_plug_in_crash_protection?taxonomyId=85

 

]]>
http://duffysrant.com/2010/06/26/new-version-of-firefox-released/feed/ 0
Twitter settles FTC suit http://duffysrant.com/2010/06/26/twitter-settles-ftc-suit/ http://duffysrant.com/2010/06/26/twitter-settles-ftc-suit/#comments Sat, 26 Jun 2010 15:36:56 +0000 Duffy http://duffysrant.com/2010/06/26/twitter-settles-ftc-suit/ Again, from the SANS Newsbites newsletter:

–Twitter Settles FTC Privacy Charges

(June 24, 2010)

Twitter has agreed to a settlement with the US Federal Trade Commission

(FTC) over privacy issues stemming from two attacks that compromised

Twitter accounts.  The FTC complaint says that Twitter’s stated privacy

policy at the time led users to believe that stronger privacy

protections were in place than were actually in use.  On two separate

occasions in 2009, attackers gained unauthorized access to

administrative control of the Twitter service.  In January 2009, an

attacker gained administrative access to Twitter through a brute force

dictionary attack.  The intruder reset user passwords and posted some

of the passwords on a website, where others accessed them and used them

to send phony messages from those accounts.  In April 2009, a Twitter

employee’s account was compromised, compromising Twitter user’s personal

information and messages sent.  At the time, Twitter had no policy

against easy-to-guess administrative passwords, nor did it suspend or

disable account access after a certain number of failed log-in attempts.

Twitter has now implemented many of the FTC’s security recommendations.

The terms of the agreement prohibit Twitter from “misleading consumers

about the extent to which it maintains and protects the security,

privacy, and confidentiality of nonpublic consumer information.”

Twitter will also be required to undergo third-party security audits.

http://voices.washingtonpost.

com/posttech/2010/06/twitter_

settles_charges_by_ftc.html

http://www.wired.com/

threatlevel/2010/06/twitter-

settles-with-ftc/

http://www.msnbc.msn.com/id/

37903432/ns/technology_and_

science-security/

http://www.computerworld.com/

s/article/9178473/Twitter_

settles_FTC_privacy_complaint

[Editor's Note (Pescatore and Paller): Back in 2007 the FTC managed to

reach a similar agreement with Microsoft around questionable privacy

practices in Microsoft Passport. Notice how the FTC has managed to be

an effective regulatory agency without requiring any new laws or

regulations? Kudos to FTC.]

]]>
http://duffysrant.com/2010/06/26/twitter-settles-ftc-suit/feed/ 0
CORRECTION: Posting about the Protecting Cyberspace as a National Asset Act http://duffysrant.com/2010/06/26/correction-posting-about-the-protecting-cyberspace-as-a-national-asset-act/ http://duffysrant.com/2010/06/26/correction-posting-about-the-protecting-cyberspace-as-a-national-asset-act/#comments Sat, 26 Jun 2010 15:35:39 +0000 Duffy http://duffysrant.com/2010/06/26/correction-posting-about-the-protecting-cyberspace-as-a-national-asset-act/ I’m not the only one who got FUDed on this one.

This is from my SANS Newsletter!  Go to the links and read.

–No Kill Switch in Cyber Security Bill

(June 23 & 24, 2010)

In response to misconceptions about their proposed cyber security

legislation, US Senators Joseph Lieberman (I-Conn.), Susan Collins

(R-Maine) and Thomas Carper (D-Del.) have published a fact sheet to

clarify issues and quash rumors about the powers the bill grants.  The

Protecting Cyberspace as a National Asset Act

does not give the

president the authority to take control or shut down the Internet.

http://cybersecurityreport.

nextgov.com/2010/06/cyber_

bills_welcomed_scrutiny.php

http://www.informationweek.

com/news/government/security/

showArticle.jhtml?articleID=

225701368

http://www.pcworld.com/

businesscenter/article/199825/

senate_panel_approves_

controversial_cybersecurity_

bill.html

http://hsgac.senate.gov/

public/?FuseAction=home.

Cybersecurity

]]>
http://duffysrant.com/2010/06/26/correction-posting-about-the-protecting-cyberspace-as-a-national-asset-act/feed/ 0
Viacom loses another lawsuit http://duffysrant.com/2010/06/25/viacom-loses-another-lawsuit/ http://duffysrant.com/2010/06/25/viacom-loses-another-lawsuit/#comments Fri, 25 Jun 2010 17:59:33 +0000 Duffy http://duffysrant.com/2010/06/25/viacom-loses-another-lawsuit/ The Google v. Viacom case has come to the ruling that Google is not liable for the postings on YouTube.

Click on the link for more info.

Viacom/Google case ruling

]]>
http://duffysrant.com/2010/06/25/viacom-loses-another-lawsuit/feed/ 0
New version of Firefox http://duffysrant.com/2010/06/23/new-version-of-firefox/ http://duffysrant.com/2010/06/23/new-version-of-firefox/#comments Wed, 23 Jun 2010 18:09:43 +0000 Duffy http://duffysrant.com/2010/06/23/new-version-of-firefox/ It’s out.  3.6.4.  This is the latest and greatest and, if the reports are to be believed, will help with those retarded Flash apps

that regularly puke on everyone.

PC Mag article on Firefox 3.6.4

]]>
http://duffysrant.com/2010/06/23/new-version-of-firefox/feed/ 0