Defeating the Same Origin Policy part 2 25 Mar 2008 03:52 GMTIn my first post in this series, I discussed the Same Origin Policy and how it protects us from some very serious attacks, the dangers of domain name based trust, and how to attack implementations of the Same Origin Policy within the Java Virtual Machine (JVM). In order to demonstrate...
Source: ZDNet What Microsoft can teach Apple about software updates 24 Mar 2008 22:55 GMTLast summer, I looked at Apple's announced plans for its Safari web browser and wondered out loud, Is Steve Jobs planning a hostile takeover of the Windows desktop? Apple's decision last week to begin aggressively pushing Safari to any Windows user running iTunes (in other words, anyone with an iPod or an...
Source: ZDNet Security: Lintel vs Wintel 24 Mar 2008 12:15 GMTIn the PC community "security" just means defending against attacks aimed at destroying or misusing all or part of a computer system. In that context most of the complexities associated with trying to decide whether wintel or lintel will expose you to less security risk arise from the absense of...
Source: ZDNet Microsoft confirms Word attacks 24 Mar 2008 11:47 GMTMicrosoft has confirmed reports of vulnerability in Word that allows an attacker to exploit a system via the Microsoft Jet Database Engine, which shares data with Access, Visual Basic and third party applications. Microsoft in its advisory said the potential for attack is "very limited." Reports of...
Source: ZDNet News to know: Ubuntu; Microsoft's Albany; Google; Safari flap 24 Mar 2008 09:14 GMTNotable headlines: Adrian Kingsley-Hughes: First look: Hardy Heron Beta. Gallery: Installation. Screen shots: OS tour Mary Jo Foley: âAlbany': New Microsoft âhome office' in the works? Michael Krigsman: Is IT becoming extinct? Garett Rogers: New Google Mobile feature...
Source: ZDNet N.J. County Clerks Call for Probe of Primary E-Voting 24 Mar 2008 04:57 GMTIn the wake of discrepancies in e-voting results on Sequoia machines during New Jersey's Feb. 5 primary election, an association of county clerks is asking the state's attorney general to launch an investigation.

Source: Computerworld Microsoft sounds bug alarm, confirms Windows-Word attacks 22 Mar 2008 13:00 GMTAfter several weeks' worth of discoveries and warnings from third-party researchers, Microsoft on Friday acknowledged a critical vulnerability affecting users of Word running on Windows 2000, XP and Server 2003 SP1.

Source: Computerworld Mozilla CEO accuses Apple of malware distribution practices 22 Mar 2008 03:42 GMTYesterday Apple pushed out a Safari 3.1 update via Software Update on Windows. In a blog post, Mozilla CEO John Lilly describes why Mozilla feels Apple's decision is wrong -- and how moves like it can endanger the security of the Web. From John Lilly's blog: What Apple...
Source: ZDNet Red Hat takes the open source security challenge 21 Mar 2008 13:35 GMTOne big hole for open source lies in security. It's not a real hole. It's a meta-hole. But we still view it as a hole, so it's a hole. That hole opened up again in Australia this week, where a "loud minority" got personal...
Source: ZDNet