Microsoft Outlook Support

  • Subscribe to our RSS feed.
  • Twitter
  • StumbleUpon
  • Reddit
  • Facebook
  • Digg

Wednesday, 20 January 2010

German Government advice on web security not optimal

Posted on 10:23 by Unknown

Trusteer says German Government advice on web security not optimal

by Michael Smith (Veshengro) (with material from Eskenzi PR)

London, January, 2009 – Reports that the German government has advised Internet users not to use Internet Explorer may not be the optimum solution to the problem of Web browser security, says Trusteer, the customer protection company for online businesses.

"The German government appears to be taking a knee-jerk reaction to reports that hackers have been exploiting an IE security weakness, but the problem is that, even if users switch to another Web browser, they are still likely to encounter similar potential security problems,” said Mickey Boodaei, Trusteer's CEO.

"What is really needed is a high security - but light-weight – browser security service that creates a secure environment between the users' keyboard and the Web site, so preventing man-in-the-middle, man-in-the-browser, phishing and similar attack methodologies," he added.

According to Boodaei - whose company has a number of prestigious banking clients whose customers use the firm's security technology to protect their online banking sessions - the German saga is in danger of descending into a war of words between the regulators and Microsoft, leaving Internet users to fend for themselves on the security front.

Browser vulnerabilities will keep cropping up, and as such the concept of perimeter defense for the consumer's PC are not realistic. The German government, he said, should really be working to help Internet users make their Web banking sessions more secure, rather than steering users towards alternative browser software which may also have its fair share of security vulnerabilities.

The problem, he explained, is that most Web browsers have vulnerabilities, in the same way that a regular telephone handset has potential for eavesdropping. What is needed is a technology - which is already available in the marketplace - to make the communication session more secure, rather than simply advising users to switch devices.

Trusteer's CEO went on to say that most of the vulnerabilities that his company hears about are discovered by researchers and then patched by the vendor, before being published. The problem is that, however, just like white hat security researchers, criminals have their own research activities and they find vulnerabilities which obviously they don't share with the vendors. And, he says, when they start exploiting one of these vulnerabilities, this is when it becomes a zero-day attack like the one used with Google.

"It's against this backdrop that we think Internet users need to understand that Firefox is actually not more secure than Internet Explorer. There are no significant architectural differences between the two browsers that would make Firefox less vulnerable," he said.

"Owing to its higher market profile, IE is tested more than other browsers by both the security and the criminal communities, resulting in more vulnerabilities being discovered. It's therefore important that the regulators understand this, and advise users accordingly," he added.

“If the German Government is advising on browser security will they next be telling Germans that they should not use adobe or flash as there are inherent risks and vulnerabilities in many widely used programs not just internet explorer?” he concluded.

For more on the German government IE advisory: http://bit.ly/72MdGW

For more on Trusteer: http://www.trusteer.com

Rapport from Trusteer is a lightweight browser plug-in plus security service that acts like a vault inside the browser and prevents redirection of user information to fraudulent websites. It protects personally identifiable information (PII) and Web pages from unauthorized access and theft while users are accessing sensitive Web sites. Trusteer also offers in-the-cloud reporting services where unauthorized access attempts detected by Rapport are analyzed by fraud experts who provide actionable intelligence to financial institutions.

Trusteer enables online businesses to secure communications with their customers over the Internet and protect PII from a user's keyboard into the company's Web site. Trusteer's flagship product, Rapport, allows online banks, brokerages, healthcare providers, and retailers to protect their customers from identity theft and financial fraud. Unlike conventional approaches to Web security, Rapport protects users' PII even if their computer is infected with malware including Trojans and keyloggers, or is victimized by pharming or phishing attacks. Trusteer is a privately held corporation led by former executives from Cyota/RSA Security, Imperva, and NetScreen/Juniper. For more information visit www.trusteer.com.

Personally, I must say that some companies are rather disingenuous when they make claims about Firefox being no more secure than Internet Explorer. The truth, from experts and normal users, is that Firefox is much more secure, and even more so if and when certain kinds of free and open-source plug-ins are being provided, installed and used.

Too many vendors, and this can be seen again and again, are too much in the pockets of the people in Redmond and cannot not, therefore, be seen as unbiased and neither are they. Rather the opposite and this can be seen time and again and in many different situations.

This is the same when the attacks are being led by many such vendors and companies against Open Source software, whether they be operating systems such as Linux, or simply applications such as Open Office, the GIMP and others. Understandably, in a way, as most Open Source, if not indeed all, is free at the point of take up. Something that those who make a living from writing software for a fee and selling proprietary software are dead against, it would seem, and hence the negative attitude.

Yes, there are problems with other browsers too and with Open Source software, including the likes of Ubuntu Linux and others but maybe the proprietary software vendors and companies might like to remember that it took just a few seconds for hackers to crack the latest Apple OS not so long ago, a couple of minutes for Vista but had to give up after a number of days on Ubuntu.

I rest my case.

© 2010

Email ThisBlogThis!Share to XShare to FacebookShare to Pinterest
Posted in | No comments
Newer Post Older Post Home

0 comments:

Post a Comment

Subscribe to: Post Comments (Atom)

Popular Posts

  • DDoS-Attacks disable many shopping websites, including Amazon
    Just in time for last minute Christmas shopping major shopping sites disabled by Michael Smith (Veshengro) London, December 26, 2009: An...
  • Open Source Software in Business & Government
    by Michael Smith (Veshengro) Lots of Open Source in use in mainland Europe, including EU member states, very little in the UK and less still...
  • Cyber-Ark Expands RSA Secured Partner Program Certification Status
    Cyber-Ark Privileged Identity Management Suite, Inter-Business Vault and Sensitive Document Vault Now Formally Interoperable with RSA enVisi...
  • Infosecurity Adviser applauds forensics lab training facilities at key UK university
    London, UK. May 2009: Infosecurity Adviser, Infosecurity Europe’s online community for the information security industry, has published a r...
  • Scientific company discusses simultaneously protecting applications and data
    Simultaneously protecting applications and data: The next evolution in security? September 2009 (Eskenzi PR) – In a recent Imperva podcast...
  • TUFIN TECHNOLOGIES WINS the PRESTIGIOUS 2010 Computing Security Award for ‘Best bench tested solution of the Year’
    Network Computing and Computing Security Magazine Editors Select Tufin’s SecureChange Workflow as the Top Product Reviewed in 2010 Londo...
  • Brocade Service Could Help Reduce Billions in Data Centre Operations Costs
    New Energy Efficiency Review provides holistic assessment and remedial strategies to help companies optimise efficiency and reduce costs Ene...
  • Infosecurity Europe 2011 Hall of Fame nominations now open
    London UK, February  2011 – The time is ripe to elevate the greatest movers and shakers in the world of information security as nominations ...
  • Tufin survey reveals the truth about fudging audits, IT cost cutting and buying equipment online
    Ramat Gan, Israel – May 27, 2009 – Tufin Technologies today announced the results of its “Reality Bytes” security survey. The survey parti...
  • ISACA’s EuroCACS Conference Demystifies the Cloud
    Event for IT Professionals Will Take Place 20-23 March, Manchester London, England, (8 th March 2011)— Global business and information ...

Categories

  • ASUS
  • AVG Link Scanner
  • BeCrypt
  • book review
  • Brocade
  • Codenomicon
  • Columbian USB stick loss
  • computer recycling
  • Conficker worm
  • Credant Technologies
  • cyber crime
  • Cyber-Ark
  • Cyber-Ark®
  • Data Center
  • data encryption
  • DeviceLock
  • Digital Pathways
  • diskGenie
  • Eclypt
  • Eee PC
  • Eee PC Seashell 1008HA
  • F5 Networks
  • Facebook
  • Finjan
  • Finjan Inc.
  • Finjan MCRC
  • Firewall Management
  • Fortify
  • Fortify 360
  • Fortify Software
  • Fortify® Software
  • gadgets
  • Google
  • Google Chrome
  • green computing
  • green IT
  • IBM
  • Infosec
  • Infosec Europe 2009
  • Infosecurity Adviser
  • Infosecurity Europe
  • Infosecurity Europe 2009
  • Internet privacy
  • iStorage
  • iStorage diskGenie
  • iStorage Ltd.
  • Juniper Networks
  • Lakeland
  • Lapdesk
  • LLC
  • Logitech
  • malware
  • ManageEngine
  • McAfee International Ltd
  • MI6
  • MI6 data loss
  • Microsoft
  • MiFi™ 2352
  • Mio
  • Mobile Broadband
  • MS Office
  • National Cybersecurity Advisor
  • Navman
  • Navman Spirit
  • Netac
  • Novatel
  • Novatel Wireless Intelligent Mobile Hotspot 2352
  • OneClick IntelliPanel Desktop
  • online social media
  • open source
  • OpenOffice.org
  • Optenet
  • Origin Data Locker
  • Origin Storage
  • PNDs
  • product review
  • Red
  • SaaS
  • Sat Nav
  • saving energy
  • Security
  • Shavlik Technologies
  • SIS
  • spam
  • Stonewood Group
  • Storage Area Networks
  • Storage Expo
  • Storage Expo 2009
  • Sun Microsystems
  • Swine Flu
  • Syphan Technologies
  • Throwing Sheep in the Boardroom
  • Tufin Technologies
  • Twitter
  • U256
  • Unisys Security Index
  • USB drives
  • Vektor
  • VisionRacer
  • VisionRacer VR3
  • VMware
  • Weast
  • Web Apps Security
  • WebFilter PC Solution
  • WebSpy
  • XSS-driven attacks

Blog Archive

  • ►  2012 (1)
    • ►  January (1)
  • ►  2011 (67)
    • ►  December (1)
    • ►  April (1)
    • ►  March (14)
    • ►  February (30)
    • ►  January (21)
  • ▼  2010 (192)
    • ►  December (20)
    • ►  November (22)
    • ►  October (19)
    • ►  September (5)
    • ►  August (8)
    • ►  July (5)
    • ►  June (22)
    • ►  May (13)
    • ►  April (11)
    • ►  March (13)
    • ►  February (27)
    • ▼  January (27)
      • Novatel Wireless Announces Successful HSPA+ Dual-C...
      • Origin says Swiss Army encryption challenge worth ...
      • RockYou hack reveals world's most popular passwords
      • FalconStor® FDS Version 2.0 Delivers Enterprise-Cl...
      • Data hung out to dry as 4,500 USBs are left in Dry...
      • 8,378 reasons for better banking security
      • MiFi security weakness highlights need for code au...
      • CTO Doubts Internet Explorer Vulnerability Was Beh...
      • New Security Score Offers Snapshot of Firewall Ris...
      • 360°IT Event gives thumbs up on IBM/Panasonic clou...
      • Lighting Down the Line
      • German Government advice on web security not optimal
      • Oaklee Housing Association protect sensitive data ...
      • False Advertising by Vodaphone
      • Time for multi-factor security on portable data as...
      • Cyber-Ark Labs launched to combat emerging threats...
      • Where Does the Ownership Lie?
      • Creating uniform security across the police force
      • Modified portable devices create significant secur...
      • Serious SQL flaw could have compromised millions
      • Logitech Speaker Lapdesk N700 Brings the Cinema Home
      • Did Santa bring you a Netbook?
      • Police force computer misuse investigation "no sur...
      • Companies advised to code audit open source applic...
      • Securing Web 2.0 in the workplace
      • Kingston Datatraveler security flaws highlight nee...
      • Credant says MoD laptop theft highlights dangers o...
  • ►  2009 (240)
    • ►  December (25)
    • ►  November (9)
    • ►  October (21)
    • ►  September (19)
    • ►  August (30)
    • ►  July (35)
    • ►  June (30)
    • ►  May (21)
    • ►  April (42)
    • ►  March (8)
Powered by Blogger.

About Me

Unknown
View my complete profile