Skip to main content

Home/ Unintended Consequences/ Group items tagged security

Rss Feed Group items tagged

Skeptical Debunker

Hold vendors liable for buggy software, group says - 0 views

  • "The only way programming errors can be eradicated is by making software development organizations legally liable for the errors," he said. SANS and Mitre, a Bedford, Mass.-based government contractor, also released their second annual list of the top 25 security errors made by programmers. The authors said those errors have been at the root of almost every major type of cyberattack, including the recent hacks of Google and numerous utilities and government agencies. According to the list, the most common mistakes continue to involve SQL injection errors, cross-site scripting flaws and buffer overflow vulnerabilities. All three have been well-known problems for
  •  
    A coalition of security experts from more than 30 organizations is urging enterprises to exert more pressure on software vendors to ensure that they use secure code development practices. The group, led by the SANS Institute and Mitre Corp., offered enterprises recent hacks of Google draft contract language that would require vendors to adhere to a strict set of security standards for software development. In essence, the terms would make vendors liable for software defects that lead to security breaches. "Nearly every attack is enabled by [programming] mistakes that provide a handhold for attackers," said Alan Paller, director of research at SANS, a security training and certification group.
  •  
    Of course, a more general way to address this and other "business" generated problems / abuses (like expensive required "arbitration" by companies owned and in bed with the companies requiring the arbitration!), is to FORBID contract elements that effectively strip any party of certain "rights" (like the right to sue for defectives; the right to freedom of speech; the right to warranty protections; the right to hold either party to public or published promises / representations, etc.). Basically, by making LYING and DECEIT and NEGLIGENCE liability and culpability unrestricted. Or will we hear / be told that being honest and producing a quality product is "anti-business"? What!? Is this like, if I can't lie and cheat being in business isn't worth it!? If that is true, then those parties and businesses could just as well "go away"! Just as "conservatives" say other criminals like that should. One may have argued that the software industry would never have "gotten off the ground" (at least, as fast as it did) if such strict liability had been enforced (as say, was eventually and is more often applied to physical building and their defects / collapses). That is, that the EULAs and contracts typically accompanying software ("not represented as fit for any purpose" more or less!) had been restricted. On the other hand, we might have gotten software somewhat slower but BETTER - NOT being associated with or causing the BILLIONS of dollars in losses due to bugs, security holes, etc. Others will rail that this will merely "make lawyers richer". So what if it will? As long as government isn't primarily "on the side" of the majority of the people (you know, like a "democracy" should be), then being able to get a individual "hired gun" is one of the only ways for the "little guy" to effectively defend themselves from corporate criminals and other "special interest" elites.
Skeptical Debunker

Browser history hijack + social networks = lost anonymity - 1 views

  •  
    Simply joining a few groups at social networking sites may reveal enough information for hackers to personally identify you, according to some recent computer science research. In a paper that will be presented at a security conference later this year, an international team of academics describes how they were able to build membership sets using information that social networking sites make available to the public, and then leverage an existing attack on browsing history to check for personal identity. That information, they argue, can then be combined with other data to create further security risks, such as a personalized phishing attack.
Skeptical Debunker

Huge 'botnet' amputated, but criminals reconnect - washingtonpost.com - 0 views

  •  
    "The sudden takedown of an Internet provider thought to be helping spread one of the most promiscuous pieces of malicious software out there appears to have cut off criminals from potentially millions of personal computers under their control. But the victory was short-lived. Less than a day after a service known as "AS Troyak" was unplugged from the Internet, security researchers said Wednesday it apparently had found a way to get back online, and criminals were reconnecting with their unmoored machines. "
Skeptical Debunker

Suspend airport body scanner program, privacy groups say - 0 views

  • Based on the discussions at the event, it is evident that body scanners can be easily defeated by concealing explosive materials in body cavities, the letter says. There is also little information on the health risks posed by the use of such scanners, according to the letter. The fact that the systems can be configured at any time to record and store images of travelers also raises privacy questions, the letter says. "The public does not currently understand the inability of these devices to detect the types of explosive materials that could be used or the possible risks to privacy and health," Rotenberg and Nader wrote. "The Department of Homeland Security has made significant mistakes with similar programs in the past," they added, citing as an example the agency's discontinued effort to equip airports with so-called explosive trace portals (ETP), which are designed to detect traces of explosives on travelers' clothing.
  •  
    "The Electronic Privacy Information Center and consumer advocate Ralph Nader are urging President Obama to review the administration's plans to install whole body scanners at U.S. airports. In a joint letter, Marc Rotenberg, the president of EPIC, and Nader asked the president to suspend deployment of the devices until a "comprehensive evaluation" of the effectiveness of the technology and potential health hazards, is completed."
Skeptical Debunker

Firing the $70 billion man - Mar. 10, 2010 - 0 views

  • Not only did TCW oust Gundlach, but the firm also announced that it was acquiring an entire company -- crosstown rival Metropolitan West Asset Management -- to replace him. That in turn set off a wave of defections from TCW, as 45 of the 60 staffers who had worked for Gundlach streamed out the door to join him at a new firm that he had opened within days of leaving.Then things really turned nasty. TCW filed an incendiary lawsuit in January accusing Gundlach of conspiring with confederates at TCW to steal proprietary information as part of a long-running plot to form their own competing firm. The suit added a salacious twist of the knife, perfectly calibrated for maximum media interest -- Gundlach had allegedly stashed a trove of illicit material in his office: 70 pornographic magazines and videos, 12 "sexual devices," and several bags of marijuana.Gundlach has countered with his own lawsuit. He charges TCW and its owner, the French bank Société Générale, with pushing him out so that they can get their hands on his lucrative fees. In addition to his mutual funds, Gundlach had managed what were effectively two hedge funds for TCW, each of which commanded the amped-up fees typical of those vehicles. Gundlach calculates that he would have personally reaped $600 million to $1.2 billion over the next few years.
  • TCW seemed content with the arrangement and did little to tie its managers' fates to the company as a whole. Few of them, for example, received significant stakes in TCW. That bred frustration in multiple generations of standout performers, who viewed corporate executives (some of whom did receive ownership shares) as getting rich off their toil.So it went for Gundlach, a bona fide investing star who, by the end, oversaw about 70% of TCW's assets, some $70 billion, putting him in charge of one of the biggest pots of money in the country. Gundlach didn't just generate steady returns; he avoided the blowup of the century. A specialist in mortgage-backed securities, he publicly warned in 2007 that "the subprime mortgage market is a total, unmitigated disaster, and it's going to get worse." He invested accordingly, not only delivering positive returns in the blighted year of 2008 but also earning himself a growing role as a media sage. His ego grew along with it.There are few people like Jeffrey Gundlach in the mutual fund world -- or in any world. A former rock-and-roll drummer, Gundlach, 50, is a math whiz (but not a quant). He views everything in binary terms: Either you perform to his standards or you don't, and he won't hesitate to let you know which category you fall into. Nor is he shy in articulating his view of himself. "I was by far the biggest revenue generator at TCW, by far the biggest performer," he says. "I created $4 billion in value for clients in '09. If telling you that is self-promotion, so be it. It's just a fact."
  •  
    On November 19, 2009 Jeffrey Gundlach was named a finalist for Morningstar's award for bond fund manager of the decade. For Gundlach, the nomination recognized 10 years of stellar results, exceeding even the returns of the legendary king of bonds, Bill Gross. Two weeks later Gundlach was confronted, fired, and then pursued on foot out of a Los Angeles skyscraper by two lawyers working for TCW, the money management firm with $110 billion in assets where Gundlach had worked for 24 years.
1 - 5 of 5
Showing 20 items per page