<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>BrandonLive &#187; Security</title>
	<atom:link href="http://brandonlive.com/tag/security/feed/" rel="self" type="application/rss+xml" />
	<link>http://brandonlive.com</link>
	<description>Seattle Geek with lots to say.</description>
	<lastBuildDate>Tue, 27 Apr 2010 17:53:27 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.2</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>Why are browser plug-ins so insecure?</title>
		<link>http://brandonlive.com/2008/08/09/why-are-browser-plug-ins-so-insecure/</link>
		<comments>http://brandonlive.com/2008/08/09/why-are-browser-plug-ins-so-insecure/#comments</comments>
		<pubDate>Sun, 10 Aug 2008 04:59:07 +0000</pubDate>
		<dc:creator>Brandon</dc:creator>
				<category><![CDATA[Microsoft]]></category>
		<category><![CDATA[News]]></category>
		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://brandonlive.com/2008/08/09/why-are-browser-plug-ins-so-insecure/</guid>
		<description><![CDATA[Flash and Java, I’m looking at you.
You may have heard about the paper released at this week’s Black Hat conference, describing limitations in Windows’ memory protection schemes like ASLR, DEP, etc.&#160; The paper is well-written, very detailed, and I’ve no reason to doubt that it’s pretty accurate.&#160; Some points it makes are things that teams [...]]]></description>
			<content:encoded><![CDATA[<p>Flash and Java, I’m looking at you.</p>
<p>You may have heard about <a href="http://blogs.zdnet.com/hardware/?p=2387">the paper released at this week’s Black Hat conference</a>, describing limitations in Windows’ memory protection schemes like ASLR, DEP, etc.&#160; The paper is well-written, very detailed, and I’ve no reason to doubt that it’s pretty accurate.&#160; Some points it makes are things that teams at Microsoft are already aware of and working to remedy (such as DEP not being enabled for IE, for example).&#160; </p>
<p>But reading the paper made it very clear that the most exploitable targets these days aren’t even web browsers, they’re plug-ins like Flash and Java.&#160; The article points out how the Java run-time (“JVM”) was made DEP-compatible with the ingenious change to make all of the memory it allocates be marked as executable.&#160; So yeah, it works with DEP by making DEP irrelevant.&#160; Hilarious.&#160; And sad.</p>
<p>Flash is still not ASLR or DEP compatible.&#160; We’re rapidly approaching two years from the release of Vista.&#160; They’ve had <em>way longer than that</em> to prepare to take advantage of these very helpful security features.&#160; Yet here we are in August 2008 and the most prevalent and successful browser add-ins do virtually nothing to ensure that they aren’t abused by attackers.</p>
<p>Now, to be fair, the attackers also mention .NET as a possible attack vector.&#160; In fact, what they describe is pretty clever.&#160; But that’s the thing, at least they had to be clever.&#160; With Flash and Java they don’t, as those add-ins make no attempt to be secure.&#160; And if you want to make a bet about which of those three (Flash, JVM, .NET) has its issues fixed first, I know where I’m putting my money.</p>
]]></content:encoded>
			<wfw:commentRss>http://brandonlive.com/2008/08/09/why-are-browser-plug-ins-so-insecure/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Snow Leopard = Apple&#8217;s XP SP2?  It better be.</title>
		<link>http://brandonlive.com/2008/06/22/snow-leopard-apples-xp-sp2/</link>
		<comments>http://brandonlive.com/2008/06/22/snow-leopard-apples-xp-sp2/#comments</comments>
		<pubDate>Mon, 23 Jun 2008 04:23:31 +0000</pubDate>
		<dc:creator>Brandon</dc:creator>
				<category><![CDATA[Other]]></category>
		<category><![CDATA[Apple]]></category>
		<category><![CDATA[Macintosh]]></category>
		<category><![CDATA[News]]></category>
		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://brandonlive.com/2008/06/22/snow-leopard-apples-xp-sp2/</guid>
		<description><![CDATA[
Update: Today a few people started talking about Snow Leopard&#8217;s supposed new features, including a report on dramatically reduced file sizes.  I think it&#8217;s pretty obvious how they accomplished that &#8211; no more fat binaries with PowerPC and PowerPC/64-bit support.

 
As I read the initial details about Apple&#8217;s &#8220;Snow Leopard&#8221; release (ostensibly called OS X 10.6), [...]]]></description>
			<content:encoded><![CDATA[<ul>
<li><strong>Update: </strong>Today a few people started talking about Snow Leopard&#8217;s supposed new features, including a report on <a href="http://www.appleinsider.com/articles/08/06/23/five_undisclosed_features_of_apples_mac_os_x_snow_leopard.html">dramatically reduced file sizes</a>.  I think it&#8217;s pretty obvious how they accomplished that &#8211; no more fat binaries with PowerPC and PowerPC/64-bit support.</li>
</ul>
<p> </p>
<p>As I read the initial details about Apple&#8217;s <a href="http://www.apple.com/macosx/snowleopard/">&#8220;Snow Leopard&#8221; release</a> (ostensibly called OS X 10.6), I got to thinking&#8230; What do they mean that they&#8217;ve taken the focus away from new features?</p>
<p>From Apple.com:</p>
<blockquote><p>Taking a break from adding new features, Snow Leopard — scheduled to ship in about a year — builds on Leopard’s enormous innovations by delivering a new generation of core software technologies that will streamline Mac OS X, enhance its performance, and set new standards for quality.</p></blockquote>
<p>One word was striking to me, not for its presence, but for its absence.  That word is &#8220;security.&#8221;  A few years ago Microsoft was more or less caught with its pants down when it came to the wild world of the web.  But a couple years after Windows XP was released, Microsoft &#8220;got religion&#8221; on security and made some deep changes.  Those culminated in the release of XP SP2 &#8211; which consisted of a top-to-bottom review of the XP code and a major security-focused overhaul of its code.  It&#8217;s been said many times that certain high-level Windows execs thought XP SP2 should have been an entire OS release instead of a service pack.  That&#8217;s how big the changes were.  But who would ship a new OS with basically zero new features?  Well, now we know.</p>
<p>That has me wondering&#8230; why <em>is</em> Apple taking the focus off of new features for 10.6.  Especially when Leopard wasn&#8217;t exactly brimming with new hotness.  I think there are three reasons:</p>
<p>1) iPhone.  Jobs has shown a great ability to focus the entirety of Apple on a &#8220;north star&#8221; and drive toward it full-steam-ahead.  That&#8217;s what the iPhone is doing now, and to great effect.  However, this is not without cost.  Apple&#8217;s focus on the iPhone has left it with fewer resources to devote to other projects, particularly when it comes to software development.  Thus I have a feeling the crew working on OS X these days is a good deal smaller than the group that worked on Panther and Tiger.</p>
<p>2) Embedded devices.  Apple says they&#8217;re going to slim-down OS X in 10.6.  That makes sense, especially when you consider their affinity for flash-based devices.  If we&#8217;re going to see a Mac sub-tablet / super-sized iPhone device, this will be the OS for it.  It&#8217;s also likely a way to leverage some of those iPhone-focused resources in order to ship a version of OS X timed to counter Windows 7.</p>
<p>3) Security.  Apple&#8217;s PC marketshare is growing.  This is great for them, but only if they can hold onto it.  An onslaught of security nightmares, like those suffered by Windows XP a few years ago, would be disasterous.  They can&#8217;t afford to risk it.  Apple knows that they won&#8217;t be spared by attackers for much longer, not when their market is growing.  The untested nature of its software (untested by the &#8220;hacker&#8221; community) and its increasing prevalence on machines will make it a very tempting target soon enough.</p>
<p>So why is number 3 so important?  Because Apple can&#8217;t keep claiming that <a href="http://rixstep.com/1/20080620,00.shtml">gaping holes in their software aren&#8217;t important.</a>  They have an opportunity to have their XP SP2 without having their MS.Blaster / Code Red / Slasher / etc.  They can do something now to prevent malware from becoming as rampant on Macs as it was on Windows XP systems.  If they <em>aren&#8217;t</em> doing this, they&#8217;re being foolish, and they&#8217;ll get little sympathy from those who keep telling them to<a href="http://www.oreillynet.com/onlamp/blog/2008/05/safari_carpet_bomb.html"> get their act together.</a></p>
<p>So how much time does Apple have left to figure this out?  I think not long.  Heck, the first shots <a href="http://www.computerworld.com/action/article.do?command=viewArticleBasic&amp;articleId=9101898">may already have been fired.</a></p>
<p> </p>
]]></content:encoded>
			<wfw:commentRss>http://brandonlive.com/2008/06/22/snow-leopard-apples-xp-sp2/feed/</wfw:commentRss>
		<slash:comments>4</slash:comments>
		</item>
		<item>
		<title>Trend Micro thinks your PC is too secure (UPDATED)</title>
		<link>http://brandonlive.com/2008/03/23/dont-trust-trend-micro-with-your-pc-security/</link>
		<comments>http://brandonlive.com/2008/03/23/dont-trust-trend-micro-with-your-pc-security/#comments</comments>
		<pubDate>Sun, 23 Mar 2008 18:51:37 +0000</pubDate>
		<dc:creator>Brandon</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[The worst ever]]></category>
		<category><![CDATA[Windows Vista]]></category>

		<guid isPermaLink="false">http://brandonlive.com/2008/03/23/dont-trust-trend-micro-with-your-pc-security/</guid>
		<description><![CDATA[Update 2: Trend Micro has sent a new response to the guy with the original problem, viewable here.  It seems that you can uninstall the build discussed below and install a new Vista-friendly one at this link.
Update: Apparently I misunderstood the timing of this e-mail, and it is actually from last year.  I&#8217;ve updated the post a [...]]]></description>
			<content:encoded><![CDATA[<p><strong>Update 2: </strong>Trend Micro has sent a new response to the guy with the original problem, <a href="http://esupport.trendmicro.com/support/viewxml.do?ContentID=EN-1036026&amp;id=EN-1036026">viewable here</a>.<strong>  </strong>It seems that you can uninstall the build discussed below and install a new Vista-friendly one <a href="http://esupport.trendmicro.com/support/viewxml.do?ContentID=EN-1036026&amp;id=EN-1036026">at this link.</a></p>
<p><strong>Update: </strong>Apparently I misunderstood the timing of this e-mail, and it is actually from last year.  I&#8217;ve updated the post a bit to make that clearer and to be a little less harsh, since I don&#8217;t <em>know</em> that they&#8217;re still sending mails like this.  But the user is still having the same problem, and their web site still suggests the same solution, so it&#8217;s likely they are.  If you&#8217;ve received one like it, please let me know!</p>
<p>A Neowin forum member brought up what they believed was a conflict between UAC and Trend Micro Internet Security 2007.  After <a href="http://esupport.trendmicro.com/support/viewxml.do?ContentID=EN-1036026&amp;id=EN-1036026">some discussion about it, they received this e-mail</a> from Trend Micro&#8217;s support team:</p>
<blockquote><p>Dear Lexonex,<br />
Hello there! A pleasant day to you! My name is John from Consumer Escalation Team and I will be assisting you on this issue. To keep our records up-to-date, it is very important to RESPOND to this e-mail.</p>
<p>I have carefully read your email and have understood your concern.<br />
Regarding Turning-off User Account Cotrol of WIndows Vista. This feature of Windows Vista is the same as the Suspicious Software Alarm System of Trend Micro Internet Security 2007. Turning-it off really does not harm your computer since you have this kind of feature working in your Trend Micro program. It even allows you not to have that annoying pop-up each time you install or open other programs.</p>
<p>Right-now we don&#8217;t have any information yet if there will be a patch for that problem since it&#8217;s really about WIndows Vista&#8217;s permissions on the programs running in your computer. It&#8217;s like Trend Micro not being allowed by Windows Vista to work normally. And for the feature to run, it&#8217;s either we turn-off User Account Control or set some exceptions for other programs in User Account Control which right-now; WIndows&#8217; Vista does not give an option.</p>
<p>If ever a patch should be created for this problem, it should be a patch from Microsoft so they can allow valid programs to run normally when User Account Control is on.</p>
<p>But we are not closing our options and are still testing if there is a way that the whole Trend Micro program as a whole can be permitted by WIndows Vista to run normally.<br />
I hope I have answered your inquiries clearly.<br />
I will patiently wait for your reply.<br />
Please let me know if I can close this case already.<br />
VERY IMPORTANT: In order for me to have a history of our correspondence, please do not delete the subject and the contents of this email.<br />
Hope this proves useful and have a nice day<br />
Best Regards,<br />
Consumer Support Team<br />
TrendLabs HQ, Trend Micro Incorporated</p>
<p><strong>Apr 12 2007, 04:12 AM </strong></p></blockquote>
<p>Did he really just say that?!?  Let&#8217;s count the problems with this message:</p>
<ol>
<li>Turning off UAC has a <strong>substantial</strong> impact on your PC security.</li>
<li>Trend Micro&#8217;s &#8220;Suspicious Software Alarm&#8221; is nothing like UAC.  It doesn&#8217;t even have the same goal!  That feature, as its name implies, is about preventing malware from getting on your machine.  <a href="http://esupport.trendmicro.com/support/viewxml.do?ContentID=EN-1036026&amp;id=EN-1036026">UAC has nothing to do with malware.</a></li>
<li>It&#8217;s impossible for a third-party application or service to do what UAC does.</li>
<li>He blames their crappy software design on Vista!  If their developers think this way, you should run as fast you possibly can <strong>away from Trend Micro</strong>.</li>
<li>Every other virus scanner developer has gotten along just fine with UAC.  You know, because they actually know how to write software. </li>
<li>&#8220;Either we turn off UAC or set some exception&#8221; &#8211; you don&#8217;t set any exceptions!!! You show an elevation dialog.  Or you run as a service like everybody else.  If your virus scanner is running in user mode, you&#8217;ve already failed.</li>
</ol>
<p><strong>Update: </strong>Now it&#8217;s been nearly a year since that e-mail was sent.  Have they fixed the problem?  It doesn&#8217;t look like it.  They still tell you the same thing <a href="http://esupport.trendmicro.com/support/viewxml.do?ContentID=EN-1036026&amp;id=EN-1036026">on their knowledge base site!</a></p>
<p>My advice?  Get OneCare, AVG, eTrust, or another offering.  Just make sure it&#8217;s from someone who understands security and software development.</p>
]]></content:encoded>
			<wfw:commentRss>http://brandonlive.com/2008/03/23/dont-trust-trend-micro-with-your-pc-security/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
		</item>
		<item>
		<title>UAC to the rescue!</title>
		<link>http://brandonlive.com/2007/04/01/uac-to-the-rescue/</link>
		<comments>http://brandonlive.com/2007/04/01/uac-to-the-rescue/#comments</comments>
		<pubDate>Mon, 02 Apr 2007 06:47:28 +0000</pubDate>
		<dc:creator>Brandon</dc:creator>
				<category><![CDATA[Microsoft]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Windows Vista]]></category>

		<guid isPermaLink="false">http://brandonlive.com/2007/04/01/uac-to-the-rescue/</guid>
		<description><![CDATA[Windows Vista&#8217;s new User Account Control is already earning its keep!  New attacks were reported this weekend that take advantage of a vulnerability in how Windows handles animated mouse cursors.  A patch is due out tomorrow (apparently it&#8217;s been pushed up from an original April 10th release date).  The patch will address the issue on XP [...]]]></description>
			<content:encoded><![CDATA[<p>Windows Vista&#8217;s new User Account Control is already earning its keep!  New attacks were reported this weekend that take advantage of a <a href="http://www.microsoft.com/technet/security/advisory/935423.mspx">vulnerability in how Windows handles animated mouse cursors</a>.  A patch is due out tomorrow (apparently it&#8217;s been pushed up from an original April 10th release date).  The patch will address the issue on XP and on Vista.  Yes, the vulnerability exists on Vista.  And yet, most Vista users are protected from these attacks already.</p>
<p>That is, assuming they have UAC enabled and are using IE7.  On Windows Vista with UAC enabled, Internet Explorer runs in &#8220;Protected Mode&#8221; which successfully protects you from all known web-based attacks that use this vulnerability.  How does it do that?  Basically, &#8220;Protected Mode&#8221; runs IE in a &#8220;sandbox&#8221; of sorts, and doesn&#8217;t allow it to access anything but its own files and registry keys.  If an attacker can successfully inject code into your web browser, and the browser is running in Protected Mode (also known as the &#8220;low&#8221; UAC integrity level) &#8211; that code is prevented from doing any harm.</p>
<p>To all the UAC naysayers &#8211; this is certainly only the first of many examples proving its value (especially it&#8217;s use in IE&#8217;s Protected Mode).</p>
]]></content:encoded>
			<wfw:commentRss>http://brandonlive.com/2007/04/01/uac-to-the-rescue/feed/</wfw:commentRss>
		<slash:comments>8</slash:comments>
		</item>
		<item>
		<title>More secure way to disable UAC.  Without losing Protected Mode IE</title>
		<link>http://brandonlive.com/2007/02/06/more-secure-way-to-disable-uac-without-losing-protected-mode-ie/</link>
		<comments>http://brandonlive.com/2007/02/06/more-secure-way-to-disable-uac-without-losing-protected-mode-ie/#comments</comments>
		<pubDate>Tue, 06 Feb 2007 22:04:59 +0000</pubDate>
		<dc:creator>Brandon</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[Windows Shell]]></category>
		<category><![CDATA[Windows Vista]]></category>

		<guid isPermaLink="false">http://brandonlive.com/2007/02/06/more-secure-way-to-disable-uac-without-losing-protected-mode-ie/</guid>
		<description><![CDATA[Warning:  The default configuration of UAC is far more secure, you should not alter it or turn it off!
Warning #2:  Microsoft does NOT endorse any practice that reduces or disables UAC functionality, and neither do I.  I do NOT use this mechanism on my own machines, and run all of them with UAC completely enabled. 
However, if you&#8217;re [...]]]></description>
			<content:encoded><![CDATA[<p><strong>Warning:  The default configuration of UAC is far more secure, you should not alter it or turn it off!</strong></p>
<p><strong><span style="color: #ff0000;">Warning #2:  Microsoft does NOT endorse any practice that reduces or disables UAC functionality, and neither do I.  I do NOT use this mechanism on my own machines, and run all of them with UAC completely enabled.</span></strong> </p>
<p>However, if you&#8217;re going to turn it off <em>anyway</em>, at least consider the following&#8230;</p>
<p>There are TWO ways to effectively disable UAC.  They are:</p>
<ol>
<li>Hit the big master switch that disables UAC.  This runs <strong>every</strong> application with admin privileges and access to everything on your system.</li>
<li>Enable the &#8220;Elevate without prompting&#8221; option.  This means requests for elevation <strong>automatically succeed</strong>, no prompt.</li>
</ol>
<p>So how is method #2 different?</p>
<blockquote>
<ul>
<li>Applications will still run with non-Admin privileges unless they request them.</li>
<li>Requests for elevation will succeed automatically.</li>
<li>Filesystem and registry virtualization (ie. the &#8220;sandbox&#8221;) will still be enabled for applications running with low privileges.</li>
<li><strong>Protected Mode IE will still work</strong></li>
</ul>
</blockquote>
<p>You can do it by running <a href="http://brandonlive.com/files/DisableElevationPrompts.html">this reg file</a> which won&#8217;t even require a reboot.  However, it WILL set off the Security Center alert just like completely disabling UAC.  If you had previously disabled UAC using the other method, you will have to re-enable it and reboot first.</p>
<p>So if you currently have UAC disabled, or are going to &#8211; try this instead.  No, it is not nearly as secure as the default setup.  <strong>Remember, any application requesting elevation will get it without telling you</strong>!  But it&#8217;s better than just running with everything elevated all the time. </p>
]]></content:encoded>
			<wfw:commentRss>http://brandonlive.com/2007/02/06/more-secure-way-to-disable-uac-without-losing-protected-mode-ie/feed/</wfw:commentRss>
		<slash:comments>17</slash:comments>
		</item>
		<item>
		<title>Vista Myths:  &#8220;Users will just click OK&#8221;</title>
		<link>http://brandonlive.com/2007/01/31/vista-myths-users-will-just-click-ok/</link>
		<comments>http://brandonlive.com/2007/01/31/vista-myths-users-will-just-click-ok/#comments</comments>
		<pubDate>Wed, 31 Jan 2007 21:29:46 +0000</pubDate>
		<dc:creator>Brandon</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[Windows Vista]]></category>

		<guid isPermaLink="false">http://brandonlive.com/2007/01/31/vista-myths-users-will-just-click-ok/</guid>
		<description><![CDATA[Today I&#8217;d like to dispel a myth about Windows Vista which says that User Account Control (UAC) will not protect users because they will just click &#8220;Continue&#8221; or &#8220;Allow&#8221; on the dialogs that ask them for permission for an application to run with Administrator privileges.
Is it a problem that users are often too willing to click [...]]]></description>
			<content:encoded><![CDATA[<p>Today I&#8217;d like to dispel a myth about Windows Vista which says that User Account Control (UAC) will not protect users because they will just click &#8220;Continue&#8221; or &#8220;Allow&#8221; on the dialogs that ask them for permission for an application to run with Administrator privileges.</p>
<p>Is it a problem that users are often too willing to click Allow or Continue buttons without knowing the full consequences of their action?  Certainly.  Please don&#8217;t think I am contending otherwise.  However, consider the following scenario:</p>
<ol>
<li>Joe User starts up his Windows Vista machine and logs into an Administrator account with UAC enabled.</li>
<li>Joe opens up Mail Program Express* &#8211; which automatically runs with reduced privileges because of UAC.</li>
<li>Joe clicks on a malicious HTML e-mail message that triggers a buffer overrun exploit against Mail Program Express, which executes some malicious code.  Perhaps this code includes instructions to delete important system files, muck with the registry, or access sensitive information about your computer or other users of the machine.</li>
<li>The attack against Mail Program Express succeeds, and the code is run &#8211; but the code fails to have any impact on the system because it is running in the context of Mail Program Express &#8211; which does not have Administrator privileges.</li>
</ol>
<p>At no point during this example is a UAC dialog thrown. </p>
<p>Could a more sophisticated attack cause an attempt at privilege escalation?  Depending on the nature of the attack, it&#8217;s possible.  But in such a case, the user would be presented with a UAC dialog completely out-of-the-blue.  It would probably be an unsigned app (scarier dialog), and the user would probably say no.</p>
<p>So what does this mean?  It means that UAC is a lot more than just another warning dialog.  Don&#8217;t turn it off.  It just might save you a lot of heartache one day.</p>
<p><span style="font-size: xx-small;">* this could be any benign application you use daily, especially internet-connected ones like mail readers, web browsers, chat clients, etc. </span></p>
]]></content:encoded>
			<wfw:commentRss>http://brandonlive.com/2007/01/31/vista-myths-users-will-just-click-ok/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
	</channel>
</rss>
