Archive for the ‘Network World’ Category

Google Chrome will no longer check for revoked SSL certificates online

|
Comments Off
Google plans to remove online certificate revocation checks from future versions of Chrome, because it considers the process inefficient and slow.

EU to stengthen its cybersecurity watchdog

|
Comments Off
A push by European authorities to strengthen the European Union's cyber security watchdog has been given a green light by parliamentarians.

Free Web tool consolidates data on code vulnerabilities

|
Comments Off
Enterprise coders can now use an open source Web application that lets them consolidate software vulnerability data from a range of scanning and test tools. With a centralized view, and reporting and management tools, ThreadFix speeds the work needed to fix software bugs and vulnerabilities, including those in proliferating mobile apps.

Trustwave admits issuing man-in-the-middle digital certificate, Mozilla debates punishment

|
Comments Off
Digital Certificate Authority (CA) Trustwave revealed that it has issued a digital certificate that enabled an unnamed private company to spy on SSL-protected connections within its corporate network, an action that prompted the Mozilla community to debate whether the CA's root certificate should be removed from Firefox.

Data breach? Blame your third party’s remote access systems

|
Comments Off
An in-depth study of data-breach problems last year where hackers infiltrated 312 businesses to grab gobs of mainly customer payment-card information found the primary way they got in was through third-party vendor remote-access applications or VPN for systems maintenance.

Adobe sets IE as next target in Flash security work

|
Comments Off
Adobe next plans to tackle Microsoft's Internet Explorer in its ongoing work to "sandbox" its popular Flash Player within browsers, Adobe's head of security said today.

FBI declares cloud vendors must meet CJIS security rules

|
Comments Off
The FBI Tuesday reaffirmed its rule that all cloud products sold to to U.S. law enforcement agencies must comply with the FBI's Criminal Justice Information Systems security requirements.

FTC warns makers of background checking apps

|
Comments Off
The U.S. Federal Trade Commission has sent warning letters to the makers of six mobile apps used for background checks, saying the apps may violate a consumer credit protection law.

Something fishy about Google Chrome’s Safe Browsing API, lab says

|
Comments Off
A research firm that measures the security effectiveness of browsers noticed something it thought might be fishy with the way Chrome was doing things. Turns out, there may currently be a privacy concern about Google's use of end user IP addresses as part of its Safe Browsing API.

Anonymous claims to have released source code of Symantec’s pcAnywhere

|
Comments Off
Hacker group Anonymous claimed late Monday that the source code of Symantec's pcAnywhere had been uploaded on The Pirate Bay site.