<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	xmlns:georss="http://www.georss.org/georss" xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#" xmlns:media="http://search.yahoo.com/mrss/"
	>

<channel>
	<title>Secure IT Foundation</title>
	<atom:link href="http://secureitfoundation.wordpress.com/feed/" rel="self" type="application/rss+xml" />
	<link>http://secureitfoundation.wordpress.com</link>
	<description>Security for all</description>
	<lastBuildDate>Wed, 25 Jan 2012 14:11:29 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.com/</generator>
<cloud domain='secureitfoundation.wordpress.com' port='80' path='/?rsscloud=notify' registerProcedure='' protocol='http-post' />
<image>
		<url>http://s2.wp.com/i/buttonw-com.png</url>
		<title>Secure IT Foundation</title>
		<link>http://secureitfoundation.wordpress.com</link>
	</image>
	<atom:link rel="search" type="application/opensearchdescription+xml" href="http://secureitfoundation.wordpress.com/osd.xml" title="Secure IT Foundation" />
	<atom:link rel='hub' href='http://secureitfoundation.wordpress.com/?pushpress=hub'/>
		<item>
		<title>HUD = Horrible Ubuntu Design</title>
		<link>http://secureitfoundation.wordpress.com/2012/01/25/hud-horrible-ubuntu-design/</link>
		<comments>http://secureitfoundation.wordpress.com/2012/01/25/hud-horrible-ubuntu-design/#comments</comments>
		<pubDate>Wed, 25 Jan 2012 14:10:20 +0000</pubDate>
		<dc:creator>secureitfoundation</dc:creator>
				<category><![CDATA[Secure IT Foundation Blog]]></category>
		<category><![CDATA[Blog updated]]></category>
		<category><![CDATA[H.U.D.]]></category>
		<category><![CDATA[HUD]]></category>
		<category><![CDATA[Linux]]></category>
		<category><![CDATA[Secure IT Foundation]]></category>
		<category><![CDATA[Ubuntu]]></category>

		<guid isPermaLink="false">http://secureitfoundation.wordpress.com/?p=678</guid>
		<description><![CDATA[Once upon a time, roughly April 2010, there was a Linux operating system called Ubuntu that was on the verge of becoming mainstream for home computers. Easy to use, easy to recommend. Simple clean user interface that only needed 5 minutes training for Windows and OSX users to get going. What happens next appears to [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=secureitfoundation.wordpress.com&amp;blog=7656431&amp;post=678&amp;subd=secureitfoundation&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>Once upon a time, roughly April 2010, there was a Linux operating system called Ubuntu that was on the verge of becoming mainstream for home computers. Easy to use, easy to recommend. Simple clean user interface that only needed 5 minutes training for Windows and OSX users to get going. What happens next appears to down to one of two things&#8230; conspiracy or cock-up.</p>
<p>The conspiracy theory is that other operating system makers placed their own people within the Linux and Ubuntu community to ruin Ubuntu and the immediate future of Linux on the desktop.</p>
<p>The cock-up theory is that the management of Ubuntu are so visionary and looking into the future that they did not see the immediate problems with their track in front of them and just derailed.</p>
<p>Either way, in 2012 the Linux desktop market is so fragmented with multiple versions of Linux that newcomers looking for a stable operating system cannot find anything close to the stability of Windows or OSX and give up reverting to a proprietary operating system, as &#8216;free&#8217; does not mean better to them.</p>
<p>To highlight this Linux problem, the latest Ubuntu feature is to reintroduce typing in the mouse / touch driven menus system. While the rest of the world moves to touch based computers, Ubuntu thinks the future is in typing in a command line to start a program, just like it was still 1982, 10 PRINT &#8220;hello world&#8221;.</p>
<p>Their new &#8216;HUD &#8211; Head Up Display&#8217; can be seen here:</p>
<p><iframe width="480" height="270" src="http://www.youtube.com/embed/w_WW-DHqR3c?fs=1&#038;feature=oembed" frameborder="0" allowfullscreen></iframe></p>
<p>You can almost see their train of thought, converting the HUD into a voice driven system in a few years but reliable fully voice driven computers are still mostly science fiction.</p>
<p>Until we all talk routinely to our computers, our own operating system PrentOS under development will be strictly mouse and keyboard. Touch may be added in the future as it would fit well with our ARM based version but typing commands to start a program will always remain in the geek domain.</p>
<p>init 6 please Ubuntu&#8230;</p>
<p>SecurityBrad</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/secureitfoundation.wordpress.com/678/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/secureitfoundation.wordpress.com/678/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/secureitfoundation.wordpress.com/678/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/secureitfoundation.wordpress.com/678/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/secureitfoundation.wordpress.com/678/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/secureitfoundation.wordpress.com/678/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/secureitfoundation.wordpress.com/678/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/secureitfoundation.wordpress.com/678/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/secureitfoundation.wordpress.com/678/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/secureitfoundation.wordpress.com/678/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/secureitfoundation.wordpress.com/678/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/secureitfoundation.wordpress.com/678/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/secureitfoundation.wordpress.com/678/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/secureitfoundation.wordpress.com/678/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=secureitfoundation.wordpress.com&amp;blog=7656431&amp;post=678&amp;subd=secureitfoundation&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://secureitfoundation.wordpress.com/2012/01/25/hud-horrible-ubuntu-design/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/5d24558eeb6d4c815f56b70d748fb279?s=96&#38;d=http%3A%2F%2Fs0.wp.com%2Fi%2Fmu.gif&#38;r=G" medium="image">
			<media:title type="html">secureitfoundation</media:title>
		</media:content>
	</item>
		<item>
		<title>How to avoid meeting Count Duqu &#8211; Updated</title>
		<link>http://secureitfoundation.wordpress.com/2012/01/04/how-to-avoid-meeting-count-duqu/</link>
		<comments>http://secureitfoundation.wordpress.com/2012/01/04/how-to-avoid-meeting-count-duqu/#comments</comments>
		<pubDate>Wed, 04 Jan 2012 03:25:26 +0000</pubDate>
		<dc:creator>secureitfoundation</dc:creator>
				<category><![CDATA[Secure IT Foundation Blog]]></category>
		<category><![CDATA[Blog updated]]></category>
		<category><![CDATA[Count Duqu Virus]]></category>
		<category><![CDATA[Secure IT Foundation]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Windows]]></category>

		<guid isPermaLink="false">http://secureitfoundation.wordpress.com/?p=674</guid>
		<description><![CDATA[Update  &#8211; 04/01/2012 Microsoft release a proper patch in the December monthly update release, so if you ran the FixIt then ideally you need to run the remove FixIt tool before updating Windows. We did test applying the update over the FixIt and it does appear to work successfully but this is not the Microsoft [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=secureitfoundation.wordpress.com&amp;blog=7656431&amp;post=674&amp;subd=secureitfoundation&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p><strong>Update  &#8211; 04/01/2012</strong></p>
<p>Microsoft release a proper patch in the December monthly update release, so if you ran the <a href="http://support.microsoft.com/kb/2639658" target="_blank">FixIt</a> then ideally you need to run the <a href="http://go.microsoft.com/?linkid=9788942" target="_blank">remove FixIt</a> tool before updating Windows.</p>
<p>We did test applying the update over the FixIt and it does appear to work successfully but this is not the Microsoft recommended approach&#8230;</p>
<p>When you run Windows Update you may notice a new <a href="http://support.microsoft.com/kb/2638420" target="_blank">.Net update</a>. This is a new emergency patch issued by Microsoft for another .net security flaw.</p>
<p>SecurityBrad</p>
<p>&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8211;</p>
<p>You may have heard of a new security problem with all version of Windows, originally identified as a virus called Duqu. What made this virus count is that it uses a previously unknown bug in Windows to install itself.</p>
<p>The Duqu file may come from any source, not just what appears to be a word document as was stated from the initial reports. To protect yourself until there is a proper fix for Windows, Microsoft has made a FixIt, a temporary software plaster, available.</p>
<p>Our advice is to run the <a href="http://support.microsoft.com/kb/2639658" target="_blank">FixIt</a> as soon as possible (Do choose the <a href="http://go.microsoft.com/?linkid=9788941" target="_blank">&#8216;Enable&#8217; FixIt</a>!) and also check that your Anti Virus software is up to date and updated. Eventually a proper fix will be released but that may be too late for some people&#8230;</p>
<p>SecurityBrad</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/secureitfoundation.wordpress.com/674/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/secureitfoundation.wordpress.com/674/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/secureitfoundation.wordpress.com/674/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/secureitfoundation.wordpress.com/674/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/secureitfoundation.wordpress.com/674/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/secureitfoundation.wordpress.com/674/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/secureitfoundation.wordpress.com/674/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/secureitfoundation.wordpress.com/674/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/secureitfoundation.wordpress.com/674/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/secureitfoundation.wordpress.com/674/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/secureitfoundation.wordpress.com/674/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/secureitfoundation.wordpress.com/674/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/secureitfoundation.wordpress.com/674/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/secureitfoundation.wordpress.com/674/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=secureitfoundation.wordpress.com&amp;blog=7656431&amp;post=674&amp;subd=secureitfoundation&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://secureitfoundation.wordpress.com/2012/01/04/how-to-avoid-meeting-count-duqu/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/5d24558eeb6d4c815f56b70d748fb279?s=96&#38;d=http%3A%2F%2Fs0.wp.com%2Fi%2Fmu.gif&#38;r=G" medium="image">
			<media:title type="html">secureitfoundation</media:title>
		</media:content>
	</item>
		<item>
		<title>Toolbars should be called &#8216;Malware&#8217;</title>
		<link>http://secureitfoundation.wordpress.com/2011/10/31/toolbars-are-malware/</link>
		<comments>http://secureitfoundation.wordpress.com/2011/10/31/toolbars-are-malware/#comments</comments>
		<pubDate>Mon, 31 Oct 2011 01:10:37 +0000</pubDate>
		<dc:creator>secureitfoundation</dc:creator>
				<category><![CDATA[Secure IT Foundation Blog]]></category>
		<category><![CDATA[Secure IT Foundation]]></category>
		<category><![CDATA[Blog updated]]></category>
		<category><![CDATA[Personal Security]]></category>
		<category><![CDATA[Toolbar]]></category>
		<category><![CDATA[Malware]]></category>

		<guid isPermaLink="false">http://secureitfoundation.wordpress.com/?p=660</guid>
		<description><![CDATA[If it walks like a duck, quacks like a duck, looks like a duck, it must be a duck&#8230; If software on computer communicated to third parties like malware, altered settings like malware, behaved like malware, it must be malware. You would think so but there is a threat to computer security that does not [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=secureitfoundation.wordpress.com&amp;blog=7656431&amp;post=660&amp;subd=secureitfoundation&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>If it walks like a duck, quacks like a duck, looks like a duck, it must be a duck&#8230;</p>
<p>If software on computer communicated to third parties like malware, altered settings like malware, behaved like malware, it must be malware. You would think so but there is a threat to computer security that does not get classified as malware.</p>
<p>It gets around being classified as malware by making the user accept the software as part of an installation of other software. For example if you look at the Top 10 downloads from <a href="http://download.cnet.com/windows/" target="_blank">Download.com</a> at the moment you will see at number three there is a program called <a href="http://download.cnet.com/YouTube-Downloader/3000-2071_4-10647340.html" target="_blank">YouTube Downloader</a>, with nearly 800,000 downloads in the previous month.</p>
<p>When you install the software you get a typical install process for Windows, but with an additional option page for a Toolbar:</p>
<div id="attachment_663" class="wp-caption aligncenter" style="width: 490px"><a href="http://secureitfoundation.files.wordpress.com/2011/10/youtube-downloader-toolbar-screenshot.png"><img class="size-full wp-image-663" title="YouTube Downloader Toolbar Screenshot" src="http://secureitfoundation.files.wordpress.com/2011/10/youtube-downloader-toolbar-screenshot.png?w=480&#038;h=373" alt="YouTube Downloader Toolbar Screenshot" width="480" height="373" /></a><p class="wp-caption-text">YouTube Downloader Toolbar Screenshot</p></div>
<p>While there is an option to decline (which we strongly recommend you use!), most users do not. There is no informed consent for the user that they are about to install a potentially unwanted program, which will make changes to your computer. But if you click &#8216;Accept&#8217; the toolbar takes over you browsers and your PC. In nature, this would be called a parasite, as it feeds on the others in a symbiotic relationship.</p>
<p>As the user has clicked &#8216;Accept&#8217; to the <a href="http://youtubedownloader.mybrowserbar.com/terms.html" target="_blank">legalese terms</a> they have agreed to allow it control of their computer. Following the trail, brings you to a company called <a href="http://www.spigot.com/" target="_blank">Spigot</a> whose slogan is &#8216;Turn on the revenue&#8217;. In case you don&#8217;t realise it, they mean revenue for application developers by using your internet data, mined by the toolbar! You are the cash cow, as they make money on selling marketing information based on your surfing habits.</p>
<p>These terms include:</p>
<p><em>&#8220;The Spigot Toolbar Privacy Policy applies to the Spigot Toolbar only and is independent of any other application(s) you may be installing or using concurrently. Spigot Toolbar is built and maintained by Spigot, Inc. (&#8220;We&#8221;). We care about your privacy and will never collect personally identifiable information or monitor usage on an individual level.&#8221;</em></p>
<p><em>The information we collect is for basic reporting purposes only, and includes the following:</em><br />
<em>a) Date and time of installation</em><br />
<em>b) Date and time of un-installation</em><br />
<em>c) <strong>Originating IP address</strong> and the user&#8217;s country at time of installation/un-installation</em><br />
<em>d) Toolbar status in Internet Explorer or Firefox (i.e. if a toolbar is hidden or displayed in the browser)</em><br />
<em>e) Partner ID at time of installation</em><br />
<em>f) Toolbar version at time of installation</em></p>
<p><em>Information we collect during Toolbar Usage</em></p>
<p><em>We do not monitor the web pages you visit. When you perform a search, your search may be sent through our servers in order to <strong>&#8216;optimize the search result&#8217;</strong>. This will record the following anonymous usage information:</em><br />
<em>a) <strong>Date and time of search</strong></em><br />
<em>b) <strong>Originating IP address</strong></em><br />
<em>c) Partner / Channel ID of your Toolbar</em><br />
<em>d) Toolbar version</em><br />
<em>e) <strong>Search term</strong></em></p>
<p><em>In addition, your web browser will communicate to us the same information it gives to every web server on the Internet. This could include information such as your computer hardware and software attributes, cookies for our site, and the URL of web page you are requesting.</em></p>
<p><em>How we use the Information we collect</em></p>
<p><em>Information we collect from you is used on an aggregate basis and for reporting purposes only. For example, we measure the total number of Toolbar installations per month in order to pay our partners, the total number of Toolbar searches conducted per month to measure growth patterns, the number of Toolbars used in Microsoft Internet Explorer or Mozilla Firefox per month to study browser trends, and so on. All information is collected in aggregate and never measured on an individual basis.</em></p>
<p><em>Information collected by Third Parties</em></p>
<p><em>Search results pages you visit when performing a search using the toolbar are provided by our search engine partners (i.e. Yahoo, Baidu, Yandex, eBay, Amazon). These search engines can track the following:</em><br />
<em>a) Search term that was entered into the search box</em><br />
<em>b) Originating IP address and the user&#8217;s country or OS language setting</em><br />
<em>c) Sponsored listings or other advertisements that were clicked on</em><br />
<em>d) That the search request came from the Spigot Toolbar and its associated revenue tag</em></p>
<p><em>The <strong>toolbar does not collect personally identifiable information or monitor your surfing behavior</strong>.</em></p>
<p><em>Use of Cookies</em></p>
<p><em>When you conduct a search using the toolbar, our content providers who supply search results (i.e. Yahoo, Baidu, Yandex, eBay, Amazon) may set or access cookies on your computer. The cookies are used for the purpose of measuring referrals from our toolbar on an aggregate basis and are not tied to your personal information. Many browsers offer users the option of declining cookies. If you do not wish to accept cookies, please modify the settings in your browser.</em></p>
<p><em>Toolbar Updates</em></p>
<p><em>The toolbar communicates with our servers from time to time to check for available software updates such as bug fixes, patches, enhanced functions and new versions. By installing the toolbar, you agree to automatically request and receive updates. If you wish to turn off automatic updates, you can do so from the &#8220;Options&#8221; menu in the toolbar.</em></p>
<p><em>Toolbar Uninstall</em></p>
<p><em>You can easily uninstall the toolbar in the traditional Add/Remove programs section in Windows, or from the toolbar by selecting</em></p>
<p><em>Options &gt; Help &gt; Uninstall.</em></p>
<p><em>Toolbar Deactivation</em></p>
<p><em>You can easily hide or deactivate the Toolbar in Internet Explorer or FireFox by selecting View &gt; Toolbars, and then unselecting the checkbox for the toolbar.</em></p>
<p><em>Changes to this Privacy Policy</em></p>
<p><em>We may update this privacy policy from time to time. We will notify you about significant changes in the way we treat personal information by placing a prominent notice on our site. &#8220;</em></p>
<p>The bold type highlights the problem. It claims it only monitors your search terms without identifying you but your IP address is like a fingerprint. It always leaves a trail on every computer you communicate with and all those in between. The legal issue is that on its own an IP address is not classed as personal data, for example compare the <a href="http://www.out-law.com/page-8060" target="_blank">UK stance</a> with the <a href="http://www.out-law.com/page-11901" target="_blank">US approach</a>. In reality, every email you send, website you visit or post on a public forum can log your IP address. Combined with your email address or forum username and you can have personally identifiable data.</p>
<p>In addition some toolbars &#8216;optimise&#8217; the search results to preferred companies whose activities may not be strictly legal or could be classified by some people as scam merchants.</p>
<p>Until these legal issues are resolved, Anti Virus and Computer Security companies cannot classify Toolbars as malware without risk of litigation from the companies involved, says a lot about the money involved here.</p>
<p>So there is a stalemate situation where you know its bad software but your security defences let it through as if it was ok. For now, all we can advise is when you install new software, read the install pages and look out for Toolbars and changes to your search engine and browser settings. If you see one, untick all options and decline it! Weasel words to look for include &#8216;<a href="http://www.conduit.com/" target="_blank">Community</a>&#8216;, &#8216;<a href="http://www.conduit.com/" target="_blank">Conduit</a>&#8216;, &#8216;<a href="http://www.spigot.com/" target="_blank">Spigot</a>&#8216; and &#8216;<a href="http://www.mybrowserbar.com/" target="_blank">Mybrowserbar</a>&#8216; amongst many&#8230; Clues to look for are those companies who don&#8217;t tell you where they are and have no publicly checkable address showing.</p>
<p>Say No to Toolbars and rid the Internet of another parasite by cutting off their revenue stream, namely <em>your information</em>.</p>
<p>SecurityBrad</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/secureitfoundation.wordpress.com/660/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/secureitfoundation.wordpress.com/660/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/secureitfoundation.wordpress.com/660/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/secureitfoundation.wordpress.com/660/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/secureitfoundation.wordpress.com/660/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/secureitfoundation.wordpress.com/660/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/secureitfoundation.wordpress.com/660/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/secureitfoundation.wordpress.com/660/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/secureitfoundation.wordpress.com/660/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/secureitfoundation.wordpress.com/660/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/secureitfoundation.wordpress.com/660/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/secureitfoundation.wordpress.com/660/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/secureitfoundation.wordpress.com/660/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/secureitfoundation.wordpress.com/660/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=secureitfoundation.wordpress.com&amp;blog=7656431&amp;post=660&amp;subd=secureitfoundation&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://secureitfoundation.wordpress.com/2011/10/31/toolbars-are-malware/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/5d24558eeb6d4c815f56b70d748fb279?s=96&#38;d=http%3A%2F%2Fs0.wp.com%2Fi%2Fmu.gif&#38;r=G" medium="image">
			<media:title type="html">secureitfoundation</media:title>
		</media:content>

		<media:content url="http://secureitfoundation.files.wordpress.com/2011/10/youtube-downloader-toolbar-screenshot.png" medium="image">
			<media:title type="html">YouTube Downloader Toolbar Screenshot</media:title>
		</media:content>
	</item>
		<item>
		<title>How did I get a virus?</title>
		<link>http://secureitfoundation.wordpress.com/2011/10/01/how-did-i-get-a-virus/</link>
		<comments>http://secureitfoundation.wordpress.com/2011/10/01/how-did-i-get-a-virus/#comments</comments>
		<pubDate>Sat, 01 Oct 2011 11:23:05 +0000</pubDate>
		<dc:creator>secureitfoundation</dc:creator>
				<category><![CDATA[Secure IT Foundation Blog]]></category>
		<category><![CDATA[Blog updated]]></category>
		<category><![CDATA[Secure IT Foundation]]></category>

		<guid isPermaLink="false">http://secureitfoundation.wordpress.com/?p=136</guid>
		<description><![CDATA[One of the most common questions asked, is how did I get a virus on my Windows computer? Simple answer &#8211; human error. To get a virus to infect your computer you had to do / not to do one or more of the following scenarios: Use Windows with no firewall and never update Windows [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=secureitfoundation.wordpress.com&amp;blog=7656431&amp;post=136&amp;subd=secureitfoundation&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>One of the most common questions asked, is how did I get a virus on my Windows computer? Simple answer &#8211; human error.</p>
<p>To get a virus to infect your computer you had to do / not to do one or more of the following scenarios:</p>
<ol>
<li>Use Windows with no firewall and never update Windows (Windows XP Service Pack 2 or older, ME, 98, 95 users &#8211; that means you). The virus is sent by bad people to every computer on the Internet. Your lack of a firewall allows the bad code to enter your computer and without any other security the code will run. The computer is then in the control of the bad guys.</li>
<li>Use Windows with a firewall, update Windows occasionally, but have no Anti Virus software. The firewall stops the bad guys code but you receive an email or instant message with an attached file, from person known or unknown (doesn&#8217;t matter!). You open email and double click on the attachment. Bad guys code runs, no Anti Virus which may stop the code, bad guys have control of your computer.</li>
<li>Use Windows with a firewall, update Windows occasionally, use up to date Anti Virus software, but also use Internet Explorer to browse the Internet. You visit a web site. The trusted web site receives adverts from a third party but bad guys manage to get their bad code sent as an advert to all web site visitors of the trusted web site, including yours. Firewall does not help as you want your computer to communicate with the Internet. The bad guys code is new so not stopped by your Anti Virus software. Your Windows is not fully up to date and the bad guys use a known problem with Windows to get their code to run. The bad guys have control of your computer.</li>
<li>Use Windows with firewall, up to date Anti Virus, Windows is fully updated, and you use Firefox. The bad guys publish a new message on FaceTubeHive which links to their bad website, under excuse of a funny / rude / surprising / adult / flash video (delete as appropriate). You click on link to see the mentioned funny / rude / surprising / adult / flash video (delete as appropriate). As you have never updated your Adobe Flash Player, the bad guys&#8217; code uses a known problem with the software and the bad guys have control of your computer.</li>
<li>Use Windows with firewall, up to date Anti Virus, updated Windows, updated Office, updated all installed applications, use Firefox instead of Internet Explorer with Adblock Plus and NoScript plugins. However you wanted to speed up your old computer / remove viruses from your computer / remove spyware from your computer (delete as appropriate) and clicked on a link to software that claimed to do just that. Guess what, the software is a fake and the bad guys wrote it. It is new code so not detected by Anti Virus software, and now the bad guys have control of your computer.</li>
<li>You use Windows with firewall, up to date Anti Virus, updated Windows, updated Office, updated all installed applications, use Firefox instead of Internet Explorer with Adblock Plus and NoScript plugins, hardened to equivalent of Secure IT Foundation Standard Level 4 (highest!). Your kids use the computer and want to play a new game, they click randomly on links in Google / use eMule / use Bittorrent / use Limewire (delete as appropriate) and download bad guys&#8217; code. They double click on the file and it goes to run. The kids are prompted to enter the administrators password which they do not know. They moan and whine, so you give in and enter your password for them. The bad guys&#8217; code runs and they now have control of your computer.</li>
</ol>
<p>It should be:</p>
<p>You use Windows with firewall, up to date Anti Virus, updated Windows, updated Office, updated all installed applications, use Firefox instead of Internet Explorer with Adblock Plus and NoScript plugins, hardened to equivalent of Secure IT Foundation Standard Level 4 (highest!). Your kids use the computer and want to play a new game, they click randomly on links in Google and download bad guys&#8217; code. They double click on the file and it goes to run. The kids are prompted to enter the administrators password which they do not know.</p>
<ul>
<li>They moan and whine so you contact your IT Security professional and ask is this file safe to run. They check and say yes or no. You listen and kids may or may not have a new game to play. If not, you explained it was a computer virus and not a real game. You even told them the example of a Xmas present with a loaded mouse trap inside to explain that all that looks shiny may not be what it looks like. If you must demonstrate use your own fingers!</li>
<li>You have some IT knowledge, upload the suspicious file to www.virustotal.com, and it comes back clean. You test it in a virtual computer using VMware or similar and find no problems or suspicious firewall traffic. Nothing happens, kids get new game the next day.</li>
</ul>
<p>Anything less than full security all the time, is all it takes to give your computer to the bad guys.</p>
<p>Even with the highest level of security there are no guarantees and occasionally the bad guys get lucky and write code that goes through all defences. Only up to date backups will save you then, assuming you do make backups.</p>
<p>Prepare for the worst and you should be ok. Hope for the best and it won&#8217;t be ok. Security can be so simple.</p>
<p>SB</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/secureitfoundation.wordpress.com/136/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/secureitfoundation.wordpress.com/136/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/secureitfoundation.wordpress.com/136/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/secureitfoundation.wordpress.com/136/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/secureitfoundation.wordpress.com/136/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/secureitfoundation.wordpress.com/136/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/secureitfoundation.wordpress.com/136/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/secureitfoundation.wordpress.com/136/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/secureitfoundation.wordpress.com/136/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/secureitfoundation.wordpress.com/136/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/secureitfoundation.wordpress.com/136/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/secureitfoundation.wordpress.com/136/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/secureitfoundation.wordpress.com/136/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/secureitfoundation.wordpress.com/136/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=secureitfoundation.wordpress.com&amp;blog=7656431&amp;post=136&amp;subd=secureitfoundation&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://secureitfoundation.wordpress.com/2011/10/01/how-did-i-get-a-virus/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/5d24558eeb6d4c815f56b70d748fb279?s=96&#38;d=http%3A%2F%2Fs0.wp.com%2Fi%2Fmu.gif&#38;r=G" medium="image">
			<media:title type="html">secureitfoundation</media:title>
		</media:content>
	</item>
		<item>
		<title>Diginotar Disaster Explained</title>
		<link>http://secureitfoundation.wordpress.com/2011/09/07/diginotar-debarcle-explained/</link>
		<comments>http://secureitfoundation.wordpress.com/2011/09/07/diginotar-debarcle-explained/#comments</comments>
		<pubDate>Wed, 07 Sep 2011 14:58:03 +0000</pubDate>
		<dc:creator>secureitfoundation</dc:creator>
				<category><![CDATA[Secure IT Foundation Blog]]></category>
		<category><![CDATA[Blog updated]]></category>
		<category><![CDATA[Diginotar]]></category>
		<category><![CDATA[password security]]></category>
		<category><![CDATA[Personal Security]]></category>
		<category><![CDATA[Secure IT Foundation]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Windows]]></category>

		<guid isPermaLink="false">http://secureitfoundation.wordpress.com/?p=651</guid>
		<description><![CDATA[It has been difficult to avoid the news stories regarding a Dutch company called Diginotar and the prediction of the end of Internet security as we know it. Some stories have been based on facts, while others have clearly been written just to sell news or by those who have little comprehension of how the [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=secureitfoundation.wordpress.com&amp;blog=7656431&amp;post=651&amp;subd=secureitfoundation&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>It has been difficult to avoid the news stories regarding a Dutch company called Diginotar and the prediction of the end of Internet security as we know it. Some stories have been based on facts, while others have clearly been written just to sell news or by those who have little comprehension of how the Internet and computers work.</p>
<p>To help explain the saga we have written a FAQ based on queries we have received.</p>
<p><strong>Who is Diginotar?</strong></p>
<p><a href="http://www.diginotar.nl">Diginotar</a> is a private company set up in 1998 to supply electronic identity management products including the issuing of &#8216;digital certificates&#8217; for secure Internet transactions. In 2004 the Dutch government trusted Diginotar with the responsibility for providing digital certificates for all government / citizen interactions under a scheme called &#8216;<a href="http://www.logius.nl/producten/toegang/pkioverheid/">PKIoverheid</a>&#8216;.</p>
<p><strong>What are digital certificates?</strong></p>
<p>Digital certificates are part of the technology which allows a home computer user to communicate securely over the Internet for important transactions like banking, paying bills, interacting with government services online etc.</p>
<p>Each time you see padlock in your browser, or the address bar turns green or you see http<strong>s</strong>:// in the address you browser has established a secure channel over the Internet using complex mathematics to provide encryption.</p>
<p>If you think that most of your Internet activity does not involve using a secure channel, you can liken it to using a postcard to send a message to a friend in the real world. Anyone can read the message between you and your friend. This may be fine for arranging a meet in a bar but you would not the world to be able to view your banking transactions in the same way. This is where digital certificates come in, to provide secure electronic communications.</p>
<p>Each major company who wants you to communicate with them purchase digital certificates from companies like Diginotar, called Certificate Authorities officially. These Certificate Authorities verify the identity of the company wishing to buy a certificate, and issues the company with a unique code. When you want to establish a secure channel with your bank, your browser receives part of the unique code and checks that is really does belong to the company it claims to be. This proves that you are talking to the right company and allows a secure channel to start.</p>
<p><strong>How does my browser know the identity of my bank?</strong></p>
<p>Your browser e.g. Google Chrome, Apple Safari, Mozilla Firefox, Microsoft&#8217;s Internet Explorer etc all contain a list of trusted Certificate Authorities including Diginotar, each represented by a unique code. These companies around the world are trusted to provide digital certificates, some government owned but mostly private companies.</p>
<p>When your browser wants to verify the identity of the company or organisation e.g. a bank, it obtains the unique code from the digital certificate for the bank and mathematically checks it that it is valid with the unique code stored by the browser for the issuing certificate authority. If all checks pass then a secure channel is started. The proper name for this secure channel is an &#8216;<strong>SSL</strong>&#8216; connection.</p>
<p>The digital certificate gives you trust that you are communicating with the right organisation or company. Extra checks are made for a scheme called <strong>E</strong>xtended <strong>V</strong>erification <strong>SSL </strong>certificates. When used, these &#8216;<strong>EVSSL</strong>&#8216; certificates are the type that make your browser address bar change colour to green, which highlights the verified nature of the company you are communicating with.</p>
<p><strong>So what actually happened?</strong></p>
<p>Based on the information published by <a href="http://www.rijksoverheid.nl/bestanden/documenten-en-publicaties/rapporten/2011/09/05/diginotar-public-report-version-1/rapport-fox-it-operation-black-tulip-v1-0.pdf">Fox-IT BV</a>, a major Dutch computer forensics company sited close to the Secure IT Foundation base in Rotterdam. It seems that hackers gained access to Diginotar&#8217;s internal computer systems as early as 6th June 2011. The hackers then attempted to make their own digital certificates. On the 10th July they succeeded in making a certificate which allow them to impersonate Google. The hackers continued for 10 more days making hundreds of digital certificates for major companies and computer systems.</p>
<p>Finally a security breach was detected by Diginotar on the 22nd July and an unnamed security company was called in to report, which they did on 27th July 2011. The same day, other security experts began to report unusual use of Google&#8217;s digital certificate and the next day traced it and it was being used in Iran. Diginotar went public on the security breach on the 30th August 2011, with the consequence that Diginotar&#8217;s validity as a certificate authority has been revoked by most browsers in recent updates.</p>
<p>While information is still being gathered and full facts may never be known publicly, it appears that the Iranian authorities have been able to intercept &#8216;secure communications&#8217; with any of the companies impersonated by these rogue digital certificates by anyone using an Iranian computer network for about a month. In addition there was a potential for people outside of Iran to have been redirected to websites under the Iran authorities control, allowing for interception to occur to non Iranian citizens.</p>
<p>A similar attack on another certificate authority was made earlier in March 2011 on a US company called Comodo, which Comodo blamed fully at the Iranian authorities. However in this case only 9 rogue digital certificates were produced and the incident was stopped in a much shorter time frame than Diginotar.</p>
<p><strong>How does this affect my home computer?</strong></p>
<p>You may have noticed Mozilla and Google updated their browsers recently and Microsoft issued a patch via Windows Update. These changes remove the use of Diginotar as a valid certificate authority. If you visit a website using on of the rogue digital certificates then you should get a message not to trust the website you are communicating with. If you see a browser warning about the website&#8217;s authenticity then it is best not to continue the session and seek expert advice.</p>
<p>Outside of The Netherlands and Iran, most people will not see any impact from this security breach. Secure communications in Iran have become significantly harder but the most affect country so far is The Netherlands. Diginotar also managed part of the PKIoverheid system for secure Government communications so there has been some disruption to the service while new digital certificates have been issued to replace Diginotar supplied certificates. Thankfully the Dutch government had the sense to use multiple suppliers so the digital certificates issued by Diginotar have been replaced by one of the other three accepted certificate providers, without collapsing the whole Dutch system.</p>
<p><strong>Is the problem now solved?</strong></p>
<p>The dust has yet to settle and there are claims that other certificate authorities like Diginotar have also been compromised, however until new information is confirmed it does appear that the matter has been finalised. Diginotar&#8217;s continuing ability to trade is certainly going to be questioned as the initial findings from Fox-IT show Diginotar to be well below best practice for a security business.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/secureitfoundation.wordpress.com/651/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/secureitfoundation.wordpress.com/651/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/secureitfoundation.wordpress.com/651/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/secureitfoundation.wordpress.com/651/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/secureitfoundation.wordpress.com/651/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/secureitfoundation.wordpress.com/651/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/secureitfoundation.wordpress.com/651/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/secureitfoundation.wordpress.com/651/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/secureitfoundation.wordpress.com/651/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/secureitfoundation.wordpress.com/651/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/secureitfoundation.wordpress.com/651/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/secureitfoundation.wordpress.com/651/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/secureitfoundation.wordpress.com/651/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/secureitfoundation.wordpress.com/651/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=secureitfoundation.wordpress.com&amp;blog=7656431&amp;post=651&amp;subd=secureitfoundation&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://secureitfoundation.wordpress.com/2011/09/07/diginotar-debarcle-explained/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/5d24558eeb6d4c815f56b70d748fb279?s=96&#38;d=http%3A%2F%2Fs0.wp.com%2Fi%2Fmu.gif&#38;r=G" medium="image">
			<media:title type="html">secureitfoundation</media:title>
		</media:content>
	</item>
		<item>
		<title>Spreading the word on home computer security</title>
		<link>http://secureitfoundation.wordpress.com/2011/07/09/spreading-the-word-on-home-computer-security/</link>
		<comments>http://secureitfoundation.wordpress.com/2011/07/09/spreading-the-word-on-home-computer-security/#comments</comments>
		<pubDate>Sat, 09 Jul 2011 10:54:23 +0000</pubDate>
		<dc:creator>secureitfoundation</dc:creator>
				<category><![CDATA[Secure IT Foundation Blog]]></category>
		<category><![CDATA[750000]]></category>
		<category><![CDATA[Blog updated]]></category>
		<category><![CDATA[Secure IT Foundation]]></category>

		<guid isPermaLink="false">http://secureitfoundation.wordpress.com/?p=647</guid>
		<description><![CDATA[Although it can seem like we are only the bringers of bad news, once in while though we do have our good news. Our Secure IT Foundation site now has had over 750,000 visitors so hopefully a percentage of these have learned something about home computer security from our advice&#8230; SecurityBrad<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=secureitfoundation.wordpress.com&amp;blog=7656431&amp;post=647&amp;subd=secureitfoundation&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>Although it can seem like we are only the bringers of bad news, once in while though we do have our good news. Our Secure IT Foundation site now has had over 750,000 visitors so hopefully a percentage of these have learned something about home computer security from our advice&#8230;</p>
<p>SecurityBrad</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/secureitfoundation.wordpress.com/647/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/secureitfoundation.wordpress.com/647/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/secureitfoundation.wordpress.com/647/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/secureitfoundation.wordpress.com/647/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/secureitfoundation.wordpress.com/647/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/secureitfoundation.wordpress.com/647/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/secureitfoundation.wordpress.com/647/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/secureitfoundation.wordpress.com/647/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/secureitfoundation.wordpress.com/647/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/secureitfoundation.wordpress.com/647/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/secureitfoundation.wordpress.com/647/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/secureitfoundation.wordpress.com/647/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/secureitfoundation.wordpress.com/647/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/secureitfoundation.wordpress.com/647/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=secureitfoundation.wordpress.com&amp;blog=7656431&amp;post=647&amp;subd=secureitfoundation&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://secureitfoundation.wordpress.com/2011/07/09/spreading-the-word-on-home-computer-security/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/5d24558eeb6d4c815f56b70d748fb279?s=96&#38;d=http%3A%2F%2Fs0.wp.com%2Fi%2Fmu.gif&#38;r=G" medium="image">
			<media:title type="html">secureitfoundation</media:title>
		</media:content>
	</item>
		<item>
		<title>Recent Security Updates</title>
		<link>http://secureitfoundation.wordpress.com/2011/06/29/recent-security-updates/</link>
		<comments>http://secureitfoundation.wordpress.com/2011/06/29/recent-security-updates/#comments</comments>
		<pubDate>Wed, 29 Jun 2011 10:38:21 +0000</pubDate>
		<dc:creator>secureitfoundation</dc:creator>
				<category><![CDATA[Secure IT Foundation Blog]]></category>
		<category><![CDATA[Adobe Flash Security]]></category>
		<category><![CDATA[Adobe reader security]]></category>
		<category><![CDATA[Blog updated]]></category>
		<category><![CDATA[Firefox]]></category>
		<category><![CDATA[itunes]]></category>
		<category><![CDATA[Java]]></category>
		<category><![CDATA[mobileme]]></category>
		<category><![CDATA[quicktime]]></category>
		<category><![CDATA[Secunia PSI]]></category>
		<category><![CDATA[Secure IT Foundation]]></category>
		<category><![CDATA[Skype]]></category>
		<category><![CDATA[Sumatra PDF]]></category>
		<category><![CDATA[thunderbird]]></category>
		<category><![CDATA[Windows]]></category>

		<guid isPermaLink="false">http://secureitfoundation.wordpress.com/?p=644</guid>
		<description><![CDATA[If you only ever update your computer&#8217;s operating system and applications once every few months, if at all, then it is time you checked your updates as June proved to be a busy month for security exploits used to take over your computer. Adobe has released updates to their Flash player, Shockwave Player and Reader [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=secureitfoundation.wordpress.com&amp;blog=7656431&amp;post=644&amp;subd=secureitfoundation&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>If you only ever update your computer&#8217;s operating system and applications once every few months, if at all, then it is time you checked your updates as June proved to be a busy month for security exploits used to take over your computer.</p>
<p>Adobe has released updates to their <a href="http://get.adobe.com/flashplayer/" target="_blank">Flash player</a>, <a href="http://get.adobe.com/shockwave/" target="_blank">Shockwave Player</a> and <a href="http://get.adobe.com/reader/" target="_blank">Reader</a> products plus a host of other updates for their paid versions.</p>
<p>Java has been updated to <a href="http://www.java.com/" target="_blank">Version 6 Update 26</a></p>
<p><a href="http://blog.kowalczyk.info/software/sumatrapdf/download-free-pdf-viewer.html" target="_blank">Sumatra PDF</a> has been updated to version 1.6, but do choose not to install the plugins for browsers.</p>
<p><a href="http://update.microsoft.com/" target="_blank">Microsoft</a> issued 16 new security updates for multiple versions of Windows. Link only works for Internet Explorer users sadly. If you have already installed the June updates, there has been an update released on the 28th June to fix an additional problem with TLS/SSL.</p>
<p>Apple released new versions for Itunes, Quicktime and MobileMe. From Windows run Apple Software Update but mind their trick of showing you items not installed in the hope you leave then selected!</p>
<p>Mozilla updated both <a href="http://www.mozilla.com/firefox/" target="_blank">Firefox</a> to version 5.0 and <a href="http://www.mozilla.org/thunderbird/" target="_blank">Thunderbird</a> to 3.1.11.</p>
<p>While you are running updates, Skype also should be updated from the built in check for updates option.</p>
<p>If that hasn&#8217;t got you rushing to patch your PC, then either you do not consider your computer&#8217;s security important yet or you have already installed <a href="http://secunia.com/vulnerability_scanning/personal/" target="_blank">Secunia&#8217;s PSI</a> application to check your patch level on a regular basis for you&#8230;</p>
<p>SecurityBrad</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/secureitfoundation.wordpress.com/644/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/secureitfoundation.wordpress.com/644/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/secureitfoundation.wordpress.com/644/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/secureitfoundation.wordpress.com/644/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/secureitfoundation.wordpress.com/644/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/secureitfoundation.wordpress.com/644/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/secureitfoundation.wordpress.com/644/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/secureitfoundation.wordpress.com/644/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/secureitfoundation.wordpress.com/644/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/secureitfoundation.wordpress.com/644/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/secureitfoundation.wordpress.com/644/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/secureitfoundation.wordpress.com/644/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/secureitfoundation.wordpress.com/644/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/secureitfoundation.wordpress.com/644/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=secureitfoundation.wordpress.com&amp;blog=7656431&amp;post=644&amp;subd=secureitfoundation&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://secureitfoundation.wordpress.com/2011/06/29/recent-security-updates/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/5d24558eeb6d4c815f56b70d748fb279?s=96&#38;d=http%3A%2F%2Fs0.wp.com%2Fi%2Fmu.gif&#38;r=G" medium="image">
			<media:title type="html">secureitfoundation</media:title>
		</media:content>
	</item>
		<item>
		<title>Fake Anti Virus Installs on Macs Without a Password</title>
		<link>http://secureitfoundation.wordpress.com/2011/05/26/fake-anti-virus-installs-on-macs-without-a-password/</link>
		<comments>http://secureitfoundation.wordpress.com/2011/05/26/fake-anti-virus-installs-on-macs-without-a-password/#comments</comments>
		<pubDate>Thu, 26 May 2011 11:54:27 +0000</pubDate>
		<dc:creator>secureitfoundation</dc:creator>
				<category><![CDATA[Secure IT Foundation Blog]]></category>
		<category><![CDATA[Blog updated]]></category>
		<category><![CDATA[Mac Virus]]></category>
		<category><![CDATA[Smug Mac]]></category>

		<guid isPermaLink="false">http://secureitfoundation.wordpress.com/?p=640</guid>
		<description><![CDATA[Once upon a time Apple Mac users were happy people, laughing at Windows users suffering with virus problems&#8230; As Macs became more popular, the malware and virus writers have turn more attention to the Apple operating system OSX. Now a fake Anti Virus program can run on a Mac without needing a password. This brings [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=secureitfoundation.wordpress.com&amp;blog=7656431&amp;post=640&amp;subd=secureitfoundation&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>Once upon a time Apple Mac users were happy people, laughing at Windows users suffering with virus problems&#8230; As Macs became more popular, the malware and virus writers have turn more attention to the Apple operating system OSX. Now a fake Anti Virus program can run on a Mac without needing a password. This brings Mac security on a level par with Windows.</p>
<p>Perhaps as the Windows users have years of experience dealing with viruses and malware, the naivety and now abundance of Apple&#8217;s user base makes them ripe for the picking.</p>
<p>You can read the recent timeline of Apple&#8217;s security model failing <a href="http://nakedsecurity.sophos.com/2011/05/26/apple-malware-evolved-no-password-required/">here</a> and then install the AV for Mac from <a href="http://www.sophos.com/en-us/products/free-tools/sophos-antivirus-for-mac-home-edition.aspx">Sophos</a> for free before you get caught out. Don&#8217;t be a smug mac user, get protected and resign yourself to being no more secure than the Windows user next to you. Read the history of <a href="http://nakedsecurity.sophos.com/2010/11/24/apple-mac-malware-short-history/">Mac viruses</a> and find they pre-date Windows viruses by a few years!</p>
<p>The quicker Mac users accept the change then the quicker they can move on and begin to deal with the problem&#8230; Denial of a problem has always works so well with computers.</p>
<p>SecurityBrad</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/secureitfoundation.wordpress.com/640/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/secureitfoundation.wordpress.com/640/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/secureitfoundation.wordpress.com/640/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/secureitfoundation.wordpress.com/640/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/secureitfoundation.wordpress.com/640/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/secureitfoundation.wordpress.com/640/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/secureitfoundation.wordpress.com/640/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/secureitfoundation.wordpress.com/640/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/secureitfoundation.wordpress.com/640/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/secureitfoundation.wordpress.com/640/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/secureitfoundation.wordpress.com/640/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/secureitfoundation.wordpress.com/640/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/secureitfoundation.wordpress.com/640/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/secureitfoundation.wordpress.com/640/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=secureitfoundation.wordpress.com&amp;blog=7656431&amp;post=640&amp;subd=secureitfoundation&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://secureitfoundation.wordpress.com/2011/05/26/fake-anti-virus-installs-on-macs-without-a-password/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/5d24558eeb6d4c815f56b70d748fb279?s=96&#38;d=http%3A%2F%2Fs0.wp.com%2Fi%2Fmu.gif&#38;r=G" medium="image">
			<media:title type="html">secureitfoundation</media:title>
		</media:content>
	</item>
		<item>
		<title>PrentOS &#8211; a Simple Secure Computer</title>
		<link>http://secureitfoundation.wordpress.com/2011/05/26/prentos-a-simple-secure-computer/</link>
		<comments>http://secureitfoundation.wordpress.com/2011/05/26/prentos-a-simple-secure-computer/#comments</comments>
		<pubDate>Thu, 26 May 2011 10:00:33 +0000</pubDate>
		<dc:creator>secureitfoundation</dc:creator>
				<category><![CDATA[PrentOS]]></category>
		<category><![CDATA[Secure IT Foundation Blog]]></category>
		<category><![CDATA[Blog updated]]></category>
		<category><![CDATA[Brads Computer Service Station]]></category>
		<category><![CDATA[Home Computer Policy]]></category>
		<category><![CDATA[Linux]]></category>
		<category><![CDATA[Mac]]></category>
		<category><![CDATA[Operating System]]></category>
		<category><![CDATA[Secure IT Foundation]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Simple Secure Computer]]></category>
		<category><![CDATA[Windows]]></category>

		<guid isPermaLink="false">http://secureitfoundation.wordpress.com/?p=636</guid>
		<description><![CDATA[September 2010 we said it was time for a brand new start to computing, well it is starting to take shape&#8230; PrentOS is the official public name for the project to develop a new open source licensed operating system with the goal of making a simple, secure computer. Why PrentOS? Simple really, as it PrentOS [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=secureitfoundation.wordpress.com&amp;blog=7656431&amp;post=636&amp;subd=secureitfoundation&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p><a href="http://secureitfoundation.wordpress.com/2010/09/28/a-brand-new-start-for-computing/" target="_blank">September 2010</a> we said it was time for a brand new start to computing, well it is starting to take shape&#8230;</p>
<p>PrentOS is the official public name for the project to develop a new open source licensed operating system with the goal of making a simple, secure computer.</p>
<p>Why PrentOS? Simple really, as it PrentOS is being developed primarily by Brad Prent, the owner of SecurityBrad and <a href="http://www.securitybrad.com" target="_blank">Brads Computer Service Station</a></p>
<p>For now, we have parked the domains <a href="http://www.prentos.com" target="_blank">www.prentos.com</a> and <a href="http://www.prentos.org" target="_blank">www.prentos.org</a> while we work on producing the Alpha version and we aim to launch limited public testing via the shop in Rotterdam by the end of 2011.</p>
<p>SecurityBrad</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/secureitfoundation.wordpress.com/636/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/secureitfoundation.wordpress.com/636/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/secureitfoundation.wordpress.com/636/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/secureitfoundation.wordpress.com/636/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/secureitfoundation.wordpress.com/636/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/secureitfoundation.wordpress.com/636/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/secureitfoundation.wordpress.com/636/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/secureitfoundation.wordpress.com/636/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/secureitfoundation.wordpress.com/636/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/secureitfoundation.wordpress.com/636/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/secureitfoundation.wordpress.com/636/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/secureitfoundation.wordpress.com/636/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/secureitfoundation.wordpress.com/636/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/secureitfoundation.wordpress.com/636/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=secureitfoundation.wordpress.com&amp;blog=7656431&amp;post=636&amp;subd=secureitfoundation&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://secureitfoundation.wordpress.com/2011/05/26/prentos-a-simple-secure-computer/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/5d24558eeb6d4c815f56b70d748fb279?s=96&#38;d=http%3A%2F%2Fs0.wp.com%2Fi%2Fmu.gif&#38;r=G" medium="image">
			<media:title type="html">secureitfoundation</media:title>
		</media:content>
	</item>
		<item>
		<title>New Features = New Security Risks</title>
		<link>http://secureitfoundation.wordpress.com/2011/05/11/new-features-means-new-security-risks/</link>
		<comments>http://secureitfoundation.wordpress.com/2011/05/11/new-features-means-new-security-risks/#comments</comments>
		<pubDate>Wed, 11 May 2011 11:56:43 +0000</pubDate>
		<dc:creator>secureitfoundation</dc:creator>
				<category><![CDATA[Secure IT Foundation Blog]]></category>
		<category><![CDATA[Blog updated]]></category>
		<category><![CDATA[Chrome]]></category>
		<category><![CDATA[Firefox]]></category>
		<category><![CDATA[Safari]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[WebGL]]></category>

		<guid isPermaLink="false">http://secureitfoundation.wordpress.com/?p=632</guid>
		<description><![CDATA[As usual whenever new technology is released, there are security issues found from the early implementations. Web browsers are no different, and a new vulnerability has been identified in Mozilla&#8217;s Firefox 4, Apple&#8217;s Safari and Google&#8217;s Chrome browsers. This time the issue is with a new feature called WebGL which allows 3D graphics in the [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=secureitfoundation.wordpress.com&amp;blog=7656431&amp;post=632&amp;subd=secureitfoundation&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p>As usual whenever new technology is released, there are security issues found from the early implementations. Web browsers are no different, and a new vulnerability has been identified in Mozilla&#8217;s Firefox 4, Apple&#8217;s Safari and Google&#8217;s Chrome browsers.</p>
<p>This time the issue is with a <a href="http://www.contextis.com/resources/blog/webgl/">new feature called WebGL</a> which allows 3D graphics in the browser. As a new feature you most probably do not need to use it for some time, and until updated versions of the browsers are released then we advise that you disable WebGL for now.</p>
<p>For Firefox users, type: about:config in the address bar and find the option webgl.disabled and set the value to &#8216;True&#8217;. Chrome and Safari have other methods to disable WebGL which are too complex for most home users to implement and as such we recommend that you only use Firefox until updates are released.</p>
<p>SecurityBrad</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/secureitfoundation.wordpress.com/632/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/secureitfoundation.wordpress.com/632/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/secureitfoundation.wordpress.com/632/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/secureitfoundation.wordpress.com/632/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/secureitfoundation.wordpress.com/632/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/secureitfoundation.wordpress.com/632/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/secureitfoundation.wordpress.com/632/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/secureitfoundation.wordpress.com/632/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/secureitfoundation.wordpress.com/632/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/secureitfoundation.wordpress.com/632/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/secureitfoundation.wordpress.com/632/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/secureitfoundation.wordpress.com/632/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/secureitfoundation.wordpress.com/632/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/secureitfoundation.wordpress.com/632/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=secureitfoundation.wordpress.com&amp;blog=7656431&amp;post=632&amp;subd=secureitfoundation&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://secureitfoundation.wordpress.com/2011/05/11/new-features-means-new-security-risks/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://1.gravatar.com/avatar/5d24558eeb6d4c815f56b70d748fb279?s=96&#38;d=http%3A%2F%2Fs0.wp.com%2Fi%2Fmu.gif&#38;r=G" medium="image">
			<media:title type="html">secureitfoundation</media:title>
		</media:content>
	</item>
	</channel>
</rss>
