Última actualització: 01/02/2005; 18:02:52
Weblog d'en Xavi Caballé Weblog d'en Xavi Caballé
Pàgina personal de Xavier Caballé.
«Sometimes we're strong, sometimes we're wrong, sometimes we cry» (Van Morrison)

diumenge, 30 / gener / 2005


[Los Angeles Times] No More Internet for Them (cal registre; dades a bugmenot.com). Un dels perills que va indicar en Bruce Schneier quan el vam entrevistar el passat novembre era el risc que la gent abandonés l'ús d'Internet en cas que comencessin a perdre diners. Ells es referia a això tot parlant del phishing. En la notícia de «Los Angeles Times» es fa ressò d'una empresa que ha decidit deixar d'utilitzar Internet doncs no els era una eina útil, com conseqüència del correu brossa, els programes espies i la inundació de virus.
Sick of spam clogging his in-box and spyware and viruses crashing his system, Seemayer yanked out his high-speed connection

«I'm not going to pay for something that I can't use», he said

(...)

Seemayer's machine, for instance, got so jammed with spam that he stopped checking e-mail. When he surfed the Web, pop-up ads from a piece of spyware he couldn't wipe out spewed sexually explicit images and used so much computing power that the PC would just stop.
 
I això, segons l'article, no és pas un fet aïllat:
A small but growing number of frustrated computer owners are coming to the same conclusion. They're giving up or cutting back their use of the Internet, especially at home, where no corporate tech support team will ride to their rescue.

Instead of making life easier — the essential promise of technologies since the steam engine — the home PC of late has made some users feel stupid, endangered or just hassled beyond reason.
 
In a recent survey, 31% of online shoppers said they were buying less than before because of security issues.

(...)

«If, as an industry, we're not able to provide a safe, reliable computing environment, we do think consumers will get increasingly frustrated,» said Michael George, general manager of Dell's U.S. consumer business. "We're concerned, and we want to get to a position where we play an instrumental role in fixing the problem."
 


23:02 (# Enllaç permanent) | Comentaris: | Trackback:


http://rfidanalysis.org/, estudi sobre el tag DST de Texas Instuments, utilitzat a determinades claus de cotxe i baades en la tecnologia RFID, i les seves vulnerabilitats de seguretat. ExxonMobile SpeedPass
The Texas Instruments DST tag is a cryptographically enabled RFID transponder used in several wide-scale systems including vehicle imobilizers and the ExxonMobil SpeedPass system. This page serves as an overview of our successful attacks on DST enabled systems. A preliminary version of the full academic paper describing our attacks in detail is also available.
 
Sembla que RFDI no és un bon pany pel cotxe.


22:00 (# Enllaç permanent) | Comentaris: | Trackback:


El president d'Ucraïna, Viktor Yuschenko, manté una mena de weblog, amb font RSS.

Actualització: Via fernand0, no és ben bé un weblog sinó una simple web que recull de les activitats del president.


14:06 (# Enllaç permanent) | Comentaris: | Trackback:


[Vnunet] Linux security is a 'myth', claims Microsoft. Un dels principals directius de Microsoft UK diu que la seguretat de Linux és un mite i que no està pas preparat per a suportar el nucli de les operacions informàtiques (mission-critical computing).
Nick McGrath, head of platform strategy for Microsoft in the UK, said that the myths surrounding the open source operating system are rapidly being exploded, and that customers are dismissing Linux as too immature to cope with mission-critical computing.

«The biggest challenge we need to face centres on the myth and reality. There are lots of myths out there as to what Linux can do. One myth we see is that Linux is more secure than Windows. Another is that there are no viruses for Linux,» said McGrath.

(...)

«In Microsoft's world customers are confidant that we take responsibility. They know that they will get their upgrades and patches.»

(...)

«There a myth in the market that there are hundreds of thousands of people writing code for the Linux kernel. This is not the case; the number is hundreds, not thousands,» he said.

«If you look at the number of people who contribute to the kernel tree, you see that a significant amount of the work is just done by a handful.»

«There are very few of the improvements that come through the wider community. There are more skilled developers writing for the Microsoft platform than for open source. »

(...)

McGrath argued that recent growth in Linux deployments came largely at the expense of installed Unix systems, rather than replacement of Windows servers.

«We are increasingly seeing that the biggest challenges in the marketplace are less for Microsoft and more in the Unix space. Customers are moving away from Risc to Intel as the price performance ratio is compelling,» he said.

«A lot of the percentage growth figures mask the fact that Linux is coming from a very small base. There are more Unix servers than Linux servers in the UK. There are more Windows servers than Linux servers in the UK.»

(...)

«A lot of customers have got trials and pilots of Linux, but are holding back Linux deployment into the mainstream because the operating system does not have the solution stack that they were expecting,» he said.

«Most customers look for more than just a product from their vendors. They need a solution that comes with the appropriate levels of support and service. This is where Linux is becoming more challenged as people expect more from Linux.»

«Linux is not ready for mission-critical computing. There are fundamental things missing. For example, there is no single development environment for Linux as there is for Microsoft, neither is there a single sign-on system.»

«There are bits of the Linux software stack that are missing. These are factors that are holding back Linux.»
 
Personalment no estic d'acord amb pràcticament res del que diu, excepte en el paràgraf que he ressaltat: Linux sovint es vist com una alternativa als grans sistemes Unix que no pas com una alternativa a Windows. Personalment crec que aquesta afirmació es bastant propera a allò que em trobo a les diverses empreses que, per motius professionals, conec.


13:35 (# Enllaç permanent) | Comentaris: | Trackback:


[News.com] Report: Major Windows security update foiled. Una empresa russa afirma haver trobar una greu vulnerabilitat de seguretat al Service Pack 2 de Windows XP, concretament als mecanismes implementats per impedir l'aprofitament dels desbordaments de memòria intermèdia. 

Més detalls a la web dels descobridors del problema: Defeating Microsoft Windows XP SP2 Heap protection and DEP bypass.
In October 2004 it was discovered by MaxPatrol team that it is possible to defeat Microsoft® Windows® XP SP2 Heap protection and Data Execution Prevention mechanism. As a result it is possible to implement:
  1. Arbitrary memory region write access (smaller or equal to 1016 bytes)
  2. Arbitrary code execution
  3. DEP bypass.
Details are described in the article by our expert: PDF format, HTML format.
 


13:21 (# Enllaç permanent) | Comentaris: | Trackback:

© Copyright 2003-2005 Xavier Caballe. . Si no s'indica expressament el contrari, el material publicat en aquest weblog es distribueix d'acord amb la llicència Creative Commons. El contingut és responsabilitat única i exclusivament del seu autor i no té cap relació amb les seves activitats professionals.

350

Wishlist
Gener 2005
Diu Dil Dim Dim Dij Div Dis
            1
2 3 4 5 6 7 8
9 10 11 12 13 14 15
16 17 18 19 20 21 22
23 24 25 26 27 28 29
30 31          
Des   Feb

Click to see the XML version of this web page.




Contingut actualitzat




Categories


Darrers comentaris

Arxiu

Contingut antic
(ja no s'actualitza)


Articles
(fins maig 2003)



Versions anteriors
d'aquesta pàgina

Webs d'amics
jcea
Vicent Partal
Jordi Mas
Toni Hermoso
Mercè Molist
Mina Nabona-Jassans

Gurus
Scripting News
Jon Udell
Bruce Sterling
Bruce Schneier
Howard Rheingold
Reflexiones e irreflexiones
Atalaya
Cuaderno de bitácora
Linotipo
Pedro Jorge Romero

Seguretat
reversing.org
Seguridad de la información
Somiatruites, Ciberderechos
     en la red

eN Espiral ~> Juanma Merino
Navega seguro

PDA
CosesPalm
PalmCat
CanalPDA.com

Cultura
El Llibreter