BLOG.RONSOME.COM

Vulnerablity Found in Flash

June 05, 2010

Steve Jobs must be laughing so hard his sides hurt. Yesterday Adobe released a security advisory detailing a "critical" vulnerability in Flash (as well as Acrobat and Reader). To make matters worse, Adobe has yet to come up with a fix. According to the bulletin users can upgrade to Flash 10.1RC. So it looks like I have two choices: upgrade to a non-production software release, or remove Flash altogether. I think I'll opt for the latter.

When I first saw the security bulletin I wondered exactly which version of Flash I had. First, I tried finding a Flash movie and clicking on "About Flash" in the context menu. That sent me to a page on Adobe's website which didn't even detect my Flash Player. Nice. My solution was to write a bookmarklet in JavaScript. This works fine in browsers other than IE. making it work in Microsoft's crappy browser would simply require more work than I'm willing to put in.

Check Flash Version

Labels: , ,

The Windows vs. Linux Security Debate

June 02, 2010

I've been reading some of the coverage of Google's supposed move away from Windows in its offices. Mashable reports that the change is due, in part, to security concerns after Chinese hackers were able to compromise some of Google's systems. The initial response to the story seemed to be "Big deal, everyone knows that *nix is more secure than Windows." Microsoft got its feathers ruffled responded, though, and once again the age-old "Microsoft is the most popular OS, so it get attacked the most" argument has risen its head.

The argument goes something like this: Windows security is actually pretty good, but Windows machines are, by far, the most popular desktop computer platform, so hackers concentrate their malicious efforts on it. The argument, at first, seems pretty sound, but it got me wondering how many servers are running Linux. Certainly the number is significant among the world's total computers (according to Steve Ballmer "Forty percent of servers run Windows, 60 percent run Linux"). I think it's possible, maybe even likely that the number of discrete desktop systems in the world is higher than the number of servers, but still, that is a huge number. Consider also that the potential payday from successfully hacking a server, which may hold millions of users' sensitive information (rather than just a single user's), and it seems to me that Linux systems probably endure their fair share of malicious attacks.

Labels: , ,

Don't Ask For Help

March 02, 2010

Microsoft advises users to avoid pressing the F1 key if prompted by a web site after a researcher turned up a security flaw in Windows XP.

Labels: , , ,