Black Hat spotlights security research

IT security pros, analysts and researchers are coming together for the meeting of the minds that is Black Hat 2008. The popular security conference officially kicked off Aug. 2 in Las Vegas with a series of training sessions that wrap up Aug. 5. However, the real buzz for many attendees will be the technical briefings Aug. 6-7 at Caesars Palace.

The activities Aug. 6 will begin with some words from Black Hat founder Jeff Moss and a keynote from author and London School of Economics professor Ian Angell. From there, the conference launches into two days of briefings on several different tracks such as reverse engineering and rootkits.

Posted on: August 6, 2008 9:00 am

Looks like we’re upgraded!

Well, after about 3 1/2 hours, it looks like our new upgrade is up. What you’ll notice most is going to be a new consistency of fonts across pages. There’s more to come, and a lot of tweaks, but we think the new system is now working.

Since it’s about 3:30am here in Central Florida, it’s time to go watch some TV, wind down, and get some sleep. If you notice anything weird (weirder than usual, please!), let us know.

Posted on: August 6, 2008 9:00 am

Site update

OK, folks. We’re about to install a major upgrade we’ve been working on over the past few months. We’re going to do so from midnight tonight, until it’s working. Hopefully, you won’t see much different (the upgrade’s mostly behind the scenes) although once it’s running, it’ll enable us to do a lot we’ve been unable to do without it.

This is a big upgrade and the site may look crapply for a few hours. If it continues through to the morning, we’ll post another update, but we’re honestly hoping everything will be back to pretty much normal by about 2am.

Thanks for your patience and send cookies.

Posted on: August 6, 2008 9:00 am

IBM engineer touts SELinux

SELinux has achieved its goal of protecting Linux systems from intrusion by unauthorized access. But the effort remains in the early adopter stage, and its supporters need to work on broader implementation and greater ease of use, according to Doc Shankar, an IBM distinguished engineer.

In a preview of his LinuxWorld Conference & Expo workshop, Shankar said that the biggest benefit of SELinux is that systemwide policies automatically and absolutely enforce access controls. No one gets the unrestricted access of a "root" superuser; instead, each user is confined to what he needs to know, he said. In the case of a breech, an intruder is boxed in and can destroy only a portion of the system, he said.

Posted on: August 4, 2008 9:00 am

Comcast guilty of neutrality violations

In the first major test of the FCC’s network neutrality principles, the agency found Comcast guilty Aug. 1 of secretly degrading network traffic. On a 3-2 vote, the FCC ordered Comcast to stop blocking traffic, disclose to the FCC the full extent of the cable giant’s traffic practices and to keep the public informed of its future network management plans.

The FCC said Comcast violated the agency’s Internet policy when it blocked P2P traffic by BitTorrent. The agency also found that Comcast misled consumers when it did not properly disclose its P2P policy.

Posted on: August 4, 2008 9:00 am

IBM prepares to fight off Microsoft

IBM/Lotus hit back at Microsoft’s boast that it plans to steal 5 million Notes customers this year by detailing a new 300,000-seat licensing deal with an Asian company and strong interest in Notes from emerging markets.

Last week, Microsoft’s COO Kevin Turner told financial analysts that his goal is to have the company’s messaging and collaboration software displace 5 million Notes seats this year. Turner also said Microsoft has replaced 8 million seats of Notes in the past two years.

It was another shot in a messaging and collaboration war that has been going on between the two for nearly 20 years. In the late 1990s, the two jousted using email seat-count numbers that were often inflated if not outright dubious.

Posted on: August 4, 2008 9:00 am

Symantec warns of IE6 vulnerability

A vulnerability in as-yet unpatched Microsoft software poses a more severe threat to Internet Explorer 6 users than those on the next version of the browser, security vendor Symantec has warned.

The flaw in Microsoft’s Access database software came to light just as Microsoft issued its patches for the month in early July. The problem is within the Snapshot Viewer ActiveX control, which allows someone to see an Access report without launching the software.

Posted on: August 4, 2008 9:00 am

GAO wasted billions on IT projects

Government agencies are spending billions of dollars on IT investments that are redundant, lack clear goals and are managed by unqualified individuals, U.S. Sen. Tom Carper, D-Del., said July 31. Some of the projects have been delayed for more than a decade and are costing billions more than originally budgeted.

Citing a new GAO (Government Accountability Office) study that found more than 400 federal IT projects worth approximately $25 billion are suffering from poor planning or are underperforming, Carper said it might time for Congress to pull the plug on some of the projects.

Posted on: August 4, 2008 9:00 am

Homeland Security can seize laptops indefinitely

The U.S. Department of Homeland Security has concocted a remarkable new policy: It reserves the right to seize for an indefinite period of time laptops taken across the border. A pair of DHS policies from last month say that customs agents can routinely–as a matter of course–seize, make copies of, and "analyze the information transported by any individual attempting to enter, re-enter, depart, pass through, or reside in the United States." DHS claims the border search of electronic information is useful to detect terrorists, drug smugglers, and people violating "copyright or trademark laws."

This is a disturbing new policy, and should convince anyone taking a laptop across a border to use encryption to thwart DHS snoops. Encrypt your laptop, with full disk encryption if possible, and power it down before you go through customs. Here’s a guide to customs-proofing your laptop published in March.

Posted on: August 1, 2008 9:00 am

Federal laptops mostly unsecured, unencrypted

The Government Accountability Office slammed the Bush administration in a report released July 29 saying 70 percent of laptops, notebook PCs, and mobile devices used by federal agencies in the executive branch are not encrypted or secure.

The GAO report comes more than two years after the Department of Veterans Affairs reported a laptop stolen and the names and Social Security numbers of 26 million veterans were exposed, in the second-largest data breach on record. Today only 30 percent of federal agency laptops and mobile devices are using encryption to protect data, according to the report.

Posted on: August 1, 2008 9:00 am