Profile

unixronin: Galen the technomage, from Babylon 5: Crusade (Default)
Unixronin

December 2012

S M T W T F S
      1
2345678
9101112131415
16171819202122
23242526272829
3031     

Most Popular Tags

Expand Cut Tags

No cut tags
Tuesday, August 9th, 2005 04:43 pm

eWeek reports discovery of a massive ID theft ring powered by CoolWebSearch.  Yeah, only Windows is vulnerable -- anyone surprised?  ....No?  Didn't think so.  Why people put up with this shit is beyond me, let alone why people who surely KNOW how dangerous it is running around out there with an insecure OS will still just click on this shit and install it with no idea what it's actually doing and in the knowledge that they have no way to find out.  Sometimes I wish one of these crooks would come along and clean out forty million people's bank accounts, just because I can't help but think it'll take something on that scale to get people's attention.

Trend Micro has a free online scanner that will detect and remove CoolWebSearch.  Then again, anyone stupid enough to install a piece of untrusted code like that in this day and age probably isn't reading, or paying any attention to, this anyway.


Footnote:  I don't particularly wish Microsoft would crash and burn.  I don't particularly wish Windows would dry up and blow away in the wind.  Not only are Unix and the Mac not for everyone, but a monoculture of ANYTHING is a bad.  I just wish Microsoft would start taking security seriously and actually make a real effort to make Windows secure.  I've heard some intimations Longhorn Vista may finally make some progress in that direction, provided that doesn't get dropped before release as well.

Tuesday, August 9th, 2005 04:22 pm (UTC)
Yeah .... that, IMHO, is another failing of Windows: It's too easy for an unprivileged user to screw it up, in ways ranging from trivial to catastrophic.
Tuesday, August 9th, 2005 05:08 pm (UTC)
I'm responding to this comment in part because I want all three of the other commenters to see this in email and this is the only one that has you all in a chain. Also, it addresses the specific comment it is in reply to.

As a Microsoft employee, there are limits to what I can say without breaching corporate confidentiality rules but what I can tell you is that Microsoft really is making very large changes to its culture with regard to security. It has been going on for several years now, and it continues to progress. We have made fundamental, and I mean *really* fundamental changes to our processes to incorporate security into the development, testing, and distribution of our products. Windows Server 2003 is the most secure OS we've put out and the stats prove it.

We also have this guy (http://blogs.msdn.com/michael_howard/) working for us. Perhaps you've heard of a little book he wrote called "Writing Secure Code." () He, along with a team of very very smart people are dedicated full-time to making sure that we don't repeat the mistakes of the past. Yeah, some things will always get through, but that's going to happen to everyone, not just Microsoft.

As for the unprivileged user messing up the OS, Windows Vista is going to have some *significant* changes which will go a very long way toward preventing that kind of problem. Actually, the problem with XP is not that an unprivileged user can screw up the system; a "regular" user actually can't. It's that running as a regular user makes it hard to do a lot of things that you want to do, such as setting the system date and time or even set up a game to play. Therefore a lot of people run with Administrator privileges all the time. Vista will solve a lot of these problems. I don't know how much of this is public knowledge yet, so I'll stop here.
Tuesday, August 9th, 2005 05:16 pm (UTC)
This sounds really positive. Thanks for going out on a limb and posting it.
Tuesday, August 9th, 2005 05:27 pm (UTC)
Just figured out what's wrong with that Amazon link.

s/a ref=/a href=/