Click here to Skip to main content
15,890,579 members

The Insider News

   

The Insider News is for breaking IT and Software development news. Post your news, your alerts and your inside scoops. This is an IT news-only forum - all off-topic, non-news posts will be removed. If you wish to ask a programming question please post it here.

Get The Daily Insider direct to your mailbox every day. Subscribe now!

 
GeneralRe: Google Study Shows Security Questions Aren’t All That Secure Pin
Dan Neely22-May-15 5:35
Dan Neely22-May-15 5:35 
NewsUS proposes tighter export rules for computer security tools Pin
Kent Sharkey21-May-15 8:20
staffKent Sharkey21-May-15 8:20 
NewsJava's key to success is simplicity Pin
Kent Sharkey21-May-15 8:19
staffKent Sharkey21-May-15 8:19 
GeneralRe: Java's key to success is simplicity Pin
Nemanja Trifunovic21-May-15 9:08
Nemanja Trifunovic21-May-15 9:08 
NewsWith one false tweet, computer-based Hack Crash led to real panic Pin
Kent Sharkey20-May-15 18:54
staffKent Sharkey20-May-15 18:54 
NewsNewer versions of Windows are getting better at protecting against malware according to security report Pin
Kent Sharkey20-May-15 8:44
staffKent Sharkey20-May-15 8:44 
GeneralRe: Newer versions of Windows are getting better at protecting against malware according to security report Pin
Dan Neely21-May-15 3:03
Dan Neely21-May-15 3:03 
GeneralRe: Newer versions of Windows are getting better at protecting against malware according to security report Pin
Dan Neely21-May-15 3:43
Dan Neely21-May-15 3:43 
Flipping through the report itself[^] a few interesting things I've noticed are:

Page 23 (MS page numbers, not pdf reader page number): In a steady slump, the frequency of Java based exploits is half of what it was a year ago. Whether this is due to whOracle patching bugs out or the general booting of java from browsers this is a very good thing even if it means OS exploits (also down over the year) are back to the number 2 category. Flash player attacks have remained a rounding error for the entire year. Congrats to Adobe for cleaning up their mess. Cool | :cool:

Page 30: Almost all of the OS exploits have been against a single bug that uses social engineering to get people to click a malicious shortcut in explorer. The bug was patched in 2010. Cry | :(( Cry | :(( Cry | :(( Stuff like this is why I'd really like to see a comparison between a fully patched Vista/Weven machine and a fully patched 8.1 machine.

Page 32: The overwhelming majority of document exploits target an Acrobat Reader bug that was patched in 2010. Cry | :(( Cry | :(( Cry | :((

Page 33: Top 3 Flash bugs were from 2014 at least; but one of the two tied for #4 for the year was another patched in 2010 bug. Cry | :((

Page 34: If page 23 shows that successful flash attacks were rare; it's not for lack of trying. They were the most commonly seen attempted attack type for the year.

Page 39: 19.2% of computers encountered malware at least once in 2014, 0.91% were pwned.

Page 41/44: Malware encounter rates were two or three times higher in selected middle income countries than in rich ones. The map on page 44 suggests that poor countries fared even worse and that the middle east/north Africa got hammered. Not really sure what to make about this.

Page 56/57: MS added crapware that bypasses browser addon confirmation dialogs to its malware detection categories in Q4; big spike in reports for that type as a result.

Page 68: Ransomware (eg cryptolocker) was a category of malware that unlike the overall picture was largely limited to attacks in the rich world; but the most common flavor was limited to in browser attacks.

Page 80: Computers without AV get pwned a lot more often than those with. You know that. I know that. But there're a lot of sunshines who're convinced they're too smart to do something to get infected. A lot of malware installs via drive by downloads in exploited webpages belonging to trusted organizations. You don't have to be browsing the underbelly of the net to get infected.
Did you ever see history portrayed as an old man with a wise brow and pulseless heart, waging all things in the balance of reason?
Is not rather the genius of history like an eternal, imploring maiden, full of fire, with a burning heart and flaming soul, humanly warm and humanly beautiful?
--Zachris Topelius

Training a telescope on one’s own belly button will only reveal lint. You like that? You go right on staring at it. I prefer looking at galaxies.
-- Sarah Hoyt


modified 22-Sep-15 17:05pm.

NewsDev Tidbits #001: How much caffeine do developers consume? Pin
Kent Sharkey20-May-15 8:34
staffKent Sharkey20-May-15 8:34 
GeneralRe: Dev Tidbits #001: How much caffeine do developers consume? Pin
R. Giskard Reventlov20-May-15 9:46
R. Giskard Reventlov20-May-15 9:46 
GeneralRe: Dev Tidbits #001: How much caffeine do developers consume? Pin
Sander Rossel20-May-15 10:41
professionalSander Rossel20-May-15 10:41 
GeneralRe: Dev Tidbits #001: How much caffeine do developers consume? Pin
Matt T Heffron20-May-15 16:04
professionalMatt T Heffron20-May-15 16:04 
NewsEFF's Secure Messaging Scoreboard empowers developers and educates users Pin
Kent Sharkey20-May-15 8:32
staffKent Sharkey20-May-15 8:32 
GeneralRe: EFF's Secure Messaging Scoreboard empowers developers and educates users Pin
Duncan Edwards Jones20-May-15 20:33
professionalDuncan Edwards Jones20-May-15 20:33 
NewsAmericans don't trust government or corporations with their privacy, Pew Survey says Pin
Kent Sharkey20-May-15 8:24
staffKent Sharkey20-May-15 8:24 
GeneralRe: Americans don't trust government or corporations with their privacy, Pew Survey says Pin
Sander Rossel20-May-15 11:10
professionalSander Rossel20-May-15 11:10 
NewsProducing open source software: “free” versus “open source” Pin
Kent Sharkey20-May-15 8:17
staffKent Sharkey20-May-15 8:17 
NewsWindows 10's success hinges on apps, and overcoming developer apathy Pin
Kent Sharkey20-May-15 8:16
staffKent Sharkey20-May-15 8:16 
NewsTwenty years of Java through its creator’s eyes Pin
Christopher Shields20-May-15 6:13
Christopher Shields20-May-15 6:13 
NewsC# Futures: Method Contracts Pin
Christopher Shields20-May-15 6:06
Christopher Shields20-May-15 6:06 
NewsWCF is Open Source Pin
Kent Sharkey20-May-15 5:54
staffKent Sharkey20-May-15 5:54 
GeneralRe: WCF is Open Source Pin
Marc Clifton20-May-15 6:01
mvaMarc Clifton20-May-15 6:01 
GeneralRe: WCF is Open Source Pin
Christopher Shields20-May-15 6:06
Christopher Shields20-May-15 6:06 
JokeRe: WCF is Open Source Pin
Ravi Bhavnani20-May-15 8:47
professionalRavi Bhavnani20-May-15 8:47 
NewsJava at 20: Its successes, failures, and future Pin
Kent Sharkey20-May-15 5:52
staffKent Sharkey20-May-15 5:52 

General General    News News    Suggestion Suggestion    Question Question    Bug Bug    Answer Answer    Joke Joke    Praise Praise    Rant Rant    Admin Admin   

Use Ctrl+Left/Right to switch messages, Ctrl+Up/Down to switch threads, Ctrl+Shift+Left/Right to switch pages.