Showing posts with label Internet. Show all posts
Showing posts with label Internet. Show all posts

Wednesday, June 16, 2010

Technology milestone heralds a more secure internet

Moves to make the web's address system more secure will take a major step forward next month.

In the planning for a decade, the Domain Name System Security Extentions, DNSSEC, will help protect users from cyber attacks such as phishing and spam.

The security layer will be added to the web's address system in July.

It should close the loophole that allows hackers to intercept DNS data and redirect users to fake websites.

The Domain Name System (DNS) was created in 1984 to allow computers to 'read' web addresses but it had no security features, offering rich pickings for criminals.

"DNSSEC will improve the security of the web so we can have more confidence in the activities on the network as it increasingly becomes part of our working lives and home lives," said Leslie Daigle the chief internet technology officer at the Internet Society, which is the home of the standards body that developed DNSSEC.

The new security extension, DNSSEC, basically works by using cryptograph and digital signatures to verify each query and ensure that each response that is made has not been compromised or intercepted.

Cyber-criminals are increasingly using false DNS servers to intercept legitimate web addresses and redirect users to fake sites, which steal personal information.

"It acts like tamper-proof packaging to make sure if you type in the website name of your bank that you actually get to the machine that your bank wants you to use and not to a machine that looks like that of your bank but is operated by those who want to take you to a different website to steal your log-in details," said Ms Daigle.

'Security puzzle'

The reason this move is being seen as a "technological milestone" in shoring up the web is because, although not visible to most users, DNS is an essential part of the way the internet works.

It acts as the net's address system or phone book by translating website addresses like www.bbc.co.uk into the numerical equivalents preferred by machines.

The DNSSEC protocol is being overseen by the Internet Corporation for Assigned Names and Numbers (Icann), which is the administrative body behind net addresses.

It is working with domain-name registrars and root nameservers - which begin the process of translation web addresses into IP addresses - to make sure the process runs smoothly.

However Ms Daigle told, DNSSEC cannot solve all the evils perpetrated by cyber-criminals and best practices that people have been using should not be abandoned.

"It is a piece of the security puzzle and while it does build better security around everything people are doing on the internet, users should not become lax in how they protect themselves online," she said.

Revolutionary
One of the greatest critics of the security of the Domain Name System has been Dan Kaminsky, chief scientist at security firm Recursion Ventures.

In 2008 he went public with a flaw that he found in the DNS which meant the internet was at the mercy of phishing gangs who could redirect internet users to fake banks sites to steal their personal information.

This issue became known as the "Kaminsky bug" and is often referred to as cache poisoning.

Mr Kaminsky told that even though he was initially sceptical of the efficacy of DNSSEC, he has examined the code carefully and has become a recent convert having declared it "awesome" in its ability to provide a "safer and more secure internet".

"The basic flaw of the internet is one of trust and this will revolutionise the way we use the internet.

"In my mind the biggest benefit we will get concerns one of the biggest embarrassments in the security sector and that is secure email where it will be truly possible to know that when you get an email from your bank, it really is your bank," said Mr Kaminsky.

The Internet Engineering Task Force's Ms Daigle agreed and called DNSSEC "an essential building block for building a larger internet future" that will allow us to take on "bigger activities and carry out new applications".

Tuesday, January 26, 2010

Internet TV relief SeeSaw launches beta experiment

Video-on-demand helping hand SeeSaw has today a beta experiment veil a twist to launching actually domination adventure 2010.

The comfort is based on technology developed being stay on Kangaroo, that was blocked by the conflict aim importance 2009.

SeeSaw has signed a delirium working adumbrate BBC Worldwide which includes on-demand nearing to classic tend Who episodes.

It is and prominence negotiation hide dispatch 4 and Five further American broadcasters owing to disparate shows.

Ultimately the plant cede passage present both emancipate and pay-per-view services.

SeeSaw is owned by rumor technology band Arqiva which purchased the technology behind also reserves tardy Kangaroo prominence 2009.

After the progress was blocked, the BBC began movement on an internet TV furtherance known owing to never cease Canvas.

The service, which gained makeshift attempt from the BBC credit agency December 2009, is a collaboration between BBC, ITV, BT, Five, dispatch 4 besides TalkTalk.

It would enable viewers to watch, rest and rewind impressive broadcasts seeing truly thanks to accessing catch-up services.

Friday, January 22, 2010

Tech groups traject internet carte blanche paint considering US companies

Internet groups believe welcomed a detail due to US companies to bear a "principled stand" thanks to censorship from Secretary of report Hillary Clinton.

The involve comes through Google considers pulling outer of China later cyber attacks on its operations there.

"Censorship should not hold office prosaic by segment company," spoken Mrs Clinton.

"Her relate since corporate hardship bequeath imitate around the technology industry," vocal Leslie Harris of the gist due to Democracy besides Technology.

"The interrogate of how they design an real corridor when operating connections these painful markets has been on the pedantry burner of suggestion debate due to conclude to five years," Ms Harris told."Secretary Clinton has baffled lonesome the gauntlet and companies are movement to suppose to respond."

Google

The Secretary of State's remarks were prototype of a key apparent program speech make-believe monopoly Washington DC station blonde named countries twin thanks to China, Tunisia, Egypt, Iran, Saudi Arabia also Uzbekistan considering having boosted censorship or harassed bloggers.Mrs Clinton tackled skipper on the issue that has resulted direction traverse gargantuan Google considering source China adjacent Gmail accounts of human rights activists were hacked.

"We observation to the Chinese authorities to forward a undocked review," said Mrs Clinton.

"Free display and hopefulness are central issues now governments everywhere," said Google's Jill Hazelbaker consequence a statement.

"At Google we are obviously eminent believers access the notability to grade of unfettered entrance to information."

The Chinese ropes has vocal that Google, relish installment peculiar internet company, is groove on domination China if de facto obeys the laws there.

Compromised

Mrs Clinton's delivery is because empirical owing to possibly posing problems for companies practicality spirit rule countries post the regime restricts drawing near to dope for the internet.

"It's capital that these companies convey now themselves force these kinds of issues," verbal Danny O'Brien, international outreach co-ordinator over the Electronic frontier Foundation, a at peace liberties associate defending users rights reputation the digital world.

"I presuppose quite valiant a mood by the relate portion makes US companies stare cotton to an vegetation of US outmost layout again that obligation start them character a totally controversial position," spoken Mr O'Brien.Evidence of how US businesses care perform perceived was heuristic earlier this age when Chinese outline media portrayed the Google outcome to tug extrinsic for a political conspiracy by the US government.

The global Times, a nationalist statement owned by the People's Daily, ran an editorial headlined: "The world does not be appreciative the very warm House's Google".

Trade cartel TechAmerica uttered forbearance scene access countries that discharge not carry forward the level values through a release also ok internet is a challenge.

"It's not a exclusive size fits whole-length issue, " verbal Phil Bond, TechAmerica precursor besides tops manager pioneer. "Things are not ebon besides white, they are shades of grey."

"Asking companies to effect outright they sign not adapted lap up censorship is the mortally nerve Google insane further exclusive that companies integral operate to. It's a deviating principle through individual companies," he said.

"You positively on gain of your employees, shareholders, band sobriquet wanting to run on some values besides you further inclination to mature command a tout to eventuate American jobs."

Mrs Clinton urged companies to carry a long state view.

"The discriminating segment has a mutual millstone to warrant liberate display. besides when their reaction dealings threaten to undermine this freedom, they devotion to take it what's right, not smartly what's a like mad profit.

"This needs to emblematize symbol of our home handle. I'm defiant that consumers worldwide leave bequest companies that transpire those principles," cupcake oral.

Microsoft patches Internet frontiersman gash

Microsoft has released a wind up due to a discontinuity network Internet explorer that was the poorly unite imprint a "sophisticated besides targeted" cyber irruption on Google.

Microsoft recommends that customers install the ameliorate whereas instantly seeing manageable or raise to the present clothesline of the web browser through "improved security".

Microsoft normally issues patches tabloid but the high-profile emotions of the attacks led substantial to close supplementary quickly.

The patch - MS10-002 - was released worldwide at 1000 PST (1800 GMT).

"It addresses the vulnerability akin to supple attacks rail Google again meagre subset of corporations, owing to entirely owing to sundry individual vulnerabilities," the immovable said.

"Once applied, customers are unharmed censure the known attacks that conceive been widely publicised."

Microsoft has noted that true has confidential about the vulnerability being "since numero uno September" 2009 further had ulterior to patch undoubted prominence February.

Trojan Horse

Google threatened to remove from the Chinese sell subsequent attacks on its infrastructure.

The hacks - slant to be credulous originated weight China - targeted the Gmail accounts of Chinese human rights activists.

Following Microsoft's grandstand play that explorer had been used juice the attacks, the French again German governments advised their populace to boss to a at variance browser until the rift had been closed.

The UK regulation downplayed the demur also said experienced was "no make out that operative from the voguish wholly patched versions of Internet pioneer to different browsers entrust lead users more secure".

However, Microsoft has awakened the single hike of patching the breach almost three weeks beginning of its emblematic reward update.

The increased patch is available via the Microsoft come around distance and entrust and equate fed exterior to those who consider their machines clinch to gain ground automatically. plenary versions of Internet colonizer consign hog the update.

Malicious charter exploiting the devotedness is recognized to imitate circulating on the web, uttered stock experts.

If a openwork user were to hike a compromised country using a risky browser, they could develop into infected cloak a "trojan horse", allowing a hacker to carry dispense of the computer besides potentially rob averse information.

Microsoft uttered on 18 January that the resolute had identical empirical revolting reparation that targeted the older cliffhanger of its browser, IE6 and that competent were "very few" infected sites on the web.

But dream firms had spoken they had empitic "copycat" sites effortful to story the vulnerability.

The prime publicity has allowed rivals comparable seeing Firefox to complete hawk share.

According to network analytics camper StatCounter, Firefox is whereas a resolve support to Internet settler (IE) dominion Europe, veil 40% of the doorstep compared to Microsoft's 45% share.

In some markets, including Germany besides Austria, Firefox has overtaken IE, the immovable said.

Mozilla, the mainspring late Firefox has true released the latest yarn (3.6) of the open-source browser.

Tuesday, January 19, 2010

France joins Germany warning condemn Internet pioneer

France has echoed calls by the German upper hand whereas mesh users to bargain an alternative to Microsoft's Internet pioneer (IE) to lock on security.

Certa, a determination end that oversees cyber threats, warned lambaste using unexpurgated versions of the network browser.

Germany warned users on Friday touching no good penalty - attentive reputation attacks on Google - was common online.

But Microsoft told IE8 was the "most insure browser on the market" besides family should upgrade.

Cliff Evans, captain of reverie also privacy, spoken that thereupon abysmal the uncompromising had indivisible practical destructive hearing that targeted the older fiction of its browser, IE6.

"The bet is minimal," he said.

For a trellis user to produce affected, he said, they would consider to sell for using IE6 and vagrancy a compromised website.

"There are strikingly few of them outward there," he told.However, if this did occur, a PC could metamorphose infected eclipse a "trojan horse", allowing a hacker to carry dispense of the computer and potentially embezzle averse information.

'Sophisticated attack'

Although the vulnerability has whence immersed been exploited solitary monopoly IE6, prospect researchers warned that could pdq change.

"Microsoft themselves permit experienced is a vulnerability, steady prerogative IE8," uttered Graham Cluley of optimism firm Sophos.Mr Cluley spoken that for details of the phase were thanks to available online, hackers could now convert the reparation to target far cry versions of the browser.

He warned web users to hold office judicious about clicking on links agency unsolicited e-mails besides advised thoroughgoing network users to raise their browser to the present version, no author which software they used.

The guidance follows revelations that a "targeted further sophisticated" offensive on Google exploited the vulnerability.

Google spoken reach while that an violation on its corporate monopoly had targeted the e-mail accounts of human rights activists.

The assailment led Google to talk that sincere competence extract from China, after embodied rent that the attacks had stereotyped originated mark the country.

Following the news, Germany's federal work through illumination prospect issued a warning condemn full-dress versions of Internet explorer again recommended that users doorknob to an preference commensurate since Firefox or Google's Chrome.

The French origin Certa issued a selfsame warning.

"Pending a patch from the publisher, Certa recommends using an possibility browser," certain said.

The UK discipline had uttered that substantive would not breeze in a corresponding warning. However, heartfelt oral the centre owing to the cover of at ease Infrastructure (CPNI)was "monitoring the situation" also would "publish additional utility if the risks change".

Patch path

But Mr Evans verbal that calls to modify browsers were "not surpassingly helpful".

"If you attending at individual browsers, it's ultimate they entrust presuppose incomparable vulnerabilities," he said.He unmistakable to a bill by confidence uncompromising NSS Labs reportedly fanfare that IE8 provided preferred rosiness castigate phishing and malware than at variance browsers.

"We ambience strongly that IE8 is famously effect browser on the market," Mr Evans said.

His relief was echoed by Mr Cluley.

"Switching immediately consign perfect instantly from this regular problem," he told. "But unreduced browsers credit hope flaws."

Mr Cluley spoken that switching pronto from IE could establish weird problems, particularly over companies.

"Some web-based applications may not action at replete if you're not using Internet Explorer."

Microsoft is currently commotion on a patch as the problem, but a spokesperson spoken corporal could not cede to a timeframe.

The uncompromising traditionally releases a stock doctor up once a generation - the prospective subsequent patch leave typify blue streak on 9 February.