Showing posts with label security. Show all posts
Showing posts with label security. Show all posts

Monday, June 22, 2009

3.0 is here, but where's the free security update for iPod touch 2.x?

TUAW reader Jim Carroll is worried: "It is crunch time for your site," he warned ominously in an email yesterday.
Jim is worried that security updates made available via the iPhone OS 3.0 updates last week will only be available to iPod touch users through the obligatory $10 upgrade. "Please use your power as an Apple site to raise the issue." Please, Jim. We're blushing.
"As a long time computer user I am unaware of a similar incident where a company would charge for security updates," he writes. Companies charge money for updates all the time -- operating systems and anti-virus software take time and energy to make, and companies want to get their investment back. Apple has been kind with free updates to Safari, but only because they gain revenue from it via the Search bar.
Apple has always charged iPod touch users for major updates, of course, but security updates have most often come free. 1.0.1, 1.1.2, 1.1.3, 1.1.5, 2.1, and 2.2 all included security fixes, but were free to iPod touch users. (The latter two cases were free for those who bought the 2.0 update.)
1.1.5 is an interesting case. It was released a few days after the 2.0 update, and included security updates that were wrapped into the 2.0 update.
My advice? Have patience. This coming week or next, I have confidence we'll see an update for 2.x (2.2.2 perhaps?) that leaves out the new features, but includes the same security updates found in 3.0 at about $9.95 less.
We're also beginning to hear whispers of a 3.0.1 update for the device to help resolve WiFi issues in the new release; a German iPod user reports being told by an AppleCare representative that an update is expected shortly. Take that with the appropriately sized grain of salt.

Inside iPhone 3.0: Fix too-strict passcode lock settings for Exchange users

If your iPhone was connected to an Exchange server for email, contact or calendar synchronization prior to your upgrade to the 3.0 software, you may have run into the same problem that was bugging me for a day or so: the timeout on the passcode lock gets set to "Immediate," forcing you to enter the code almost every time you pick up the phone. Secure, sure, but very annoying. Going to the usual settings location to adjust the timeout shows no choices other than the insta-lock; what to do?
A thread on the Apple discussions boards points to the answer. Since the ActiveSync link to the Exchange server controls some security policies on the phone, you need to refresh those controls; the easiest way to do that, short of deleting and recreating the Exchange account, is to turn off all three sync modes and the Push setting. Once that's done, you can go back to the passcode lock screen and disable the lock or adjust the timeout. Put your sync settings back the way they were and your changes to the passcode config should remain in place.
While this is an annoying quirk, it's not all gripes and grimaces in the Exchange support department. At long last, users of Exchange calendars can send meeting invitations (hallelujah!); Exchange 2007 users can even view the reply status of attendees. Users can specify additional mail folders for sync, and Exchange 2007 users can search server-side mail from their devices.
For a full rundown on the enterprise-friendly features of iPhone OS 3.0, check out the Enterprise Integration guide via Apple's enterprise features page.

Sunday, February 1, 2009

Adobe CS4 crack app has variant of iServices trojan

The folks over at Intego let the world know about a new trojan making the rounds along with copies of an application designed to crack Adobe Creative Suite 4. They consider the risk "serious."
If you don't download software using peer-to-peer tools like BitTorrent, then you're perfectly safe. You can stop reading this story, if you like. If you're one of the 5,000 people who recently downloaded and installed the serial crack, then you have a bad day ahead of you.
The malware, after asking for your administrator password, installs an executable with a random name in /var/tmp, a folder that isn't deleted when the computer restarts.
The randomly-named program will install itself in /usr/bin/DivX, create a startup item in /System/Library/StartupItems/DivX, and if it has root privileges, save a hash of your password in the file /var/root/.DivX.
The software then listens on a random TCP port and awaits instructions from its evil overlords. With an infected computer's root password, those in control of the software will be able to execute commands on the infected computer, including deleting files and performing malicious network tasks.
Late last week, pirated copies of iWork '09 were infected with similar malware.
Intego VirusBarrier X4 and X5, as you might imagine, protect you against the Trojan. Either looking for (and removing) the files mentioned above or using a virus removal utility is recommended.
Also recommended: Not downloading pirated software (and their associated tools) on peer-to-peer networks. If you do choose to get your software that way, you have nobody to blame but yourself if your system gets infected.

Saturday, November 15, 2008

Firefox 3.0.4 patches security flaws [ MacOS ]

If your needle doesn't swing towards the compass when it comes to browsing the Web, there's an update out for you too: Firefox 3.0.4 dropped yesterday, patching four critical security vulnerabilities and several less-serious holes while improving stability and addressing other bugs. Localization is coming along too: the new version features official builds for Icelandic and Thai, and beta takes for the Bulgarian, Estonian, Latvian, Occitan, Welsh and (tre bona!) Esperanto.
You can get the 17.2MB download from Mozilla or via the automatic Software Update checker in Firefox.

Wednesday, August 13, 2008

Apple pulls out of proposed Black Hat talk

Though I'm far too dumb to understand what they're talking about, I like the Black Hat hacker guys. Most of the Internet is all "New Vegas" now; all (supposedly) family friendly and glamorous and glitzy. But those guys are back on Fremont Street, gambling with everything they've got and shoulder to shoulder with the dregs of society.

Unfortunately, Apple's marketing department doesn't share my feelings. Computerworld says they've put the kibosh on a speaking engagement they were supposed to have at the conference next week in Sin City. In fact, they can't even say they were asked to pass -- everyone involved in organizing the panel, which was set up early last month and "abruptly canceled" late last month, spoke on condition of anonymity.

Which is a shame -- organizers of the conference say the panel was supposed to be all about how serious security is at Apple and how they're committed to keeping users secure. And it wasn't even supposed to be a Q&A, which is why the organizers thought it would easily be approved by marketing.

That, however, wasn't the case -- while the panel wasn't yet approved by the conference folks, the request to have the panel was pulled. We're sure the Black Hat guys will still have fun (it is Vegas, after all), but it's a shame we couldn't get that look inside Apple's security team.

Friday, August 8, 2008

Apple Security update 2008-005 released

Apple has just released a new security update for client and server users of Mac OS X 10.4 (Tiger) and 10.5 (Leopard). This Security update 2008-005 is "recommended for all users and improves the security of Mac OS X," and includes fixes for a dozen or so features in Mac OS X.

This update fixes a QuickLook bug where loading a malicious Microsoft Office file could lead to "arbitrary code execution." Doesn't sound too good to me! It also fixes a DNS vulnerability that has been highly discussed over the past week (and which many other vendors have already patched).

You can download this update by opening Software Update (Apple menu > Software Update). You can also find more information on what this update fixes by looking at Apple's support note.

Consumer Reports pans Safari's lack of phishing protection [ MacOS ]

Consumer Reports, in its annual internet security survey, recommended that Mac users avoid Safari because of its lack of phishing protection. Instead, they recommend users install Firefox 3 or Opera 9.5 as their default browsers, since both will warn users before displaying the contents of sites known to be source of scams and personal information theft.

Jeff Fox, technology editor at Consumer Reports, noted that "e-mail is the weak vector on the Mac," meaning that most successful phishing attacks on Mac users arrive via email.

"Windows users are used to being paranoid about not clicking [links in phishing emails]," he said. "Mac users aren't, even though they say, 'Antivirus software, who needs it?'"

As we've mentioned before, 1Password does a great job of adding phishing protection to Safari. Also, always be extra-wary of clicking links in emails from people you don't know.

Protect your data with FileVault [ MacOS ]

If you use a notebook Mac, then the risks are higher for getting your computer stolen. However, Apple has included a tool to protect your entire home folder (documents, pictures, movies, etc.) right within OS X. FileVault protects your computer against stolen data by encrypting/decrypting your home folder each time you login and logout.

To use FileVault, you must first set a Master Password. This password is a fail-safe if you forget your user login info. However, if you lose both your user login info and the master password, you will not be able to decrypt your home folder and your data (if not backed up in unencrypted form) will be lost forever. To set the master password, navigate to System Preferences > Security > FileVault > Set Master Password.

Once you have the master password set, you will be able to turn on FileVault and begin protecting your data. Click the "Turn on FileVault" button in the FileVault section of the Security preference pane. You will be asked for your master password, and a disclaimer will be displayed explaining the process. Please note that you will not be able to login to your Mac via SMB (Windows file sharing) after turning on FileVault.

FileVault provides a high level of data security, but some applications have a history of incompatibility with the feature; it's also very important that you have a secure and solid backup strategy if you choose to use FileVault. For best results with Time Machine, make sure that your FV home folder is upgraded to the Leopard image format (if you were using FV under Tiger, you may have to turn it off and back on to convert your home folder) and log out of your account periodically to allow backups to run.

Thursday, July 31, 2008

How to use Ad-Aware

One of the most popular spyware-combat tools on the market is the free Ad-Aware, but don't let its cute baby-blue interface and price tag fool you: It's a powerful program capable of dealing with many of the newest, most serious threats. Here are a few basic steps for using the program effectively.

Step 1: Stay up to date

Like most antispyware utilities, Ad-Aware works by comparing your PC's contents with a database of known malware. Spyware manufacturers are always trying to stay one step ahead of the programs designed to foil them by routinely unleashing new nasties on the Web. However, antispyware developers are just as savvy, and they regularly update their databases with the newest spyware definitions. Before you scan your PC for problems, you should make sure your copy of Ad-Aware is equipped with the most up-to-date database. From the main interface, you can click the globe icon in the upper-right corner, or you can simply click the link that says "Check for updates now". You'll have to connect to the publisher's server and hit OK a couple of times, but the process goes quickly.

You can also configure Ad-Aware to regularly prompt you to update its spyware definitions. To do so, click the gear-shape button at the top of the main window. The General Settings tab contains a Definitions section, where you can enter the maximum number of days that should pass before the program asks you to update it. We'd suggest updating your spyware definitions every couple of days--it's better to be safe than sorry.

Step 2: Start the spyware scan

Ad-Aware offers two main scanning options: a quicker smart scan and a more thorough full-system scan. If you've never used the program before or suspect your PC is jam-packed with malevolent software, you should opt for the deep-scan mode. Click the Scan Now button on the program's left side, mark the box that reads "Perform full system scan", then hit the Next icon. The scanning process will probably take a while--especially if you keep a lot of files on your computer--so you might want to step away for a breath of fresh air. The next time you use the program, you can safely go with the faster smart scan option, which is still very effective.

Step 3: Remove the intruders

Once Ad-Aware has finished scanning your computer for spyware, a summary screen appears, which shows you the amount and type of threats the program detected. Ad-Aware categorizes its findings as either critical or negligible; clearly, you should focus your attention on the Critical Objects tab. There, you'll see what kinds of nefarious modules and Registry keys Ad-Aware found on your machine. The app will tell you the names of all the malicious components and what kinds of spyware they are, as well as show you the physical location of each threat on your PC. If you right-click the check box next to any entry on the list, a rather lengthy menu will pop up. Scroll about halfway down and choose the option "Select all objects". Click the Next icon, then hit OK in the pop-up box. The amount of time it takes Ad-Aware to complete the removal process depends on how much malware is on your machine, but the app will notify you when it has finished cleaning out your computer.

Step 4: Optimize scan times

As noted above, Ad-Aware's scan times can be quite lengthy if you have a large hard drive with many files. However, you can take a couple of steps to make future scans more efficient. The program searches for cookies and categorizes them as Critical Objects, even though they don't pose a real threat to your security. You can decrease scan times by configuring the program to ignore cookies. From the Scanning Results screen, find the cookies (near the bottom of the list) and mark the check boxes next to their names. Right-click one of the selected cookies, then scroll down the context menu and choose Add Selected to Ignore List. The next time you scan your machine, Ad-Aware won't include those cookies in its results.

Similarly, you can have the program ignore certain drives on your computer, such as your CD or floppy drive. When selecting a scan mode, check the radio button labeled "Use custom scanning options", then click the Customize link. Under the Drives, Folders & Files heading, click the link next to the Windows folder icon labeled "Select drives & folders to scan". From there, you can choose which drives to scan or ignore by simply checking and unchecking boxes.

How to use Ad-Aware

One of the most popular spyware-combat tools on the market is the free Ad-Aware, but don't let its cute baby-blue interface and price tag fool you: It's a powerful program capable of dealing with many of the newest, most serious threats. Here are a few basic steps for using the program effectively.

Step 1: Stay up to date

Like most antispyware utilities, Ad-Aware works by comparing your PC's contents with a database of known malware. Spyware manufacturers are always trying to stay one step ahead of the programs designed to foil them by routinely unleashing new nasties on the Web. However, antispyware developers are just as savvy, and they regularly update their databases with the newest spyware definitions. Before you scan your PC for problems, you should make sure your copy of Ad-Aware is equipped with the most up-to-date database. From the main interface, you can click the globe icon in the upper-right corner, or you can simply click the link that says "Check for updates now". You'll have to connect to the publisher's server and hit OK a couple of times, but the process goes quickly.

You can also configure Ad-Aware to regularly prompt you to update its spyware definitions. To do so, click the gear-shape button at the top of the main window. The General Settings tab contains a Definitions section, where you can enter the maximum number of days that should pass before the program asks you to update it. We'd suggest updating your spyware definitions every couple of days--it's better to be safe than sorry.

Step 2: Start the spyware scan

Ad-Aware offers two main scanning options: a quicker smart scan and a more thorough full-system scan. If you've never used the program before or suspect your PC is jam-packed with malevolent software, you should opt for the deep-scan mode. Click the Scan Now button on the program's left side, mark the box that reads "Perform full system scan", then hit the Next icon. The scanning process will probably take a while--especially if you keep a lot of files on your computer--so you might want to step away for a breath of fresh air. The next time you use the program, you can safely go with the faster smart scan option, which is still very effective.

Step 3: Remove the intruders

Once Ad-Aware has finished scanning your computer for spyware, a summary screen appears, which shows you the amount and type of threats the program detected. Ad-Aware categorizes its findings as either critical or negligible; clearly, you should focus your attention on the Critical Objects tab. There, you'll see what kinds of nefarious modules and Registry keys Ad-Aware found on your machine. The app will tell you the names of all the malicious components and what kinds of spyware they are, as well as show you the physical location of each threat on your PC. If you right-click the check box next to any entry on the list, a rather lengthy menu will pop up. Scroll about halfway down and choose the option "Select all objects". Click the Next icon, then hit OK in the pop-up box. The amount of time it takes Ad-Aware to complete the removal process depends on how much malware is on your machine, but the app will notify you when it has finished cleaning out your computer.

Step 4: Optimize scan times

As noted above, Ad-Aware's scan times can be quite lengthy if you have a large hard drive with many files. However, you can take a couple of steps to make future scans more efficient. The program searches for cookies and categorizes them as Critical Objects, even though they don't pose a real threat to your security. You can decrease scan times by configuring the program to ignore cookies. From the Scanning Results screen, find the cookies (near the bottom of the list) and mark the check boxes next to their names. Right-click one of the selected cookies, then scroll down the context menu and choose Add Selected to Ignore List. The next time you scan your machine, Ad-Aware won't include those cookies in its results.

Similarly, you can have the program ignore certain drives on your computer, such as your CD or floppy drive. When selecting a scan mode, check the radio button labeled "Use custom scanning options", then click the Customize link. Under the Drives, Folders & Files heading, click the link next to the Windows folder icon labeled "Select drives & folders to scan". From there, you can choose which drives to scan or ignore by simply checking and unchecking boxes.