<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title><![CDATA[[SecurityRatty] tag: users]]></title>
    <link>http://securityratty.com/tag/users</link>
    <description></description>
    <pubDate>Tue, 07 Oct 2008 20:00:00 +0000</pubDate>
    <generator>iRatty Engine</generator>
    <docs>http://blogs.law.harvard.edu/tech/rss</docs>
    <item>
      <title><![CDATA[40 Security Flaws Fixed In Mac OS X Security Update 2008-007]]></title>
      <link>http://securityratty.com/article/9e4b9e799dfaeee65d3d9efef1162688</link>
      <guid>http://securityratty.com/article/9e4b9e799dfaeee65d3d9efef1162688</guid>
      <description><![CDATA[Apple has released another pack of patches that cover a total of 40 documented vulnerabilities affecting the Mac OS X. The Security Update 2008-007, available for Tiger and Leopard, covers a range of...]]></description>
      <content:encoded><![CDATA[Apple has released another pack of patches that cover a total of 40 documented vulnerabilities affecting the Mac OS X. The Security Update 2008-007, available for Tiger and Leopard, covers a range of third-party components and Mac OS X flaws that could users at risk of remote code executions attacks.
The more serious vulnerabilities include:
Apache: CVE-2007-6420, [...]]]></content:encoded>
      <pubDate>Thu, 09 Oct 2008 20:56:07 +0000</pubDate>
      <category domain="http://securityratty.com/tag/mac">mac</category>
      <category domain="http://securityratty.com/tag/vulnerabilities include">vulnerabilities include</category>
      <category domain="http://securityratty.com/tag/vulnerabilities">vulnerabilities</category>
      <category domain="http://securityratty.com/tag/flaws">flaws</category>
      <category domain="http://securityratty.com/tag/third-party components">third-party components</category>
      <category domain="http://securityratty.com/tag/security">security</category>
      <category domain="http://securityratty.com/tag/range">range</category>
      <category domain="http://securityratty.com/tag/users">users</category>
      <category domain="http://securityratty.com/tag/tiger">tiger</category>
      <source url="http://cyberinsecure.com/40-security-flaws-fixed-in-mac-os-x-security-update-2008-007/">40 Security Flaws Fixed In Mac OS X Security Update 2008-007</source>
    </item>
    <item>
      <title><![CDATA[Fake YouTube pages used to spread viruses]]></title>
      <link>http://securityratty.com/article/7d25a198c2cb806ef3a9c1f78b366f73</link>
      <guid>http://securityratty.com/article/7d25a198c2cb806ef3a9c1f78b366f73</guid>
      <description><![CDATA[Savvy Internet users know that downloading unsolicited computer programs is one of the most dangerous things you can do online. It puts you at great risk for a virus or another time bomb from a...]]></description>
      <content:encoded><![CDATA[Savvy Internet users know that downloading unsolicited computer programs is one of the most dangerous things you can do online. It puts you at great risk for a virus or another time bomb from a hacker.]]></content:encoded>
      <pubDate>Thu, 09 Oct 2008 14:01:59 +0000</pubDate>
      <category domain="http://securityratty.com/tag/savvy internet users">savvy internet users</category>
      <category domain="http://securityratty.com/tag/time bomb">time bomb</category>
      <category domain="http://securityratty.com/tag/computer programs">computer programs</category>
      <category domain="http://securityratty.com/tag/hacker">hacker</category>
      <category domain="http://securityratty.com/tag/virus">virus</category>
      <category domain="http://securityratty.com/tag/risk">risk</category>
      <category domain="http://securityratty.com/tag/online">online</category>
      <category domain="http://securityratty.com/tag/dangerous">dangerous</category>
      <source url="http://digg.com/security/Fake_YouTube_pages_used_to_spread_viruses">Fake YouTube pages used to spread viruses</source>
    </item>
    <item>
      <title><![CDATA[Fake YouTube Pages Getting Popular, New Tool Released Allows Fake Pages Creation In Seconds]]></title>
      <link>http://securityratty.com/article/d448bcf7eb83e5283adf4f42f9e78631</link>
      <guid>http://securityratty.com/article/d448bcf7eb83e5283adf4f42f9e78631</guid>
      <description><![CDATA[TrendLabs report a new hacking tool that is circulating on the Internet and allows malicious users to create fake YouTube pages designed to deliver malware. The tool is detected by Trend Micro as HKTL...]]></description>
      <content:encoded><![CDATA[TrendLabs report a new hacking tool that is circulating on the Internet and allows malicious users to create fake YouTube pages designed to deliver malware. The tool is detected by Trend Micro as HKTL_FAKEYOUT, features a Spanish-language user-friendly console that a &#8220;hacker&#8221; could use to create a pair of Web pages that look eerily identical [...]]]></content:encoded>
      <pubDate>Thu, 09 Oct 2008 09:47:56 +0000</pubDate>
      <category domain="http://securityratty.com/tag/fake youtube pages">fake youtube pages</category>
      <category domain="http://securityratty.com/tag/tool">tool</category>
      <category domain="http://securityratty.com/tag/malicious users">malicious users</category>
      <category domain="http://securityratty.com/tag/user-friendly console">user-friendly console</category>
      <category domain="http://securityratty.com/tag/deliver malware">deliver malware</category>
      <category domain="http://securityratty.com/tag/trendlabs report">trendlabs report</category>
      <category domain="http://securityratty.com/tag/hktl fakeyout">hktl fakeyout</category>
      <category domain="http://securityratty.com/tag/eerily identical">eerily identical</category>
      <category domain="http://securityratty.com/tag/trend micro">trend micro</category>
      <source url="http://cyberinsecure.com/fake-youtube-pages-getting-popular-new-tool-released-allows-fake-pages-creation-in-seconds/">Fake YouTube Pages Getting Popular, New Tool Released Allows Fake Pages Creation In Seconds</source>
    </item>
    <item>
      <title><![CDATA[SmartPhones Just One More Spam Vector]]></title>
      <link>http://securityratty.com/article/3334dd3ee138602a47ef51983940dd0c</link>
      <guid>http://securityratty.com/article/3334dd3ee138602a47ef51983940dd0c</guid>
      <description><![CDATA[The Apple iPhone has another vulnerability, one that shouldnt surprise you if youve been paying attention
The news of the latest problems surfaced after Apple allegedly ignored researchers reports to...]]></description>
      <content:encoded><![CDATA[<p>The Apple iPhone has another vulnerability, one that shouldn&#8217;t surprise you if you&#8217;ve been paying attention.</p>
<p>The <a rel="nofollow" target="_blank" href="http://www.informationweek.com/news/personal_tech/iphone/showArticle.jhtml?articleID=210605451">news </a>of the latest problems surfaced after Apple allegedly ignored researchers&#8217; reports to them and the researchers decided to go public with the news :</p>
<p>In Mail, users can hover over an embedded hyperlink to see the URL, but these URLS get cut off due to the small screen. Users might see a trusted domain, but when they click it, find that the link actually resolves to an untrusted site.</p>
<p>The second vulnerability is that Mail automatically downloads images, leaving users open to malware.</p>
<p>It&#8217;s &#8220;a pretty dumb design flaw&#8221; says the <a rel="nofollow" target="_blank" href="http://aviv.raffon.net/2008/10/02/HappyNewYear.aspx">researcher </a>who discovered the problem.</p>]]></content:encoded>
      <pubDate>Thu, 09 Oct 2008 07:03:56 +0000</pubDate>
      <category domain="http://securityratty.com/tag/users">users</category>
      <category domain="http://securityratty.com/tag/researchers">researchers</category>
      <category domain="http://securityratty.com/tag/researchers reports">researchers reports</category>
      <category domain="http://securityratty.com/tag/vulnerability">vulnerability</category>
      <category domain="http://securityratty.com/tag/mail">mail</category>
      <category domain="http://securityratty.com/tag/downloads images">downloads images</category>
      <category domain="http://securityratty.com/tag/apple iphone">apple iphone</category>
      <category domain="http://securityratty.com/tag/apple allegedly">apple allegedly</category>
      <category domain="http://securityratty.com/tag/news">news</category>
      <source url="http://feeds.feedburner.com/~r/itsecurity/~3/416004668/">SmartPhones Just One More Spam Vector</source>
    </item>
    <item>
      <title><![CDATA[Microsoft to improve Vista's problematic UAC in Windows 7]]></title>
      <link>http://securityratty.com/article/390e44e4c2fdd914e79a3abbd46b23c5</link>
      <guid>http://securityratty.com/article/390e44e4c2fdd914e79a3abbd46b23c5</guid>
      <description><![CDATA[Microsoft plans to improve the much-maligned user account control (UAC) feature in the next version of its Windows client OS, acknowledging that the new security feature it built into Windows Vista...]]></description>
      <content:encoded><![CDATA[Microsoft plans to improve the much-maligned user account control (UAC) feature in the next version of its Windows client OS, acknowledging that the new security feature it built into Windows Vista has caused unnecessary problems for users.]]></content:encoded>
      <pubDate>Wed, 08 Oct 2008 20:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/security feature">security feature</category>
      <category domain="http://securityratty.com/tag/user account control">user account control</category>
      <category domain="http://securityratty.com/tag/feature">feature</category>
      <category domain="http://securityratty.com/tag/windows vista">windows vista</category>
      <category domain="http://securityratty.com/tag/improve">improve</category>
      <category domain="http://securityratty.com/tag/uac">uac</category>
      <category domain="http://securityratty.com/tag/microsoft plans">microsoft plans</category>
      <category domain="http://securityratty.com/tag/windows client">windows client</category>
      <category domain="http://securityratty.com/tag/version">version</category>
      <source url="http://www.networkworld.com/news/2008/100908-microsoft-to-improve-vistas-problematic.html?fsrc=rss-security">Microsoft to improve Vista's problematic UAC in Windows 7</source>
    </item>
    <item>
      <title><![CDATA[More on "Helping With Compliance" vs "Selling Using Compliance"]]></title>
      <link>http://securityratty.com/article/ba4460a1ff35b322ba94b7532397d8da</link>
      <guid>http://securityratty.com/article/ba4460a1ff35b322ba94b7532397d8da</guid>
      <description><![CDATA[So, here is a perfect example showing the idea I shared in my post &quot; Just A Thought on Compliance &quot;: the exact quote is &quot;its a vendors responsibility to make bearing the costs of PCI manageable

Did...]]></description>
      <content:encoded><![CDATA[So, <a href="http://www.infosecurity-magazine.com/news/081006_VendorsToSoftenBlowOfPCI.html">here</a> is a perfect example showing the idea I shared in my post "<a href="http://chuvakin.blogspot.com/2008/10/just-thought-on-compliance.html">Just A Thought on Compliance</a>":  the exact quote is "it’s a vendor’s responsibility to make bearing the  costs of PCI manageable."<br /><br />Did he say "it is vendor's role to 'sell stuff' using PCI." <span style="font-weight: bold;">God no!</span> He said that vendors will make PCI "bearable" for end-users. A big difference ...<br /><br />Yes, PCI DSS  is "a driver" for vendors to sell security tools AND "a sledgehammer" for end-users to "motivate" their bosses into releasing budget, but the reality is that PCI DSS compliance is a non-trivial challenge for many organizations, and that they need <span style="font-weight: bold;">HELP </span>more than they need "being sold to."<br /><br /><span style="font-style: italic;">And help is on its way...</span><br /><br /><span style="font-weight: bold;">Possibly related posts:</span><br /><ul><li>"<a href="http://chuvakin.blogspot.com/2008/10/just-thought-on-compliance.html">Just A Thought on Compliance</a>"</li></ul><div class="blogger-post-footer">About me: http://www.chuvakin.org</div><div class="feedflare">
<a href="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?a=gO5wM"><img src="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?i=gO5wM" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?a=TvrIM"><img src="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?i=TvrIM" border="0"></img></a> <a href="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?a=hkemM"><img src="http://feeds.feedburner.com/~f/AntonChuvakinPersonalBlog?i=hkemM" border="0"></img></a>
</div><img src="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~4/415146058" height="1" width="1"/>]]></content:encoded>
      <pubDate>Wed, 08 Oct 2008 09:37:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/pci dss">pci dss</category>
      <category domain="http://securityratty.com/tag/pci dss compliance">pci dss compliance</category>
      <category domain="http://securityratty.com/tag/pci">pci</category>
      <category domain="http://securityratty.com/tag/compliance">compliance</category>
      <category domain="http://securityratty.com/tag/vendors responsibility">vendors responsibility</category>
      <category domain="http://securityratty.com/tag/pci manageable">pci manageable</category>
      <category domain="http://securityratty.com/tag/vendors">vendors</category>
      <category domain="http://securityratty.com/tag/end-users">end-users</category>
      <category domain="http://securityratty.com/tag/exact quote">exact quote</category>
      <source url="http://feeds.feedburner.com/~r/AntonChuvakinPersonalBlog/~3/415146058/more-on-helping-with-compliance-vs.html">More on "Helping With Compliance" vs "Selling Using Compliance"</source>
    </item>
    <item>
      <title><![CDATA[Two Years of Broken Crypto: Debian's Dress Rehearsal for a Global PKI Compromise]]></title>
      <link>http://securityratty.com/article/432d2495bf0e8b9c969c9d8efd4895eb</link>
      <guid>http://securityratty.com/article/432d2495bf0e8b9c969c9d8efd4895eb</guid>
      <description><![CDATA[A patch to the OpenSSL package maintained by Debian GNU/Linux (an operating system composed of free and open source software that can be used as a desktop or server OS) submitted in 2006 weakened its...]]></description>
      <content:encoded><![CDATA[A patch to the OpenSSL package maintained by Debian GNU/Linux (an operating system composed of free and open source software that can be used as a desktop or server OS) submitted in 2006 weakened its pseudo-random number generator (PRNG), a critical component for secure key generation. Unnoticed for two years, the weak PRNG created a crypto-implementation nightmare with wide-ranging consequences that are difficult to repair. Putting both servers and users at risk, this vulnerability affected OpenSSH, Apache (mod_ssl), the onion router (TOR), OpenVPN, and other applications. In this article, I'll examine the issue and its consequences.<br style="clear: both;"/>
  <img alt="" style="border: 0; height:1px; width:1px;" border="0" src="http://www.pheedo.com/img.phdo?i=82b45bc2d7e3da625459c51c5bb78bca" height="1" width="1"/>
<img src="http://www.pheedo.com/feeds/tracker.php?i=82b45bc2d7e3da625459c51c5bb78bca" style="display: none;" border="0" height="1" width="1" alt=""/>]]></content:encoded>
      <pubDate>Wed, 08 Oct 2008 00:42:07 +0000</pubDate>
      <category domain="http://securityratty.com/tag/prng">prng</category>
      <category domain="http://securityratty.com/tag/secure key generation">secure key generation</category>
      <category domain="http://securityratty.com/tag/weak prng">weak prng</category>
      <category domain="http://securityratty.com/tag/critical component">critical component</category>
      <category domain="http://securityratty.com/tag/openssl package">openssl package</category>
      <category domain="http://securityratty.com/tag/debian gnulinux">debian gnulinux</category>
      <category domain="http://securityratty.com/tag/onion router">onion router</category>
      <category domain="http://securityratty.com/tag/consequences">consequences</category>
      <category domain="http://securityratty.com/tag/source software">source software</category>
      <source url="http://www.pheedo.com/click.phdo?i=82b45bc2d7e3da625459c51c5bb78bca">Two Years of Broken Crypto: Debian's Dress Rehearsal for a Global PKI Compromise</source>
    </item>
    <item>
      <title><![CDATA[Data Retention and Privacy in Electronic Communications]]></title>
      <link>http://securityratty.com/article/8c25f32527ed66213f5716af1ebfb28b</link>
      <guid>http://securityratty.com/article/8c25f32527ed66213f5716af1ebfb28b</guid>
      <description><![CDATA[The retention of communication data by network providers, often mandated by legislation, raises social and technical security concerns. A generic model combining technical, procedural, and legal...]]></description>
      <content:encoded><![CDATA[The retention of communication data by network providers, often mandated by legislation, raises social and technical security concerns. A generic model combining technical, procedural, and legal controls can help secure retained data and minimize privacy threats against users.<br style="clear: both;"/>
  <img alt="" style="border: 0; height:1px; width:1px;" border="0" src="http://www.pheedo.com/img.phdo?i=2decd6847ba49454704c462f5e3e7364" height="1" width="1"/>
<img src="http://www.pheedo.com/feeds/tracker.php?i=2decd6847ba49454704c462f5e3e7364" style="display: none;" border="0" height="1" width="1" alt=""/>]]></content:encoded>
      <pubDate>Wed, 08 Oct 2008 00:42:06 +0000</pubDate>
      <category domain="http://securityratty.com/tag/data">data</category>
      <category domain="http://securityratty.com/tag/technical">technical</category>
      <category domain="http://securityratty.com/tag/technical security concerns">technical security concerns</category>
      <category domain="http://securityratty.com/tag/communication data">communication data</category>
      <category domain="http://securityratty.com/tag/legal controls">legal controls</category>
      <category domain="http://securityratty.com/tag/privacy threats">privacy threats</category>
      <category domain="http://securityratty.com/tag/network providers">network providers</category>
      <category domain="http://securityratty.com/tag/raises social">raises social</category>
      <category domain="http://securityratty.com/tag/retention">retention</category>
      <source url="http://www.pheedo.com/click.phdo?i=2decd6847ba49454704c462f5e3e7364">Data Retention and Privacy in Electronic Communications</source>
    </item>
    <item>
      <title><![CDATA['Clickjackers' could hijack Webcams, microphones, Adobe warns]]></title>
      <link>http://securityratty.com/article/f35815fb20c2d92d67847e01c5b2181a</link>
      <guid>http://securityratty.com/article/f35815fb20c2d92d67847e01c5b2181a</guid>
      <description><![CDATA[Adobe Systems is warning users that hackers could use clickjacking attack tactics to secretly turn on a computer's microphone and Web...]]></description>
      <content:encoded><![CDATA[Adobe Systems is warning users that hackers could use clickjacking attack tactics to secretly turn on a computer's microphone and Web camera.<br style="clear: both;"/>
    <a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v3:4b6a3ef8e35a088ce8806ee43fbf8a97:QEvY6HHfcQvWGSYBeSV58UTzNgNQcAGqMoF1wCYP7Bh6%2BnuaH7EeediR0U6Xt6cPlyGe9ZjA77Hj'><img border='0' title='Add to digg' alt='Add to digg' src='http://www.pheedo.com/images/mm/digg.gif'/></a>
    <a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v3:9605c4c5cfe590c533ac0eee1deb5bee:KwjIVCZiU2Jxv0zOWYtX3F1%2FxrpjHk6T2Gwqn%2Bl9%2FzpjM4QvElNkYdKIsXdGrbPgeeMe%2Bb68VhbV7A%3D%3D'><img border='0' title='Add to StumbleUpon' alt='Add to StumbleUpon' src='http://www.pheedo.com/images/mm/stumbleit.gif'/></a>
    <a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v3:10afcc4ab921abb353982c76c14b5df7:EF1CDvtIuX8jdypXhMhZj%2FouCnoIxfVDEzDHTK1arrZ1RNTHvGAAVLk%2Bsb2PEYNaHOCVzbflOXks8Q%3D%3D'><img border='0' title='Add to Twitter' alt='Add to Twitter' src='http://www.pheedo.com/images/mm/twitter.png'/></a>
    <a style='font-size: 10px; color: maroon;' href='http://www.pheedo.com/hostedMorselClick.php?hfmm=v3:652bb67b00d9fc3c2c3be1d527edcc26:sSSbd2XKjdiSm7%2FXgubLNBq8cZy46qwPxXi2gzogk5c0js4Fxj2ZzNtqResWdPAdv2J1prwuWHxWwQ%3D%3D'><img border='0' title='Add to Slashdot' alt='Add to Slashdot' src='http://www.pheedo.com/images/mm/slashdot.png'/></a>
<br style="clear: both;"/>  <img alt="" style="border: 0; height:1px; width:1px;" border="0" src="http://www.pheedo.com/img.phdo?i=9230864996175b7acbdd4b4456a04f29" height="1" width="1"/>
<img src="http://www.pheedo.com/feeds/tracker.php?i=9230864996175b7acbdd4b4456a04f29" style="display: none;" border="0" height="1" width="1" alt=""/>]]></content:encoded>
      <pubDate>Wed, 08 Oct 2008 00:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/web camera">web camera</category>
      <category domain="http://securityratty.com/tag/adobe systems">adobe systems</category>
      <category domain="http://securityratty.com/tag/attack tactics">attack tactics</category>
      <category domain="http://securityratty.com/tag/microphone">microphone</category>
      <category domain="http://securityratty.com/tag/users">users</category>
      <category domain="http://securityratty.com/tag/computer">computer</category>
      <category domain="http://securityratty.com/tag/secretly">secretly</category>
      <category domain="http://securityratty.com/tag/hackers">hackers</category>
      <source url="http://feeds.computerworld.com/click.phdo?i=9230864996175b7acbdd4b4456a04f29">'Clickjackers' could hijack Webcams, microphones, Adobe warns</source>
    </item>
    <item>
      <title><![CDATA[Clickjackers could hijack Webcams, microphones, Adobe warns]]></title>
      <link>http://securityratty.com/article/540d1ce57212ad11c309ee9ea0468a55</link>
      <guid>http://securityratty.com/article/540d1ce57212ad11c309ee9ea0468a55</guid>
      <description><![CDATA[Adobe Systems warned users Tuesday that hackers could use recently-reported &quot;clickjacking&quot; attack tactics to secretly turn on a computer's microphone and Web...]]></description>
      <content:encoded><![CDATA[Adobe Systems warned users Tuesday that hackers could use recently-reported "clickjacking" attack tactics to secretly turn on a computer's microphone and Web camera.]]></content:encoded>
      <pubDate>Tue, 07 Oct 2008 20:00:00 +0000</pubDate>
      <category domain="http://securityratty.com/tag/web camera">web camera</category>
      <category domain="http://securityratty.com/tag/users tuesday">users tuesday</category>
      <category domain="http://securityratty.com/tag/adobe systems">adobe systems</category>
      <category domain="http://securityratty.com/tag/attack tactics">attack tactics</category>
      <category domain="http://securityratty.com/tag/microphone">microphone</category>
      <category domain="http://securityratty.com/tag/computer">computer</category>
      <category domain="http://securityratty.com/tag/secretly">secretly</category>
      <category domain="http://securityratty.com/tag/hackers">hackers</category>
      <source url="http://www.networkworld.com/news/2008/100808-clickjackers-could-hijack-webcams-microphones.html?fsrc=rss-security">Clickjackers could hijack Webcams, microphones, Adobe warns</source>
    </item>
  </channel>
</rss>
