Blizzard’s Two-Factor Authentication

Tuesday, July 1st, 2008

Blizzard's announcement of two-factor authentication for World of Warcraft is more significant than people realize. Passwords are obsolete. They are broken. We all recognize this, yet we aren't quite ready to give up on passwords because we haven't an easy alternative. World of Warcraft (WoW) is a good test case. It is ...

Facebook security snafu could compromise accounts

Friday, May 23rd, 2008

A researcher has spotted a security problem in Facebook that could lead to hackers taking control of user accounts. The flaw allows a hacker to execute scripts on Facebook that could potentially be used to create a fake log-in page and capture people's passwords, according to the XSSED security blog. The ...

Keep Vista’s User Account Control on guard duty

Thursday, May 1st, 2008

Well, Microsoft has finally come clean about the real motivation behind Vista's User Account Control feature. As Tom Espiner's reports from the recent RSA Conference in San Francisco, Microsoft UAC Program Manager David Cross admits that UAC was designed to annoy users. Espiner quotes Cross telling the security-conference audience that negative ...

Disabling UAC for Only Administrators

Monday, April 21st, 2008

You can disable the—sometimes annoying—User Account Control (UAC) prompts for members of the Administrators group, while leaving them active for limited user accounts. This is great if you don’t want others accessing or changing system settings. Disabling the alerts, however, requires editing the Windows Registry: Hive: HKEY_LOCAL_MACHINE Key: SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System Name: ConsentPromptBehaviorAdmin Type: REG_DWORD Value: 0 ...

Details of privilege escalation hole in Windows

Monday, April 21st, 2008

In a security alert last week, Microsoft reported a vulnerability which allows local users and users signed on with access to an Internet Information Server (IIS) or MS SQL server to escalate their privileges. Server operators such as hosting providers who allow user code to be executed, for example on ...

Turn Off or Disable User Account Control (UAC) in Windows Vista

Saturday, April 12th, 2008

User Account Control (UAC) is a new security feature in Windows Vista that requires all users to log on and run in standard user privileges mode instead of as administrator with full administrative rights, thus prevent unauthorized or accidental changes that could destabilize the computers or allows virus and malware ...

Surf More Safely In Any Browser

Saturday, March 8th, 2008

This is one of those ideas that make you want to slap your forehead and wonder why it never occurred to you before. I don't remember what prompted it, but I decided to do a little experiment with my virtual test PC. I created a low-level user account and then ...

Five steps to make your computer more secure

Saturday, March 8th, 2008

These days, a firewall, anti-virus software and anti-spyware programs are essential, but they might not be enough to protect you. Here are five things you can do for a little added security: Leave your computer on. This is a change from an earlier recommendation that you turn it off to save ...