subscriber servicessubscribecontact usabout ussite mapBuy a Classified
Sat, Nov 07 2009 

Resources

print this story   Print this story
  Post to del.icio.us

Published February 09, 2007 04:56 pm - The marketing propaganda touting Microsoft’s new Vista operating system as “the most secure version of Windows yet” has done nothing to stop both white and black hat hackers from discovering Vista vulnerabilities.

New Windows Vista hacked already


The Norman Transcript

The marketing propaganda touting Microsoft’s new Vista operating system as “the most secure version of Windows yet” has done nothing to stop both white and black hat hackers from discovering Vista vulnerabilities. Unless you simply enjoy acting as an experimental Microsoft guinea pig, it’s best to wait before trying to run Windows Vista.

Quite disturbing were recent revelations that Microsoft’s own Live OneCare antivirus program, tailored specifically for Vista, is unable to block many well-known computer viruses. Another antivirus package from McAfee also fails to do the job. This fulfills predictions made in early 2006 by antivirus firm Symantec (maker of Norton AntiVirus) that, because of Microsoft’s failure to provide ways for antivirus programmers to fully integrate their products with Vista, many antivirus programs would have a hard time protecting Vista users. I guess that includes Microsoft, as well.

Russian hackers posted instructions to an underground forum describing how to implement “privilege escalation,” which could bypass some Vista security measures. This hack could escalate the “privileges” of a normal Vista user into that of a “superuser,” allowing him to change anything he desired on the system. This would be particularly dangerous in a corporate environment where normal computer users have limited privileges, in that they cannot install programs, visit certain Web sites, etc. This threat is considered so serious that Microsoft has scrambled its “Security Response Center,” which is ostensibly still trying to figure out what to do.

Microsoft also recently acknowledged that Vista’s built-in speech recognition software could be exploited by bad guys to delete files and even shut the computer down. This wacky (and quite clever) hack works something like this: A Vista user downloads and plays a malicious audio file, probably thinking that it’s the latest Toby Keith song. Instead, the audio file begins barking commands through the computer’s speakers, such as, “Delete all files in the ‘My Documents’ folder,” or, “System shut down.” These verbal commands are picked up by the computer’s microphone, processed by the built-in speech recognition software, and the computer obeys. Crazy, huh?

Research done by Tokyo-based security vendor Trend Micro, makers of the popular PC-cillin antivirus products, has uncovered the existence of ongoing eBay-style black hat hacker auctions where attack programs that can be used to compromise Vista computers are being bought and sold for as much as $50,000. Reports are that, in order to steal as much money as possible, computer criminals are biding their time and building their arsenals, waiting for Vista to be installed on more computers around the world before unleashing their most powerful Vista-busting weapons.

In the face of known Vista security holes, Microsoft spokesmen have been unapologetic. Stephen Toulouse, senior product manager at Microsoft’s “Trustworthy Computing Group,” told CNN, “We know from the outset that we won’t get the software code 100 percent right … but Windows Vista has multiple layers of defense.” Another Microsoft representative told ZDNet, “It’s important to remember that no software is 100 percent secure.”

Still, I wonder, “Why is it important for me to remember that no software is 100 percent secure? Oh, yeah, so I’ll remember to hold off on installing Windows Vista.”

Said one very irritated and frustrated Vista early adopter, “I should have bought a Mac.”

Dave Moore has been repairing computers in Norman since 1984, when he borrowed $1,200 to buy a Commodore 64 system. He can be reached at 919-9901 or www.davemoorecomputers.com.



print this story    email this story   






autoconx
Premier Guide
Find a business

Walking Fingers
Maps, Menus, Store hours, Coupons, and more...
Premier Guide

Find a job! Find a Home! Find a car!

Premium Jobs

LPN or RN needed for a fast paced
clinic in Norman. Clinic & triage
experience required. Apply online www.mcbrideclinic.com or
fax resume to
...>MORE

RECOVERY SUPPORT
SPECIALIST
RSS certification w/Okla Dept of Mental Health req, for busy medication clinic. Req valid OK drivers lic
...>MORE

TOP PAY &
EXCELLENT
BENEFITS

Orientation at a
Comprehensible Pace!

Fulltime - Shawnee!

...>MORE

THERAPIST
Licensed or eligible for supervision. Fax resume w/refs,SS# & Job #09-038 to 632-1976 or mail to :HOPE,...>MORE

Ross Health Care
Sales Rep
Excellent Pay & Benefits
Call 224-5659
FAX 224-4790
employment@rosshc.com
...>MORE

Experienced Phone Rep
Are you GREAT on the phone?
Looking for one exp. phone rep.
to set appts.for est. Norman
Hm. Improvemen
...>MORE

See all ads

Premium Homes

See all ads

Premium Extras

See all ads


 

Community Newspaper Holdings, Inc.CNHI Classified Advertising NetworkCNHI News Service
Associated Press content © 2009. All rights reserved. AP content may not be published, broadcast, rewritten or redistributed.
Our site is powered by Zope and our Internet Yellow Pages site is powered by PremierGuide.
Some parts of our site may require you to download the Flash Player Plugin.
View our Privacy Policy
Advertiser index