Microsoft hints at “private browsing” feature in IE

Wednesday, August 20th, 2008

One of the most interesting feature that didn’t quite make it into the final release of Firefox 3 is “Private Browsing”, a.k.a. porn mode. The only other browser with this feature built-in today is Safari (another reason to try it in case you haven’t), however, Microsoft may also be building ...

New Gpcode (encryption) ransomware speading via botnet

Wednesday, August 13th, 2008

There are confirmed reports on a new version of the Gpcode ransomware being spread via a botnet.According to Vitaly Kamluk of Kaspersky Lab (my employer), the Trojan encrypts files on an infected machine (AES-256) and leaves a text file named crypted.txt with a ransom note demanding $10 to decrypt the ...

Keyczar – Google’s crypto for non-cryptographers

Tuesday, August 12th, 2008

Google has released Keyczar, billed as a "Toolkit for safe and simple cryptography", under an Apache 2.0 open source licence. Keyczar has been developed by members of the Google security team and aims to make cryptography more accessible to application developers.Keyczar's design goals were to manage the complexity of cryptography ...

Surf Jack – HTTPS will not save you

Monday, August 11th, 2008

Say hello to a new security tool called “Surf Jack” which demonstrates a security flaw found in many public sites. The proof of concept tool allows testers to steal session cookies on HTTP and HTTPS sites that do not set the Cookie secure flag. I’ve been working with two banks ...

Microsoft changing Patch Tuesday process

Sunday, August 10th, 2008

Microsoft is to release fixes for a dozen serious vulnerabilities next Tuesday, seven of them ranked critical. But the firm has also announced a three-stage process to reducing the effects of future vulnerabilities.Next week’s update (the regular ‘Patch Tuesday’ release which comes in the second week of each month) includes ...