Thursday, December 28, 2006

Vista: Secure but not perfect

Last week's disclosure of a zero-day vulnerability in Windows Vista doesn't put a lie to the claim that it's the safest Microsoft operating system so far, a company security manager has said.

"The finding of vulnerabilities in any software is to be expected," said Stephen Toulouse, senior product manager with Microsoft's security technology group, in a blog posting earlier this week. "This is all part of the process of creating complex software today, and no one is immune to it. It's not, as they say, big news to us in the security industry."

Proof-of-concept code for an unpatched bug in all supported versions of Windows, including Vista, went public last week, prompting warnings from security vendors who classified the flaw as a low or medium threat. Microsoft has said it was "closely monitoring" the situation, but has not released any additional information since Dec. 22.

Toulouse countered that the exploit doesn't invalidate Microsoft's contention that Vista is more secure than its predecessor, Windows XP. "This product [is] the most secure version of Windows we've produced to date. That doesn't mean 'zero vulnerabilities.' No one can claim that crown," he added.

He also predicted that users would see more vulnerabilities early in Vista's lifespan than in previous versions of Windows. "We're probably going to see a higher initial rate of reported vulnerabilities to us than with previous versions of our products, given the early view researchers have had into Vista," Toulouse said. "This is going to help make the product stronger before many of the threats against it have a chance to emerge."

Other Microsoft executives, including Jim Allchin, the soon-to-retire head of the Windows unit, and chief executive Steve Ballmer, have repeatedly said that Vista will prove to be the most secure Windows yet. Like Toulouse, Allchin also has noted that no software can be considered 100% safe.

Said Toulouse: "No one will ever get the software right 100% out of the gate."

Wednesday, December 27, 2006

Nintendo offers to replace Wii straps


Nintendo today offered to replace 3.2m of the straps fixed to the controllers on its new Wii computer games console.

The Japanese games giant made the costly move following a string of reports that damage was being caused by the wand-like controllers flying out of the grasp of gamers.

The wireless controllers, which mimic the motions of a tennis racket or sword depending on the game being played, have helped the £179 console become a top seller this Christmas.

However, there has been an increasing number of reports that controllers had flown out of the hands of overzealous players. Numerous players reported suffering injuries or accidentally throwing their controller at the person they were playing with.

Videos on YouTube show players suffering mishaps with the controllers - or "wiinjuries", as they have become known by some.

Nintendo today said it would allow customers to exchange the current straps for a thicker, more robust version on request. The old straps have a diameter of 0.6mm, and the new versions will be 1mm in diameter, Yasuhiro Minagawa, a company spokesman, said.

Games players have always been advised to use the strap. Today, however, the firm also issued new guidance on using the innovative controllers, warning people not to make "excessively rapid, violent or wide swinging motions" while using them.

It also advised gamers to stay at least one metre away from their televisions and ensure their hands were not "sweaty or wet".

"People tended to get a bit excited, especially while playing Wii sports, and in some cases the control would come loose from their hands," Mr Minagawa said. "The new strap will be almost twice as thick."

The pledge to replace the straps could cost Nintendo millions of pounds - a costly hitch in its three-way battle with Sony's PlayStation 3 and Microsoft's Xbox 360 in the "next generation" console market.

However, stories about Wii controllers crashing into television monitors have not had a negative impact on sales.

More than 300,000 of the machines have been sold in Europe, and the Wii sold out in less than 24 hours after going sale in the UK last week. US customers bought 476,000 Wiis in the two weeks following its release there on November 17.

Tuesday, December 26, 2006

Can You Really Trust Certified Sites?

Web sites that feature the TRUSTe security Relevant Products/Services certificate are two times more likely to contain badware than Web sites without any security certification, spyware and adware researcher Ben Edelman alleges in a new report.

Among others, adware providers Direct-revenue and Webhancer are using TRUSTe certificates in an attempt to look more trustworthy than they really are, Edelman claimed. Direct-revenue is facing legal action from the New York Attorney General for its adware software. Edelman alleged that Webhancer often is installed without the user's consent.

TRUSTe is a so-called certification authority, an independent organization that issues security certificates to Web sites. These certificates indicate that service adheres to certain privacy guidelines, allowing users to verify that they are on the Web site that they intended to visit.

The independent certificate authorities perform a background check to verify the identity of the Web site's operator and ensure compliance with the privacy standards. Web sites that meet the organization's criteria are allowed to display the TRUSTe logo on their Web site.

The perceived trustworthiness of a certified Web site makes such certificates an attractive target for Web sites pushing malware Relevant Products/Services and adware.

In his study, Edelman compared TRUSTe certified Web sites with a list of known malware sites from McAfee's Siteadvisor product, a service that black-lists Web sites containing spyware, spam, viruses and online scams.

Using a base sample of a 500,000 Web sites, Edelman determined the number of sites have TRUSTe certification and cross-checked those against the McAfee list. Edelman found that 5.4 per cent of the TRUSTe sites were considered untrustworthy. Only 2.5 per cent of the sites from the base sample were blacklisted in Siteadvisor.

Edelman alleges that TRUSTe has no incentive to properly verify compliance with privacy standards.