Showing posts with label browsing. Show all posts
Showing posts with label browsing. Show all posts

Thursday, August 2, 2012

Software Updates, why should I bother?


Why Update
Usually Software updates are released for four reasons:
  1. Patch a security vulnerability; 
  2. Fix bugs;
  3. Add new features;
  4. Pure marketing purposes.
Staying away from the fourth reason, I believe that the most important aspect to apply a software update is to patch security vulnerabilities. Hackers do exploit these security vulnerabilities in order to gain access to your workstation and ultimately compromise your confidential data (passwords, emails, bank accounts).
Usually, when any software is being created it goes through series of phases within its development life cycle (SDLC). Two important parts of this life cycle are quality assurance and user acceptance testing. Yet the best testing any software could get is the Wild Testing.
Wild testing is done when vendors release their software un-officially (leaks, test or evaluation versions) to be tested and reviewed by enthusiastic users.
When these users submit their feedback directly to the vendor or share their experience using social networking media such as Facebook and twitter or even write a detailed review on Cnet they are able to draw the software vendor / developer attention. The developer consequently fixes the problems reported. And therefore a bug free update is released.
Sometimes, the term software update is used instead of software upgrade, this happens when the developer company releases a new version of their software with added features that is didn’t exist in the previous release.  
Most software nowadays, given the proper permission from their operator, has the ability to periodically and automatically check for updates. Moreover you as an operator can configure this software to download and install updated seamlessly and on recurrent basis, without any further more intervention from your part.

Four Software updates that shouldn’t be missed:

1. Operating Systems
Operating systems provide a software platform on top of which other programs, called application programs, can run, examples of operating systems include windows 7, windows XP, ubentu, fedora, snow leopard, Lion, and most recently mountain lion released by apple a week ago.
Vulnerabilities are discovered within an operating system on daily basis, the vendor of that operating system tries to mitigate these vulnerabilities by releasing patches. Since these patches should be able to save the day, you should install updates as soon as you see a prompt to do so, or set the computer to install them automatically.

2. Web Browsers and Supporting Software
Since the internet service and browsing experience is always evolving the ability to keep your data secure becomes a greater challenge. Microsoft’s Internet Explorer and Apple ‘s Safari are updated the same way an operating system is updated, while Google’s Chrome and Mozilla Firefox are updated automatically. 
For an ultimate user experience, web browsers need supporting packages like Adobe Flash, Adobe Reader, Sun Java and Microsoft Silverlight. And therefore due to their popularity, they are often the target of malicious attackers. It is extremely essential to update these type of software as soon as you see an alert.

3. End User Applications
Every now and then applications downloaded from the internet inform their user than a newer software update is released and ready to be downloaded and installed. These software updates are there either to fix bugs within the application or to offer brand new feature: perhaps a new graphical user interface or even better processing speed. Keep in mind that although these updates may not be mandatory, but sometimes these updates fix undisclosed security vulnerabilities within the application. So whenever an application prompts you for an update. Go ahead and do it.


4. Anti-Virus/Anti-Malware Software
New threats are introduced to the information technology field every day. And so, in order immune your PC against these threats you should keep your Anti-Virus/Anti-Malware updated. Usually these protection software update themselves seamlessly without any user intervention. 





Finally, keeping all the software installed on your PC updated can sometimes be hectic, but if you consider the risks you are mitigating, it is definitely worth the hassle

Thursday, April 19, 2012

Certified and Validated

In this post, I will elaborate more on HTTPS. We previously discussed the term phishing in this blog. To summarize, phishing is an attempt to manipulate or trick a person into providing confidential information to an individual that is not authorized to receive such information. To protect yourself from phishing, recent web browsers have developed a way for checking if a website is valid or not.

Web browsers trust HTTPS websites based on certificate authorities which come pre-installed in their software. Examples of certificate authorities are “Microsoft” and “VeriSign”. In the example below, the bank's web site is verified by "VeriSign, Inc."

Always look for the green address bar. Recent web browsers show a green address bar in order to tell the user that this web site is legit and trustworthy. Its purpose is to give more confidence to the user and ensure them that they are visiting a trusted web site.

This issue plays an important role in Information Security. Next time you visit a web site make sure you look for the green address, especially web sites that ask for important and private information and web sites for payment transactions. To reassure yourself, check the certificate to know if this site is validated.

Saturday, April 14, 2012

Cookies, should we really like them

What are Cookies?
Cookies are small, mostly circular pieces of sweets, that are fun to... Oops Sorry!

Cookies are small, often encrypted text files that are stored silently on a user's computer. These files are designed to carry a little amount of data specific to a particular client and website. Cookies are automatically created when a browser loads a website, allowing a server to deliver a custom made page to a particular user every time this user goes back to the same website.

Cookies Expiry Periods
The expiry time of a cookie is assigned when the cookie is originally created. Some cookies are deleted or purged when the current browser window is closed (Session cookie), but others can be made to last for a longer period of time (Persistent cookie). Yet some can last for one year or even more.

Are Cookies Secure enough?
Internet security and privacy is of huge concern. Cookies do not in themselves present a threat to privacy, since they can only be used to store information that the user has volunteered or that the web server already has. But the existence of cookies poses an inherent risk of being abused

Cookies are NOT viruses, nor are they malicious; using a plain text format, they are not compiled pieces of code so they cannot be executed nor are they self-executing. Accordingly, they cannot make copies of themselves and spread to other networks to execute and replicate again. Unable to perform these functions, they are not classified as Malware. However, breaches of browser security can allow tracking cookies to be placed. These cookies can be used to follow users from one site to another, forming comprehensive profiles. Users consider this to be a violation of privacy, and in the wrong hands this information can potentially be exploited for questionable purposes. For that reason several anti-malware products flag cookies as candidates for deletion after standard virus and/or spyware scans.

Cookies can be exploited
Several malicious activities could be associated with the existence of cookies much like: Network eavesdropping, publishing false sub-domain – DNS cache poisoning, and Cross-site scripting. (More on these attacks in later posts)

Traffic on a network can be intercepted and read by computers on the network other than the originator (Especially over unencrypted open Wi-Fi). This traffic includes cookies sent on ordinary unencrypted HTTP sessions. When network traffic is not encrypted, attackers can read the communications of other users on the network, including HTTP cookies as well as the entire contents of the conversations.

How to live with cookies
Due to the fact that many of the largest and most-targeted websites use cookies by default, cookies usage is almost inevitable. Websites like Facebook, YouTube, Gmail, and many others require the usage of cookies for best performance and presentation. Even search settings require cookies for language settings.

Here are some tips you can use to ensure worry-free cookie-based browsing:
  • Most modern browsers support different levels of cookie acceptance, expiration time and ultimately deletion. Change your browser settings “Cookie Settings” to your preference.
  • When sharing PC access, you should make sure to set your browser to purge browsing data every time the browser is closed.
  • Don’t use other's / Public wireless networks especially when communicating sensitive information over the internet.
  • Use Https rather than Http when available.
  • Use a capable and updated anti-malware software.
  • Routinely back-up your computer to prevent data loss.
  • Make sure your browser is updated: security patches are applied when you update your browser.
Finally you should acknowledge that Cookies are widely used and can't really be avoided. If you wish to enjoy your internet surfing experience by navigating to “cookie creating websites” you should have a clear understanding of how cookies operate, and how to protect them from being abused. After all you are responsible of taking the necessary security measures to ensure your information security.