Archive for the ‘App Security’ Category

UK Government: Upgrading Away From IE6 Costs Too Much

|

Or, a more appropriate title, “UK Government: How To Fail”.

So, the bullet point version is that a petition was circulated in an effort to get the UK government to drop the use of the Internet Explorer 6 browser. Well, they got the petition and responded roughly as follows…

From Ars Technica:

Complex software will always have vulnerabilities and motivated adversaries will always work to discover and take advantage of them. There is no evidence that upgrading away from the latest fully patched versions of Internet Explorer to other browsers will make users more secure. Regular software patching and updating will help defend against the latest threats. The Government continues to work with Microsoft and other internet browser suppliers to understand the security of the products used by HMG, including Internet Explorer and we welcome the work that Microsoft are continuing do on delivering security solutions which are deployed as quickly as possible to all Internet Explorer users.

I can see VXers tenting their fingers madly and doing their best Mr. Burns impressions as we speak.

Please, pull out the clawhammer…gently…OUCH!

Article Link

(Image used under CC from billypalooza)



Online Casino Glitch Let Players Use Others’ Cash

|

So, it appears that the government sanctioned online casino, based in British Columbia, had an unintended feature when it launched the other day. Players could make bets…with other players money.

WTF?

From The Globe and Mail:

While it’s not clear how many took advantage of the rare opportunity to experience risk-free gambling, the bizarre security breach prompted BC Lottery Corporation to close down the heavily travelled site soon after it opened for business last Thursday.

PlayNow.com, the first government-sanctioned site in North America to offer online casino games, remains closed while software developers try to figure out what went wrong.

The British Columbia Lottery Corporation went with the tried and true knee jerk reaction of blaming the error on system load. Later they retracted their comments and blamed the error on “data crossover”.

I believe that’s Orwellian for “somebody fucked up”.

Article Link