ie8 fix

Security

Gmail cookie stolen via Google Spreadsheets

Security researcher Bill Rios reported Monday that a cross-site scripting (XSS) attack against Google Spreadsheet could have exposed all of Google's services. XSS can occur whenever a legitimate site accepts input from the user but does not filter that input properly and could allow the injection of potentially malicious instructions. In this case, however, once an attacker gained access to any xxxx.google.com site, they would have access to other Google services, such as Gmail, Docs, and Code.

In an e-mail to CNET News.com, a Google representative confirmed that the flaw as described by Rios has been … Read more

Researcher: Misunderstandings surround RFID in use today

When asked how RFID worked, a group of novices responded to a recent academic survey with "witchcraft" and "magic."

In a talk Monday at USENIX Usability, Psyschology and Security Conference (UPSEC) 2008 in San Francisco, Andrew McDiarmid of the University of California, Berkeley, shed light on how ordinary people perceive RFID-enabled cards in their day to day life. He said while novices and intermediates were familiar with times when RFID-enabled smart cards such as work access cards or transit cards didn't work, they couldn't explain it. On the other hand, advanced users knew enough … Read more

Press barred from Gore's RSA speech

When Al Gore agreed to talk at the end of the RSA 2008 conference, the 2007 Nobel Laureate stipulated in his contract with RSA that no members of the press would be allowed inside the keynote address. Many of my colleagues in the press were put out about this, and rightly so.

Fortunately, this year I was registered as a speaker at RSA 2008, so I didn't have my usual press pass (although the nice guardians at the press room door certainly didn't stop me from going inside).

Since individual attendees at RSA are allowed to blog and … Read more

Gore's RSA talk updates 'Inconvenient Truth'

SAN FRANCISCO--Global warming is real, and new evidence shows it may be worse than we previously thought, former Vice President Al Gore said during an RSA keynote address on emerging green technologies Friday.

The talk, which ran 45 minutes and closed the conference here, updated the presentation used in his Academy Award-winning documentary An Inconvenient Truth.

Friday's talk was similar to one Gore delivered in February at the annual TED conference, but without the slides. During the speech here, the 2007 Nobel Laureate was interrupted by hecklers three times; each was removed by security.

In an arrangement with RSA, … Read more

Echo Boom hackers: Shame

On Thursday morning, at this year's RSA conference in San Francisco, Chris Boyd of Facetime and I will present a talk "How to Adapt to the Echo Generation's Social Media Hacking Game." The following is a preview of that talk, presented in three parts. On Tuesday we learned who the Echo Generation are. Wednesday we saw how they use online social media for hacks. Today, we'll see how Chris uses features of social networks and Web 2.0 to shut these kids down.

Known as the Sherlock Holmes of France, famed criminologist Edmond Locard once … Read more

Echo Boom hackers: A dangerous game

On Thursday morning, at this year's RSA Conference in San Francisco, Chris Boyd of Facetime and I will present a talk called "How to Adapt to the Echo Generation's Social-Media Hacking Game." The following is a preview of that talk, presented in three parts. Yesterday, we saw who the Echo Generation are. Today, we're looking at how they use online social media for hacks. Tomorrow, we'll see how Chris uses features of social networks and Web 2.0 to shut these kids down.

For the last few years, Chris Boyd, director of malware research … Read more

Cryptographers speak of threats, voting, and Blu-Ray rumors

On Tuesday, the creators of the Diffie-Hellman key exchange, a cryptographic protocol, and two of the creators of EMC security division RSA gathered onstage for the annual cryptographers' panel at RSA 2008 in San Francisco.

First, panel members offered their perspectives on the state of security since last year, then they answered questions posed by a moderator. The panel included: Whitfield Diffie, chief security officer at Sun Microsystems; Martin Hellman, professor emeritus of electrical engineering at Stanford University; Ronald Rivest, professor of electrical engineering and computer science at MIT; and Adi Shamir, professor of computer science at the Weizmann Institute … Read more

Tech lobbying groups CSIA, ITAA merge

John W. Thompson, chairman and CEO of Symantec, used part of his keynote address Tuesday at RSA 2008 to announce the merger of the Cyber Security Industry Alliance and the Information Technology Association of America.

CSIA includes the top security providers and seeks to influence security policy in the U.S. and the European Union; ITAA is a much larger policy group. He said "this will give CSIA a bigger platform and a stronger voice on these critical public policy issues and the ability to work with governments and key stakeholders around the world."

In a press release, … Read more

Symantec CEO talks ID management, the future

Predicting the future for technology and business is never easy, yet Symantec CEO John Thompson ventured into that Tuesday morning in his keynote speech at RSA 2008.

On the future, Thompson predicted three things: that malicious software will outnumber legitimate software, increasing the need for so-called white listing; that identity management will grow beyond the enterprise and start to include every customer in the world; and digital rights management will be become a reality for all content, not just music and video.

He said businesses need to start thinking about these things now. "I believe this starts with a … Read more

Meet the Echo Boom hackers

On Thursday morning, at this year's RSA Conference in San Francisco, Chris Boyd of Facetime and I will present a talk, "How to Adapt to the Echo Generation's Social Media Hacking Game." The following is a preview of that talk, presented in three parts. On Tuesday, we're looking at who are the Echo Generation hackers. Wednesday , we'll look at how they use online social media for hacks. And on Thursday, we'll talk about how Chris uses features of social networks and Web 2.0 to shut these kids down.

It's a world … Read more