Homeland Security mock cyberattack

The government has ended its first large-scale mock cyberattack, aimed at gauging the nation’s readiness to handle such threats, the Department of Homeland Security said Friday. The weeklong exercise, dubbed "Cyber Storm," was organized by the department’s National Cyber Security Division and 115 public- and private-sector partners. It was designed to model the coordination among government and industry necessary for responding to and recovering from "large-scale" intrusions affecting the energy, information technology, telecommunications and transportation sectors.

Posted on: February 13, 2006 9:00 am

Senators caught rewriting Wikipedia

Wikipedia has come under fire in recent months by critics that question the reliability of its information. But the site’s investigation into Congressional changes highlight how closely amendments to information are scrutinized. The online reference compendium has found that employees working in the U.S. Congress have made several changes to political biographies, removing facts considered negative and tweaking language to portray politicians in a better light. Wikipedia began an investigation after a Democratic representative, Marty Meehan, admitted that he had spiffed up his online biography page. It was found that articles on other senators had been changed, sometimes significantly, and that the edits could be traced to computers on Capitol Hill. Researchers discovered the links to the U.S. Senate and began checking the biographies that had been visited. Half a dozen pages were changed, according to Wikipedia, including those of California Senator Dianne Feinstein, Iowa Senator Tom Harkin, and Minnesota Senator Norm Coleman.

Posted on: February 10, 2006 9:00 am

Seven deadly sins of Linux

Some security sins never change, but new threats offer new opportunities to make mistakes. Not too long ago, SearchOpenSource.com talked to Bob Toxen, security consultant and author of Real World Linux Security about the seven deadly sins of Linux security. What may be most surprising is not that this new list now includes more than the original seven sins, but that the first seven have remained intact even with millions if not billions of dollars poured into the security space by companies worldwide. Inadequate password practices and protection, general procrastination, and inefficient resource allocation all still top the list.

Posted on: February 10, 2006 9:00 am

Loyalty costs of data breaches

As the reports of companies losing customer data continue to pile up, privacy protection is becoming a top-of-mind issue, both for customers, who naturally don’t want their personal information falling into the wrong hands, and companies, who are suffering real damage to their brand, customer loyalty and bottom line. A majority of customers who received data breach notifications were unsatisfied with the quality of the notification and communication process. The method of communicating with customers can go a long way toward maintaining customer loyalty. For example, companies that report a breach are more than four times as likely to experience customer churn if they fail to communicate to the victim in a clean, consistent, and timely fashion. Companies that deploy emails or form letters to communicate a breach are more than three times more likely to experience churn than companies that use the telephone or personalized letters.

Posted on: February 10, 2006 9:00 am

Spyware tripled in 2005

Last year was the biggest year yet for spyware, as consumers, small businesses, and enterprises across the globe were invaded by a plague of malicious software. Trojan horses and system monitors were the most malicious types of spyware unleashed on computers, says software vendor Webroot in a new report called "The State of Spyware." Antivirus programs and free antispyware solutions are ineffective against these complicated and sophisticated programs, Webroot concluded.

Posted on: February 10, 2006 9:00 am

India fastest-growing market

India is the fastest-growing market worldwide for IBM, with the company increasing revenue there by 55 percent last year, a senior IBM executive said Thursday. The growth was driven by IBM’s focus on specific industries, such as banking and government, Shanker Annaswamy, managing director of IBM India, told reporters in Bangalore. Annaswamy did not disclose a dollar figure for IBM’s India revenue. The growth rate does not take into account PC revenues, as IBM sold this business in early 2005 to China’s Lenovo Group.

Posted on: February 10, 2006 9:00 am

CrossOver Office for Linspire 5.0

CodeWeavers and Linspire on Wednesday announced CrossOver Office for Linspire 5.0, the first time the software has been made available for the Linspire Linux OS. CrossOver Office 5.0 Standard is now available for Linspire users via Linspire’s one-click CNR software download service. Once installed, the supported applications will launch, just as they would in Windows, within the Linspire environment. Any documents created using CrossOver Office applications may be opened and edited with other native Linux programs, such as OpenOffice.org or GIMP, CodeWeavers said.

Posted on: February 9, 2006 9:00 am

Effects of domain hijacking

Malicious hackers who are able to hijack an organization’s Web domain may be able to steal traffic from the legitimate Web site long after the domain has been restored to its owner, according to a recent report. Design flaws in the way Web browsers and proxy servers store data about Web sites allow malicious hackers to continue directing Web surfers to malicious Web pages for days or even months after the initial domain hijacking. The persistent attack could lead to information or identity theft, according to Amit Klein, a Web application security researcher with the Web Application Security Consortium.

Posted on: February 9, 2006 9:00 am

RIM announces workaround

Research In Motion today provided an update in the patent litigation between RIM and NTP. RIM has developed and tested software workaround designs for all BlackBerry handsets operating on converged voice/data networks in the United States. Although there is no injunction order in place, and RIM believes it has strong legal and factual arguments opposing an injunction, RIM has developed these software workaround designs as a contingency to allow BlackBerry service to continue should the court implement an injunction in the current litigation involving the NTP patents.

Posted on: February 9, 2006 9:00 am

Sun issues patch

Sun Microsystems issued a patch Tuesday to address seven "highly critical" flaws in its Java Runtime Environment that could allow a malicious attacker to gain remote control over a user’s system. The flaws affect systems running on Windows, Solaris and Linux that are using certain versions of Sun’s Java Development Kit 1.5, Software Development Kit 1.3 and 1.4, and JRE 1.3, 1.4, 1.5 and 5.0, or earlier, according to an advisory issued by Secunia, which rated the flaws as "highly critical." Sun’s JRE software, especially version 1.4, is found on a number of computers and allows users to run Java applications, which operate in a "sandbox"–a separate area cordoned off from the rest of the user’s system.

Posted on: February 9, 2006 9:00 am