Icann opens up to the world
Wednesday, September 30th, 2009Loosening US grip on the internet.
Loosening US grip on the internet.
Firefox feature looks to foil XSS attacks
As we mentioned earlier we’ve been working for the past few months on turning the Content Security Policy specification into working Firefox code. (You’ll remember that CSP is a framework to protect websites from XSS and related attacks). We are happy to report that the work is nearly finished, and we have some preview builds available for you to try out.
We’re thrilled to have received so much great feedback from other browser vendors, web site administrators, and security researchers and we’re very proud of the design that has come out of that discussion. We would like to encourage any server administrators or web app security researchers who are interested in this project to grab a preview Firefox build and help us test the new features. Please be aware that there are still a few rough spots. The implementation is not quite complete so you may notice some small gaps between the preview builds and the spec. Most notably, HTTP redirects are not fully handled by CSP (but will be soon).
I posted a demo page where you can see the basic features of CSP in action, though we’re all much more excited to see all the tests and proof points our friends in the security research community are sure to turn up. Please grab a preview build and start testing!
Brandon Sterne
Security Program Manager
Currently, the H1N1 virus is running rampant (46,000+ cases) throughout the nation and the “official” flu season doesn’t start until Oct 4th. Like all viruses, H1N1 is made up of a DNA sequence, or code. The most amazing part is that it only takes about 3.2 Kbytes of data to code itself. A worm like Conficker takes over 112 Kbytes! Always striving for ultimate efficiency, it looks like Mother Nature…
![]() Voice of America |
Clinton thrilled to be president ….of the UN Security Council
AFP … who last year made an abortive White House bid, said here Wednesday she enjoyed her role as president…of the UN Security Council. … I kind of like being a President (of UN Security Council … Sexual violence threatens national security, Hillary Clinton says UN Security Council Resolution Outlines Significant Steps to … |
![]() AFP |
US: Iraq budget shortfall poses security challenge
The Associated Press Iraq's security plans have been derailed because of the drop in oil prices, hampering efforts to buy ships, planes and weapons and slowing down the … Iraq budget is 'challenge' for security forces: US Low Oil Prices Threaten Iraq's Security US: Iraq budget constraints security challenge |
![]() TrustedReviews |
Microsoft explores free option with Security Essentials
guardian.co.uk Amy Barzdukas has one of the computer industry's more thankless tasks: she's general manager for Internet Explorer and consumer security at Microsoft. … Microsoft launches free security One thumb up for MS Security Essentials in early tests Microsoft Covers the Basics With Security Essentials |
![]() Voice of America |
UN Security Council Concerned About Guinea
Voice of America The UN Security Council has expressed its concern about the killing of scores of protesters in the West African nation of Guinea on … UN Security Council condemns Guinea bloodshed UN Security Council condemns violence in Guinea UN condemns violence in Guinea |
In the first half of 2009, 77 percent of websites with malicious code were legitimate sites that had been compromised, according to a new report from Websense.
![]() |
| Comments On Blogs Likely To Be Spam |
The high percentage was maintained over the past six months due in part to widespread attacks including Gumblar, Beladen, and Nine Ball which aimed to compromise trusted and known properties with massive injection campaigns.
Web 2.0 sites allowing user-generated content are a top target for cybercriminals and spammers. The report found that 95 percent of user-generated comments to blogs, chat rooms and message boards are spam or malicious.
“The last six months have shown that malicious hackers and fraudsters go where the people are on the Web — and have heightened their attacks on popular Web 2.0 sites and continued to compromise established, trusted Web sites in the hope of infecting unsuspecting users,” said Dan Hubbard, Chief Technology Officer, Websense.
“From malicious Twitter spam campaigns and blog comment spam to the massive injection attacks, those perpetrating fraud are exploiting the inherent trust users have of known Web properties and other users.”
In addition, 69 percent of Web pages with content classified as objectionable also had at least one malicious link. This is becoming more widespread, as 78 percent of new web pages discovered in the first half of 2009 with objectionable content had at least one malicious link.
The convergence of blended web and email threats continues to increase. The report found that 85.6 percent of all unwanted emails in circulation during this period contained links to spam sites or malicious websites.
New experiment demonstrates what we already knew: That’s because people tend to view their immediate emotions, such as their perceptions of threats or risks, as more intense and important than their previous emotions. In one part of the study focusing on terrorist threats, using materials adapted from the U.S. Department of Homeland Security, Van Boven and his research colleagues presented…
![]() Al-Arabiya |
US: Iraq budget shortfall poses security challenge
The Associated Press Iraq's security plans have been derailed because of the drop in oil prices, hampering efforts to buy ships, planes and weapons and slowing down the … Iraq budget is 'challenge' for security forces: US general US: Iraq budget constraints security challenge |
Google searches on terms related to its new collaboration and communications platform, Google Wave, are leading to a rogue anti-virus programs, according to the Websense Security Labs. Users seeking information on how to sign up for Wave, which currently is by invite-only, have been victimized by manipulated search results that lead to sites designed to trick victims into paying for a security solution that doesn’t work. Searches for Microsoft’s new Security Essentials consumer anti-virus product also have led to “poisoned” results. — CAM
![]() New Zealand Herald |
UN demands end of sexual violence as tactic of war
AFP UNITED NATIONS — With US Secretary of State Hillary Clinton in the chair, the UN Security Council on Wednesday unanimously adopted a resolution to halt the … UN Security Council demands end of sexual violence in armed conflict Clinton to chair Security Council session on sexual violence Hillary Clinton likes being president for a day |
![]() Daily Star – Lebanon |
Protests start ahead of IMF/WB meetings in Istanbul
Xinhua Turkish authorities have imposed tight security measures in its largest city of Istanbul. Turkish police officer Kartal Ordubakan said more than 300 … Beware of IMF traffic in Istanbul until next Thursday Turkey tightens security in Istanbul for IMF/World Bank meetings |
![]() Techtree.com |
How essential will Microsoft Security Essentials be to you?
guardian.co.uk We have an interview with Amy Barzdukas, head of Internet Explorer and Microsoft's consumer security, in this week's Technology section (print! It's fun!). … Microsoft releases free Security Essentials download Microsoft launches free security Microsoft Security Essentials shakes up consumer antivirus |
|
Prison officers upgraded on criminal security, control
AngolaPress Luanda – At least 182 prison officers concluded on Wednesday in Luanda, training for specialists of criminal security, re-education, criminal control and … |
![]() BBC News |
£2m spent on Parliament security
The Press Association Nearly £2 million is being spent on improving security at the Scottish Parliament, msps have heard. The measures include turnstiles controlled by swipe … £2m for Holyrood security |
|
Security guards grab cash back
Bromley Times A SECURITY guard chased thieves down the street who tried to escape with bags of cash. On Saturday at 1.05am in the High Street, Penge, two black men … PENGE: Plucky security guard fends off gang ambush |