<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>IT Secure Site</title>
	<atom:link href="http://www.itsecuresite.com/feed" rel="self" type="application/rss+xml" />
	<link>http://www.itsecuresite.com</link>
	<description>Is a hourly updated security news web site</description>
	<lastBuildDate>Wed, 22 Feb 2012 17:32:45 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.1</generator>
		<item>
		<title>The Midweek Download: Feb. 22nd Edition–Three from Building Windows 8, a Windows Logo Re-Designed, and Windows Phone, Dynamics CRM &amp; Internet Explorer</title>
		<link>http://www.itsecuresite.com/seclabs/microsoft/the-midweek-download-feb-22nd-edition%e2%80%93three-from-building-windows-8-the-windows-logo-re-designed-plus-windows-phone-dynamics-crm-internet-explorer.html</link>
		<comments>http://www.itsecuresite.com/seclabs/microsoft/the-midweek-download-feb-22nd-edition%e2%80%93three-from-building-windows-8-the-windows-logo-re-designed-plus-windows-phone-dynamics-crm-internet-explorer.html#comments</comments>
		<pubDate>Wed, 22 Feb 2012 17:32:45 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Microsoft]]></category>

		<guid isPermaLink="false">http://www.itsecuresite.com/seclabs/microsoft/the-midweek-download-feb-22nd-edition%e2%80%93three-from-building-windows-8-the-windows-logo-re-designed-plus-windows-phone-dynamics-crm-internet-explorer.html</guid>
		<description><![CDATA[In this book of The Midweek Download, we’ve got stories from Building Windows 8, a re-designed Windows logo, Windows Phone evangelists, Microsoft Dynamics CRM and more. Check ‘em out! Three from Building Windows 8. If we can’t get adequate news on Windows 8, check out these 3 new posts from Building Windows 8 – reliably [...]]]></description>
			<content:encoded><![CDATA[<p>In this book of The Midweek Download, we’ve got stories from Building Windows 8, a re-designed Windows logo, Windows Phone evangelists, Microsoft Dynamics CRM and more. Check ‘em out!</p>
<p><strong>Three from Building Windows 8. </strong>If we can’t get adequate news on Windows 8, check out these 3 new posts from Building Windows 8 – <a href="http://blogs.msdn.com/b/b8/archive/2012/02/16/internet-explorer-performance-lab-reliably-measuring-browser-performance.aspx">reliably measuring browser performance</a>, <a href="http://blogs.msdn.com/b/b8/archive/2012/02/20/connecting-your-apps_2c00_-files_2c00_-pcs-and-devices-to-the-cloud-with-skydrive-and-windows-8.aspx">SkyDrive and Windows 8</a> and <a href="http://blogs.msdn.com/b/b8/archive/2012/02/21/using-the-language-you-want.aspx">using a denunciation we wish on Windows 8</a>. Don’t skip ‘em!</p>
<p><strong>The Windows trademark redesigned.</strong> We have pronounced that Windows 8 is a finish reimagination of a Windows handling system. Nothing has been left unexplored, including a Windows logo, to weigh how it hold adult to complicated PC sensibilities. The Windows trademark is a clever and widely famous mark, though when we stepped behind and analyzed it, we satisfied an expansion of a trademark would improved simulate a <a href="http://channel9.msdn.com/Events/BUILD/BUILD2011/APP-395T">Metro character design</a> beliefs and we also felt there was an event to reconnect with some of a absolute characteristics of prior incarnations. To get a rest of this story, review this <a href="http://windowsteamblog.com/windows/b/bloggingwindows/archive/2012/02/17/redesigning-the-windows-logo.aspx">Feb. 17 post on Blogging Windows</a>. Below is a screenshot of a new logo:</p>
<p><a href="http://blogs.technet.com/cfs-file.ashx/__key/communityserver-blogs-components-weblogfiles/00-00-00-80-54-metablogapi/8037.Windows_2D00_8_2D00_Logo_5F00_4368BA41.jpg"><img alt="Windows 8 Logo" src="http://www.itsecuresite.com/wp-content/plugins/RSSPoster_PRO/cache/0f196_3125.Windows_2D00_8_2D00_Logo_5F00_thumb_5F00_5D98FD98.jpg" width="400" height="99" /></a></p>
<p><strong>Google bypassing user remoteness settings.</strong> When a IE group listened that Google had bypassed user remoteness settings on Safari, we asked ourselves a elementary question: is Google circumventing a remoteness preferences of Internet Explorer users too? We’ve detected a answer is yes: Google is contracting identical methods to get around a default remoteness protections in IE and lane IE users with cookies. Below we spell out in some-more fact what we’ve discovered, as good as recommendations to IE users on how to strengthen their remoteness from Google with a use of IE9&#8242;s Tracking Protection feature. We’ve also contacted Google and asked them to dedicate to honoring P3P remoteness settings for users of all browsers. For some-more on this story, review this <a href="http://blogs.msdn.com/b/ie/archive/2012/02/20/google-bypassing-user-privacy-settings.aspx">Monday post on a IEBlog</a>.</p>
<p><strong>Finding Windows Phone Champs.</strong> Here during Microsoft we call a Windows Phone evangelists “Phone Champs”. Champs safeguard a developers get accurately a assistance and support they need and are a voice of a developer community. They are all experts on a height and offer as internal resources to answer questions from stream or impending developers. Champs can assistance we troubleshoot a problem in your app and can assistance we get your hands on a phone for testing. For some-more on this story, review this <a href="http://windowsteamblog.com/windows_phone/b/wpdev/archive/2012/02/17/find-my-champ.aspx">Feb. 17 post on The Windows Phone Developer Blog</a>.</p>
<p><strong>Windows Azure Community News Roundup.</strong> The Windows Azure Blog has published a <a href="http://blogs.msdn.com/b/windowsazure/archive/2012/02/20/windows-azure-community-news-roundup-edition-7.aspx">latest book of a weekly roundup</a> of a latest community-driven news, calm and conversations about cloud computing and <a href="http://www.windowsazure.com/en-us/?WT.mc_id=cmp_pst001_blg_post0058">Windows Azure</a>. Check it out.</p>
<p><strong>From a IEBlog: Sub-pixel digest and a CSS intent model. </strong>With Windows 8, we have an rare choice of inclination for browsing a Web, from vast desktop screens to tiny slates. In sequence to accommodate this operation of devices, a browser contingency be means to scale and blueprint a Web during many opposite shade sizes and dimensions. We&#8217;ve formerly blogged about <a href="http://blogs.msdn.com/b/ie/archive/2008/03/25/internet-explorer-8-and-adaptive-zoom.aspx">some</a> <a href="http://blogs.msdn.com/b/ie/archive/2010/11/03/sub-pixel-fonts-in-ie9.aspx">of the</a> <a href="http://blogs.msdn.com/b/ie/archive/2011/04/14/ie10-platform-preview-and-css-features-for-adaptive-layouts.aspx">features</a> in IE that support these scenarios. <a href="http://ie.microsoft.com/testdrive/Performance/TextJustificationAnimated/Default.html">Sub-pixel positioning</a> (of content and layout) is one of a core height technologies that capacitate Web pages to demeanour pleasing and unchanging during any scale. In this <a href="http://blogs.msdn.com/b/ie/archive/2012/02/17/sub-pixel-rendering-and-the-css-object-model.aspx">post</a>, we report changes done in IE10 to improved support sub-pixel positioning by a CSS-OM.</p>
<p><strong>Burns  McDonnell chooses Microsoft Dynamics CRM 2011.</strong> Microsoft announced on Monday that Burns  McDonnell, a full-service engineering, architecture, construction, environmental and consulting services firm, has selected Microsoft Dynamics CRM 2011 over Salesforce.com and Oracle Fusion CRM for a 1,600-seat CRM deployment. The palliate of use of Microsoft Dynamics CRM 2011 was a company’s determining cause in selecting it over rival CRM solutions. Burns  McDonnell expects doing of a solution, that is slated to start this spring, will assistance boost worker capability and urge customer sales and service. Want some-more detail, review this <a href="http://www.microsoft.com/presspass/press/2012/feb12/02-20BurnsMcDonnellPR.mspx">press recover on a Microsoft News Center</a>.</p>
<p>That’s a hang for this book of The Midweek Download! Thanks for reading!</p>
<p>Posted by <strong>Jeff Meisner</strong> <br />Editor, The Official Microsoft Blog</p>
]]></content:encoded>
			<wfw:commentRss>http://www.itsecuresite.com/seclabs/microsoft/the-midweek-download-feb-22nd-edition%e2%80%93three-from-building-windows-8-the-windows-logo-re-designed-plus-windows-phone-dynamics-crm-internet-explorer.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Protect Your Music Collection with Intego Personal Backup</title>
		<link>http://www.itsecuresite.com/general/protect-your-music-collection-with-intego-personal-backup.html</link>
		<comments>http://www.itsecuresite.com/general/protect-your-music-collection-with-intego-personal-backup.html#comments</comments>
		<pubDate>Wed, 22 Feb 2012 17:32:41 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[General Security]]></category>

		<guid isPermaLink="false">http://www.itsecuresite.com/general/protect-your-music-collection-with-intego-personal-backup.html</guid>
		<description><![CDATA[Protect Your Music Collection with Intego Personal Backup If we review forums about iPods and iTunes, you’ll see a lot of people looking for ways to duplicate song from their iPod behind to their computer. The many common reason for this is they had a critical problem on their computer, mislaid all their files, and [...]]]></description>
			<content:encoded><![CDATA[<p><img width="128" height="128" src="http://www.itsecuresite.com/wp-content/plugins/RSSPoster_PRO/cache/52c61_personal-backup-icon.png" class="attachment-post-thumbnail wp-post-image" alt="personal-backup-icon" /></p>
<h2><a href="http://blog.intego.com/protect-your-music-collection-with-intego-personal-backup/" title="Read Protect Your Music Collection with Intego Personal Backup">Protect Your Music Collection with Intego Personal Backup</a></h2>
<p><!--  --></p>
<p>If we review forums about iPods and iTunes, you’ll see a lot of people looking for ways to duplicate song from their iPod behind to their computer. The many common reason for this is they had a critical problem on their computer, mislaid all their files, and they wish to get their digital song back. In other words, they don’t have backups of their song collection, or of any of their other files. </p>
<p>We during Intego cruise backups to be a cornerstone of any confidence policy, both for people and for companies. The files we create, and a information that is on your Mac, are, for a many part, irreplaceable. Sure, if we use Apple’s iCloud, we can get behind your contacts and bookmarks, and maybe some files, though what if we need to strengthen your song collection? Unless we use iTunes Match, if we remove your song collection, it’s mislaid forever. </p>
<p>Think of all a time we spent importing your CDs, and a income we spent shopping song from several digital vendors. If we don’t have a backup, and your computer’s tough hoop crashes, we competence remove all your files, including your whole song collection. The song is still on your iPod, and there are some collection that can redeem it, though if we didn’t sync all of your song to your iPod, or if we find we can’t duplicate your song files from your iPod, afterwards you’re out of luck. </p>
<p>With Intego Personal Backup, we make it easy to strengthen your song collection. You can possibly make a bootable backup (clone) of your whole tough disk, or we can privately behind adult your Music folder:</p>
</p>
<p><a href="http://www.itsecuresite.com/wp-content/plugins/RSSPoster_PRO/cache/52c61_back-up-music.jpg"><img src="http://www.itsecuresite.com/wp-content/plugins/RSSPoster_PRO/cache/52c61_back-up-music.jpg" alt="Protect your song collection with Intego Personal Backup" width="307" height="172" class="aligncenter size-full wp-image-3695" /></a></p>
<p>We suggest that we behind adult your song frequently to an outmost tough hoop or a network volume. If we don’t have an outmost tough disk, we competence consider about removing one. You can get a good outmost tough hoop for about $100.</p>
<p>Intego Personal Backup is accessible as partial of <a href="http://www.intego.com/internet-security-barrier/">Intego Internet Security Barrier X6</a>. Get a giveaway 30-day demo of Internet Security Barrier X6 and try out Personal Backup, and a other good programs in a suite.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.itsecuresite.com/general/protect-your-music-collection-with-intego-personal-backup.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Google also bypassed cookie settings in Internet Explorer</title>
		<link>http://www.itsecuresite.com/general/google-also-bypassed-cookie-settings-in-internet-explorer.html</link>
		<comments>http://www.itsecuresite.com/general/google-also-bypassed-cookie-settings-in-internet-explorer.html#comments</comments>
		<pubDate>Wed, 22 Feb 2012 11:31:33 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[General Security]]></category>

		<guid isPermaLink="false">http://www.itsecuresite.com/general/google-also-bypassed-cookie-settings-in-internet-explorer.html</guid>
		<description><![CDATA[Following a explanation that Google and other online selling companies have been bypassing a resource for restraint third-party cookies in Safari, a Internet Explorer growth group asked themselves either Google competence be doing a same thing in IE. As they detail on IEBlog, they detected that this was a box – Google circumvents Internet Explorer&#8217;s [...]]]></description>
			<content:encoded><![CDATA[<p>	<!-- RSPEAK_STOP --><br />
	<span class="pic_right"><br />
		<img src="http://www.itsecuresite.com/wp-content/plugins/RSSPoster_PRO/cache/37168_mgcookies_100-fee26d80e6ab247e.png" width="100" height="100" alt="Microsoft and Google cookies icon" /></span><br />
	<!-- RSPEAK_START --><br />
Following a explanation that Google and other online selling companies have been bypassing a resource for restraint third-party cookies in Safari, a Internet Explorer growth group asked themselves either Google competence be doing a same thing in IE. As they <a href="http://blogs.msdn.com/b/ie/archive/2012/02/20/google-bypassing-user-privacy-settings.aspx" rel="external">detail</a> on IEBlog, they detected that this was a box – Google circumvents Internet Explorer&#8217;s cookie process by subverting a browser&#8217;s P3P-based remoteness insurance mechanism. </p>
<p><a href="http://wikipedia.org/wiki/P3P" rel="external">P3P</a> stands for Platform for Privacy Preferences Project and is an open W3C standard. It is dictated to assistance both users and programs establish what sites do with personal data. The cookie government complement in Internet Explorer blocks third celebration cookies from sites that do not supply a P3P process matter revelation it how cookies are used. </p>
<p>According to Microsoft&#8217;s analysis, Google exploits a disadvantage in a P3P specification. The selection states that browsers should omit uncertain policies, so that&#8217;s accurately what Google delivers:</p>
</p>
<pre>P3P: CP="This is not a P3P policy!See http://www.google.com/support/accounts/bin/answer.py?hl=enanswer=151657 for some-more info." </pre>
<p>This can be review and accepted by tellurian users, but, according to Microsoft, browsers that follow a P3P selection appreciate this to meant that a cookie will not be used for tracking purposes. As a outcome Internet Explorer lets Google cookies pass. </p>
<p>Microsoft is advising users to download a tracking insurance list to stop Internet Explorer from forwarding cookies to Google. The blog posting contains a couple to a list, that can be commissioned from within Internet Explorer with a elementary rodent click. Microsoft is also formulation to demeanour into ways of creation Internet Explorer&#8217;s cookie doing some-more secure. One probability would be to omit a P3P selection and retard all cookies with uncertain P3P policies. </p>
<p>According to a <a href="http://www.cylab.cmu.edu/files/pdfs/tech_reports/CMUCyLab10014.pdf" rel="external">2010 study</a><img src="http://www.itsecuresite.com/wp-content/plugins/RSSPoster_PRO/cache/37168_file-pdf.gif" alt="PDF" /> by Carnegie Mellon University, 11,176 of 33,139 sites examined use an shabby P3P specification. Google has now responded to Microsoft&#8217;s claim and, in an email to US media, it <a href="http://parislemon.com/post/17998654387/google-microsoft-is-full-of-shit" rel="external">describes</a> a complement used by Internet Explorer as archaic and &#8220;widely non-operational&#8221;. </p>
<p>Google points out that a couple within a P3P process does indicate to an <a href="http://support.google.com/accounts/bin/answer.py?hl=enanswer=151657" rel="external">article</a> that states their position on P3P. It also records comments from a <a href="https://twitter.com/#!/csoghoian/status/171687280824692737" rel="external">security researcher</a> that &#8220;Instead of regulating P3P loophole in IE that FB  Amazon exploited &#8230; MS did nothing. Now they protest after Google uses it&#8221;. Facebook, during least, has a same <a href="http://validator.w3.org/p3p/20020128/p3p.pl?uri=http%3A%2F%2Fwww.facebook.com%2F" rel="external">P3P process style</a> as Google, finish with <a href="http://www.facebook.com/help/?page=219494461411349" rel="external">explanation</a>. At a time of writing, Amazon was returning a <a href="http://validator.w3.org/p3p/20020128/p3p.pl?uri=http%3A%2F%2Fwww.amazon.com%2F" rel="external">valid P3P policy</a>.</p>
<p>(<!--googleoff: index-->djwm)</p>
]]></content:encoded>
			<wfw:commentRss>http://www.itsecuresite.com/general/google-also-bypassed-cookie-settings-in-internet-explorer.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>航空券予約確認のフィッシング</title>
		<link>http://www.itsecuresite.com/seclabs/symantec/%e8%88%aa%e7%a9%ba%e5%88%b8%e4%ba%88%e7%b4%84%e7%a2%ba%e8%aa%8d%e3%81%ae%e3%83%95%e3%82%a3%e3%83%83%e3%82%b7%e3%83%b3%e3%82%b0.html</link>
		<comments>http://www.itsecuresite.com/seclabs/symantec/%e8%88%aa%e7%a9%ba%e5%88%b8%e4%ba%88%e7%b4%84%e7%a2%ba%e8%aa%8d%e3%81%ae%e3%83%95%e3%82%a3%e3%83%83%e3%82%b7%e3%83%b3%e3%82%b0.html#comments</comments>
		<pubDate>Wed, 22 Feb 2012 11:31:30 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Symantec]]></category>

		<guid isPermaLink="false">http://www.itsecuresite.com/seclabs/symantec/%e8%88%aa%e7%a9%ba%e5%88%b8%e4%ba%88%e7%b4%84%e7%a2%ba%e8%aa%8d%e3%81%ae%e3%83%95%e3%82%a3%e3%83%83%e3%82%b7%e3%83%b3%e3%82%b0.html</guid>
		<description><![CDATA[最近、航空券予約の確認を装うフィッシングメールが出回っています。フィッシングとして新しい手口ではありませんが、今回のメールとフィッシングに関連する Web サイトは特徴的で、一見したところ正規のサイトのように見えます。メールには、クレジットカードでの支払いを確認する文面が書かれており、航空券とフライト情報を印刷するには本文中のリンクをクリックするように指示されています。 メール自体はテキスト形式で、特に変わったところはないように見えます。しかし、さらに詳しく調べると、送信元のドメインが詐称されており、実際には航空会社とも関係がないことがわかりました。よく似てはいますが、詐称されている実際の送信元ドメインは空気清浄機と掃除機の会社であり、航空会社とは縁もゆかりもありません。詐称しようとしている航空会社と送信元 Web サイトが一致するかどうかを確認しなかったのはスパマーの怠慢だったようで、用心深いユーザーにはメールの信憑性がすぐに疑われてしまうでしょう。もちろん、航空券を予約していなければすぐ不審に思うところですが、このメールを誤配信と考えたユーザーが、いずれにしても状況を調べようとしてリンクをクリックしてしまうことを詐欺師は期待しているのかもしれません。 メールに書かれたリンクからフィッシングドメインを調べると、正規の航空会社の Web サイトが詐欺師によって複製されていたことがわかりますが、ここにも詐欺師の手抜きがあり、偽の Web サイトは正しく表示されません。 この偽サイトでは、ユーザーが航空会社に登録しているアカウントのカード番号とパスワードを入力するよう求めています。ダミーの情報を入力したらどうなるかを調べようとしましたが、偽サイトは正しく機能せず、Web フォームが表示されません。Web フォームが壊れていて情報を盗み出せない以上、この詐欺師の努力はすべて水の泡です。そのため、今回の詐欺師の意図を見きわめるのは難しいのですが、Web フォームが機能すれば、クレジットカードと銀行口座の情報を入力するように要求されることは容易に想像できます。 メールに記されたフィッシングドメインの Whois 情報にも特筆すべき点があります。ドメインは 2 週間前に登録されたばかりですが、その登録先は著名な航空機メーカーのユーザーのメールアドレスだったのです。このことから、詐欺師はこのユーザーのメールアカウントに侵入して銀行やクレジットカードの情報を盗み出したうえで、自身の名前で偽のドメインを登録した可能性があります。このドメインの Whois 情報を見ることのできるユーザーであれば、正規の有名企業に登録されているドメインということで本物と思い込んでしまうかもしれません。 メールの署名に使われている FSA 登録番号は、まったく別の航空会社のもので、詐称されている会社の番号ではありません。今回の詐欺は Web サイトが正しく表示されないために失敗しますが、偽の Web サイトをもっと本物らしく見せ、メールの情報に間違いがないことを確認するだけの十分な時間をかけていたら、もっと判別が難しくなっていたかもしれません。 シマンテックの高度な監視システムでは、この詐欺も未然に識別され遮断されました。   * 日本語版セキュリティレスポンスブログの RSS フィードを購読するには、http://www.symantec.com/connect/ja/item-feeds/blog/2261/feed/all/ja にアクセスしてください。]]></description>
			<content:encoded><![CDATA[<p>最近、航空券予約の確認を装うフィッシングメールが出回っています。フィッシングとして新しい手口ではありませんが、今回のメールとフィッシングに関連する Web サイトは特徴的で、一見したところ正規のサイトのように見えます。メールには、クレジットカードでの支払いを確認する文面が書かれており、航空券とフライト情報を印刷するには本文中のリンクをクリックするように指示されています。</p>
<p><img alt="" src="http://www.itsecuresite.com/wp-content/plugins/RSSPoster_PRO/cache/05f38__original" /></p>
<p>メール自体はテキスト形式で、特に変わったところはないように見えます。しかし、さらに詳しく調べると、送信元のドメインが詐称されており、実際には航空会社とも関係がないことがわかりました。よく似てはいますが、詐称されている実際の送信元ドメインは空気清浄機と掃除機の会社であり、航空会社とは縁もゆかりもありません。詐称しようとしている航空会社と送信元 Web サイトが一致するかどうかを確認しなかったのはスパマーの怠慢だったようで、用心深いユーザーにはメールの信憑性がすぐに疑われてしまうでしょう。もちろん、航空券を予約していなければすぐ不審に思うところですが、このメールを誤配信と考えたユーザーが、いずれにしても状況を調べようとしてリンクをクリックしてしまうことを詐欺師は期待しているのかもしれません。</p>
<p>メールに書かれたリンクからフィッシングドメインを調べると、正規の航空会社の Web サイトが詐欺師によって複製されていたことがわかりますが、ここにも詐欺師の手抜きがあり、偽の Web サイトは正しく表示されません。</p>
<p><img alt="" src="http://www.itsecuresite.com/wp-content/plugins/RSSPoster_PRO/cache/05f38__original" /></p>
<p>この偽サイトでは、ユーザーが航空会社に登録しているアカウントのカード番号とパスワードを入力するよう求めています。ダミーの情報を入力したらどうなるかを調べようとしましたが、偽サイトは正しく機能せず、Web フォームが表示されません。Web フォームが壊れていて情報を盗み出せない以上、この詐欺師の努力はすべて水の泡です。そのため、今回の詐欺師の意図を見きわめるのは難しいのですが、Web フォームが機能すれば、クレジットカードと銀行口座の情報を入力するように要求されることは容易に想像できます。</p>
<p>メールに記されたフィッシングドメインの Whois 情報にも特筆すべき点があります。ドメインは 2 週間前に登録されたばかりですが、その登録先は著名な航空機メーカーのユーザーのメールアドレスだったのです。このことから、詐欺師はこのユーザーのメールアカウントに侵入して銀行やクレジットカードの情報を盗み出したうえで、自身の名前で偽のドメインを登録した可能性があります。このドメインの Whois 情報を見ることのできるユーザーであれば、正規の有名企業に登録されているドメインということで本物と思い込んでしまうかもしれません。</p>
<p>メールの署名に使われている FSA 登録番号は、まったく別の航空会社のもので、詐称されている会社の番号ではありません。今回の詐欺は Web サイトが正しく表示されないために失敗しますが、偽の Web サイトをもっと本物らしく見せ、メールの情報に間違いがないことを確認するだけの十分な時間をかけていたら、もっと判別が難しくなっていたかもしれません。</p>
<p>シマンテックの高度な監視システムでは、この詐欺も未然に識別され遮断されました。</p>
<p> </p>
<p>* 日本語版セキュリティレスポンスブログの RSS フィードを購読するには、<a href="http://www.symantec.com/connect/ja/item-feeds/blog/2261/feed/all/ja">http://www.symantec.com/connect/ja/item-feeds/blog/2261/feed/all/ja</a> にアクセスしてください。</p>
]]></content:encoded>
			<wfw:commentRss>http://www.itsecuresite.com/seclabs/symantec/%e8%88%aa%e7%a9%ba%e5%88%b8%e4%ba%88%e7%b4%84%e7%a2%ba%e8%aa%8d%e3%81%ae%e3%83%95%e3%82%a3%e3%83%83%e3%82%b7%e3%83%b3%e3%82%b0.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Twitter To Reach 500 Million Users Any Minute Now?</title>
		<link>http://www.itsecuresite.com/seclabs/websense/twitter-to-reach-500-million-users-any-minute-now.html</link>
		<comments>http://www.itsecuresite.com/seclabs/websense/twitter-to-reach-500-million-users-any-minute-now.html#comments</comments>
		<pubDate>Wed, 22 Feb 2012 11:31:28 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Websense]]></category>

		<guid isPermaLink="false">http://www.itsecuresite.com/seclabs/websense/twitter-to-reach-500-million-users-any-minute-now.html</guid>
		<description><![CDATA[Twitter To Reach 500 Million Users Any Minute Now? There have been reports from several sources that Twitter is quick coming a miracle of 500 million users.  We take a demeanour during what this could meant for us all and take a contemplative demeanour behind on some of a issues that Twitter users have faced [...]]]></description>
			<content:encoded><![CDATA[<p>                    Twitter To Reach 500 Million Users Any Minute Now?<br />
                    </p>
<p>There have been reports from several sources that Twitter is quick coming a miracle of 500 million users.  We take a demeanour during what this could meant for us all and take a contemplative demeanour behind on some of a issues that Twitter users have faced over a years.</p>
<p> </p>
<p>What does that figure meant to us?</p>
<ul>
<li>This series of Twitter users is 60% some-more than a race of a United States of America (according to the <a href="http://www.census.gov/popest/data/national/totals/2011/index.html">U.S. Census Bureau</a>).</li>
<li>That figure is 8 times a race of a United Kingdom.</li>
<li>The estimate tellurian race of Earth in 1550 AD was 500 million.</li>
</ul>
<p> </p>
<p>Of course, not all Twitter users are who they explain to be. </p>
<p>You are substantially informed with saying a design of an appealing particular gracing your supporter list and afterwards realizing that a supporter is only perplexing to pass off think medication. The abuse of Twitter by spammers and bot networks is zero new and something we have seen in Websense® Security Labs™ for several years now. Over a past few years, we have seen bot networks take their instruction from generated Twitter users. We have also seen website compromises on a large scale regulating Twitter trending topics to beget a antagonistic domain they hit next. </p>
<p> </p>
<p>Malware authors and spammers burst on amicable networks in a wish that they can fast widespread their wares: 500 million users, 200 million users, even 100 million users yield a scale and network connectivity to do accurately this.</p>
<p> </p>
<p>Here are some of a not-so-high Twitter highlights of a final 5 years:</p>
<p><img src="http://www.itsecuresite.com/wp-content/plugins/RSSPoster_PRO/cache/2a745_1513.Twitter-500m-users.jpg" border="0" alt="" /></p>
<p> </p>
<p>Is there any hope?</p>
<p>Behind each cloud is a china backing and Twitter is no exception.  Our Websense Social Web Controls as good as a ThreatSeeker® Network can assistance to extent a bearing from threats on amicable networks. You can find out some-more on <a href="http://www.websense.com/">www.websense.com</a>.</p>
<p> </p>
<p>From bread bakers to candlestick makers, from celebrities to pharmacists, 500 million users/spammers/bots have incited to Twitter to share their lives and rivet in 140-character exchanges with others. Have you?</p>
<p> </p>
<p>Regards,</p>
<p><a href="https://twitter.com/websenselabs">https://twitter.com/websenselabs</a></p>
</p>
<p>Carl Leonard</p>
<p>
<h4 class="contentsubheading">Leave a Comment</h4>
<p>                                                  </p>
<p>                         <label for="ctl00_Main_ctl10_ctl00_ctl02_ctl02_chkRemember"> Remember me</label></p>
]]></content:encoded>
			<wfw:commentRss>http://www.itsecuresite.com/seclabs/websense/twitter-to-reach-500-million-users-any-minute-now.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>McAfee Q4 Threats Report Shows Malware Surpassed 75 Million Samples in 2011</title>
		<link>http://www.itsecuresite.com/seclabs/mcafee/mcafee-q4-threats-report-shows-malware-surpassed-75-million-samples-in-2011.html</link>
		<comments>http://www.itsecuresite.com/seclabs/mcafee/mcafee-q4-threats-report-shows-malware-surpassed-75-million-samples-in-2011.html#comments</comments>
		<pubDate>Wed, 22 Feb 2012 11:31:19 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[McAfee]]></category>

		<guid isPermaLink="false">http://www.itsecuresite.com/seclabs/mcafee/mcafee-q4-threats-report-shows-malware-surpassed-75-million-samples-in-2011.html</guid>
		<description><![CDATA[Today we expelled a Fourth Quarter 2011 Threat Report, divulgence that malware surpassed a a guess of 75 million singular malware samples final year. Although a recover of new malware slowed a bit in Q4, mobile malware continued to boost and available a busiest year to date. Malware The altogether expansion of PC-based malware indeed [...]]]></description>
			<content:encoded><![CDATA[<p>					<!--  --><br />
					<!--  --><br />
					<!--  --><br />
					<!--  --><br />
					<!--  --><br />
					<!--  --><br />
					<!--  --><br />
					<img src="http://www.itsecuresite.com/wp-content/plugins/RSSPoster_PRO/cache/fa4fa_6.jpg" alt="David Marcus" width="141" height="150" class="post-photo-first" /><!-- AddThis Button Begin -->
<p>Today we expelled a Fourth Quarter 2011 Threat Report, divulgence that malware surpassed a a guess of 75 million singular malware samples final year. Although a recover of new malware slowed a bit in Q4, mobile malware continued to boost and available a busiest year to date.</p>
<p><strong>Malware</strong></p>
<p>The altogether expansion of PC-based malware indeed declined around Q4 2011, and is significantly reduce than Q4 2010. The accumulative series of singular malware samples in a collection still exceeds a 75 million mark. In total, both 2011 and a fourth entertain were by distant a busiest durations for mobile malware that McAfee has seen yet, with Android resolutely bound as a largest aim for writers of mobile malware.</p>
<p>Contributing to a arise in malware were rootkits, or secrecy malware. Though rootkits are some of a many worldly classifications of malware, designed to hedge showing and â€œliveâ€� on a complement for a enlarged period, they showed a slight decrease in Q4. Fake AV forsaken extremely from Q3, while AutoRun and password-stealing Trojan malware uncover medium declines. In a pointy contrariety to Q2 2011, Mac OS malware has remained during really low levels a final dual quarters.</p>
<p><strong>Web Threats </strong></p>
<p>In a third entertain McAfee Labs available an normal of 6,500 new bad sites per day; this figure shot adult to 9,300 sites in Q4. Approximately one in each 400 URLs were antagonistic on average, and during their top levels, approximately one in each 200 URLs were malicious. This brings a sum of active antagonistic URLs to some-more than 700,000.<br />
The immeasurable infancy of new antagonistic sites are located in a United States, followed by a Netherlands, Canada, South Korea and Germany. Overall, North America housed a largest volume of servers hosting antagonistic content, during some-more than 73 percent, followed by Europe-Middle East during some-more than 17 percent and Asia Pacific during 7 percent.<br />
Spam</p>
<p>At a finish of 2011, tellurian spam reached a lowest indicate in years, generally in areas such as a United Kingdom, Brazil, Argentina and South Korea. Despite a dump in tellurian levels, McAfee Labs found that a benefaction spearphishing and spam are rarely sophisticated.</p>
<p>Overall botnet expansion rebounded in Nov and Dec after descending given August, with Brazil, Columbia, India, Spain and a United States all saying poignant increases. Germany, Indonesia and Russia declined. Of a botnets, Cutwail continues to power supreme, while Lethic has been on a solid decrease given final quarter. Grum done a poignant quip after a prolonged decline, heading Bobax and Lethic by a finish of Q4.</p>
<p><strong>Data Breaches</strong></p>
<p>The series of reports of information breaches around hacking, malware, rascal and insiders some-more than doubled given 2009, according to privacyrights.org, with some-more than 40 breaches publicly reported this entertain alone. The heading network hazard this entertain came around vulnerabilities in Microsoft Windows remote procession calls. This was followed closely by SQL injection and cross-site scripting attacks. These remote attacks can be launched during comparison targets around a globe.</p>
<p>Download <a href="http://www.mcafee.com/us/resources/reports/rp-quarterly-threat-q4-2011.pdf" target="_blank">McAfeeâ€™s Threats Report: Fourth Quarter 2011</a>.
</p>
<p><a class="addthis_button" href="//addthis.com/bookmark.php?v=250"></a>					</p>
<p><strong>Tags:</strong> <a href="http://blogs.mcafee.com/tag/android" rel="tag">Android</a>, <a href="http://blogs.mcafee.com/tag/cybercrime" rel="tag">Cybercrime</a>, <a href="http://blogs.mcafee.com/tag/data-breach" rel="tag">data breach</a>, <a href="http://blogs.mcafee.com/tag/data-protection" rel="tag">Data Protection</a>, <a href="http://blogs.mcafee.com/tag/endpoint-protection" rel="tag">Endpoint Protection</a>, <a href="http://blogs.mcafee.com/tag/tag-enterprise" rel="tag">enterprise</a>, <a href="http://blogs.mcafee.com/tag/facebook" rel="tag">facebook</a>, <a href="http://blogs.mcafee.com/tag/global-threat-intelligence" rel="tag">global hazard intelligence</a>, <a href="http://blogs.mcafee.com/tag/identity-protection" rel="tag">identity protection</a>, <a href="http://blogs.mcafee.com/tag/identity-thieves-and-cybercriminals" rel="tag">Identity thieves and cybercriminals</a>, <a href="http://blogs.mcafee.com/tag/malware" rel="tag">malware</a>, <a href="http://blogs.mcafee.com/tag/mobile-security" rel="tag">mobile security</a>, <a href="http://blogs.mcafee.com/tag/network-security" rel="tag">Network Security</a>, <a href="http://blogs.mcafee.com/tag/risk-and-compliance" rel="tag">Risk and Compliance</a>, <a href="http://blogs.mcafee.com/tag/security" rel="tag">security</a>, <a href="http://blogs.mcafee.com/tag/social-networking" rel="tag">social networking</a>, <a href="http://blogs.mcafee.com/tag/spam" rel="tag">spam</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.itsecuresite.com/seclabs/mcafee/mcafee-q4-threats-report-shows-malware-surpassed-75-million-samples-in-2011.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Chrome might get a cue generator</title>
		<link>http://www.itsecuresite.com/general/chrome-may-get-a-password-generator.html</link>
		<comments>http://www.itsecuresite.com/general/chrome-may-get-a-password-generator.html#comments</comments>
		<pubDate>Tue, 21 Feb 2012 11:29:07 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[General Security]]></category>

		<guid isPermaLink="false">http://www.itsecuresite.com/general/chrome-may-get-a-password-generator.html</guid>
		<description><![CDATA[Chrome will be means to beget passwords for you Source: Google Google&#8217;s resolution for a problem of removing improved passwords on a net – a multiple of browser sign-in and OpenID – will take some time to exercise as it involves persuading sites to switch to regulating OpenID. The developers on a Chrome plan consider [...]]]></description>
			<content:encoded><![CDATA[<p>	<!-- RSPEAK_STOP --><br />
	<span class="pic_right"><br />
		<img src="http://www.itsecuresite.com/wp-content/plugins/RSSPoster_PRO/cache/104cb_6bdd9b29ba051a0c.png" width="250" height="104" alt="" /></p>
<p><span class="pic_caption"><br />
			Chrome will be means to beget passwords for you</p>
<p>			<img src="http://www.itsecuresite.com/wp-content/plugins/RSSPoster_PRO/cache/104cb_lupe.png" alt="Zoom" width="16" height="16" /></p>
<p>		</span></p>
<p><span class="source">Source: Google</span></p>
<p>	</span><br />
	<!-- RSPEAK_START --><br />
Google&#8217;s resolution for a problem of removing improved passwords on a net – a multiple of browser sign-in and <a href="http://openid.net/" rel="external">OpenID</a> – will take some time to exercise as it involves persuading sites to switch to regulating OpenID. The developers on a Chrome plan consider that they can during slightest urge a confidence of passwords on sites, by generating passwords for a user. A new <a href="https://sites.google.com/a/chromium.org/dev/developers/design-documents/password-generation" rel="external">Password Generation</a> offer for a Chromium and Chrome browsers attempts to residence that by presumption that once a user is sealed into a browser, it can take over a doing of cue creation.</p>
<p>When a user is stirred by a web site for a username and dual cue fields, or some other heuristic for detecting when passwords will need to be generated, a prolongation will advise an suitable cue in a pop-up from a initial cue field. It will not automatically enter that new cue for them since sites mostly have sold mandate in cue formatting, though a designers wish that, in future, they could parse a HTML5 charge <code>pattern</code> for a cue margin and make a some-more suitable pointless password. If a user accepts a new password, it is entered into both fields and is stored, encrypted in a browser.</p>
<p>If a complement is implemented afterwards it would see Google contest with a series of blurb products that beget browser-neutral passwords and conduct and sync them over cloud services. It would also make a Chrome browser a most aloft value aim for hackers to take control of. The underline is now listed among a <a href="https://sites.google.com/a/chromium.org/dev/developers/design-documents" rel="external">design documents</a> of a Chromium browser, though it is misleading when it would seem in a destiny book of a browser.</p>
<p>(<!--googleoff: index-->djwm)</p>
]]></content:encoded>
			<wfw:commentRss>http://www.itsecuresite.com/general/chrome-may-get-a-password-generator.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Security awareness, confidence breaches, and a abuse of “stupid”</title>
		<link>http://www.itsecuresite.com/seclabs/eset/security-awareness-security-breaches-and-the-abuse-of-%e2%80%9cstupid%e2%80%9d.html</link>
		<comments>http://www.itsecuresite.com/seclabs/eset/security-awareness-security-breaches-and-the-abuse-of-%e2%80%9cstupid%e2%80%9d.html#comments</comments>
		<pubDate>Tue, 21 Feb 2012 11:28:59 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Eset]]></category>

		<guid isPermaLink="false">http://www.itsecuresite.com/seclabs/eset/security-awareness-security-breaches-and-the-abuse-of-%e2%80%9cstupid%e2%80%9d.html</guid>
		<description><![CDATA[Computer confidence is not created, nor is it improved, by job people stupid. That&#8217;s a end we have arrived during after some-more than dual decades in mechanism confidence and auditing. To put it another way, we should stop dropping a &#8220;S&#8221; bomb, generally when it comes to people who don&#8217;t know any better. Consider a [...]]]></description>
			<content:encoded><![CDATA[<p>Computer confidence is not created, nor is it improved, by job people stupid. That&#8217;s a end we have arrived during after some-more than dual decades in mechanism confidence and auditing. To put it another way, we should stop dropping a &#8220;S&#8221; bomb, generally when it comes to people who don&#8217;t know any better.</p>
<p><img alt="" class="alignright size-full wp-image-11697" height="575" src="http://www.itsecuresite.com/wp-content/plugins/RSSPoster_PRO/cache/f7c17_exposed-card.png" width="484" />Consider a materialisation of people posting photos of credit cards on Facebook, a arrange of self-inflicted confidence breach. Your initial greeting competence be &#8220;Is that foolish or what?&#8221;</p>
<p>In my opinion a &#8220;or what?&#8221; is a satisfactory question, one that we suspicion about this President&#8217;s Day, a day when a lot of credit cards in America get a good examination (with a important difference of a one in this picture).</p>
<p>Note that what you&#8217;re saying is a doctored chronicle of what indeed seemed on Facebook, where a sum on a front of credit label were clearly visible. These have been masked in this screenshot, along with other identifying information (I have attempted to find out who constructed a above picture in sequence to give them credit, as it were, though so distant I&#8217;ve not succeeded).</p>
<p>Also note that a chairman who posted a pic does not seem to be a label owner, so it&#8217;s not a box of &#8220;stupid child posts print of his initial credit card&#8221; that is how some bloggers described it (although we am certain there are cases of that kind as well). No, this is only a box of a person, presumably a parent, being unapproachable of that &#8220;first credit card&#8221; moment, and wanting to share it with friends and family. This chairman was substantially in a same state of mind as many other Facebook users who:</p>
<p>A. Think of Facebook as a place to share things with a few name friends, though have not practiced their &#8220;share&#8221; settings accordingly, and;</p>
<p>B. Under-estimate a series of people who are peaceful to take advantage of their associate tellurian beings.</p>
<p>In other difference &#8220;they don&#8217;t know any better&#8221; and presumably miss a kind of life practice that make other people consider twice about putting a print like that online. Now, we don&#8217;t know what commission of Facebook&#8217;s 800+ million users are now A+B positive, so to speak, though they paint a abounding capillary of potentially exploitable persons. Fraudsters and fraud artists are penetrating to cave that vein, as evidenced by a consistent coming of new deceptions documented by websites like <a href="http://facecrooks.com/" target="_blank">Facecrooks</a>.</p>
<p>What should unequivocally be of regard to companies, and multitude during large, is that these A+B folks are not only a aim on Facebook. Criminals are targeting users who miss confidence recognition opposite a far-reaching operation of information systems. They are crafting attacks that rest on exploiting digital device users who have small or no confidence training.</p>
<p>So a subsequent time we hear infosec professionals bemoaning a irrationality of users we need to ask: &#8220;Are they foolish since they are ignoring a confidence training they received, or are they doing foolish things since we have failed, as an organization, and as a society, to learn them to know better?&#8221;</p>
<p>And while we&#8217;re during it, what contend we cut Shannon and Dustin a break!</p>
<p>.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.itsecuresite.com/seclabs/eset/security-awareness-security-breaches-and-the-abuse-of-%e2%80%9cstupid%e2%80%9d.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Poll: What is a Coolest Feature on msnNOW?</title>
		<link>http://www.itsecuresite.com/seclabs/microsoft/poll-what-is-the-coolest-feature-on-msnnow.html</link>
		<comments>http://www.itsecuresite.com/seclabs/microsoft/poll-what-is-the-coolest-feature-on-msnnow.html#comments</comments>
		<pubDate>Mon, 20 Feb 2012 17:25:08 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Microsoft]]></category>

		<guid isPermaLink="false">http://www.itsecuresite.com/seclabs/microsoft/poll-what-is-the-coolest-feature-on-msnnow.html</guid>
		<description><![CDATA[Last week, Microsoft launched msnNOW, a new use from MSN during now.msn.com, combined to assistance we stay in a know. msnNOW is a initial use to aspect a latest hum from Facebook, Twitter, Bing and BreakingNews.com, all in one place. Obviously, we here during Microsoft consider it’s flattering cool, though we’d like to know that [...]]]></description>
			<content:encoded><![CDATA[<p>Last week, <a href="http://www.microsoft.com/presspass/features/2012/feb12/02-15msnNOW.mspx">Microsoft launched msnNOW</a>, a new use from <a href="http://www.msn.com">MSN</a> during <a href="http://now.msn.com/">now.msn.com</a>, combined to assistance we stay in a know. msnNOW is a initial use to aspect a latest hum from Facebook, Twitter, Bing and BreakingNews.com, all in one place.</p>
<p>Obviously, we here during Microsoft consider it’s flattering cool, though we’d like to know that facilities of msnNOW readers like a most.</p>
<p>a href=&#8221;http://www.zoomerang.com/&#8221;Online Surveys &#8211; Zoomerang.com/a</p>
<p>Thanks for voting!</p>
<p>Posted by <strong>Jeff Meisner</strong> <br />Editor, The Official Microsoft Blog</p>
]]></content:encoded>
			<wfw:commentRss>http://www.itsecuresite.com/seclabs/microsoft/poll-what-is-the-coolest-feature-on-msnnow.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Mozilla takes movement opposite CAs arising man-in-the-middle certificates</title>
		<link>http://www.itsecuresite.com/general/mozilla-takes-action-against-cas-issuing-man-in-the-middle-certificates.html</link>
		<comments>http://www.itsecuresite.com/general/mozilla-takes-action-against-cas-issuing-man-in-the-middle-certificates.html#comments</comments>
		<pubDate>Mon, 20 Feb 2012 11:24:27 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[General Security]]></category>

		<guid isPermaLink="false">http://www.itsecuresite.com/general/mozilla-takes-action-against-cas-issuing-man-in-the-middle-certificates.html</guid>
		<description><![CDATA[In an email to acceptance authorities (CAs), a Mozilla Foundation has asked CAs not to emanate certificates for sub-CAs that can be used to guard encrypted data. The ask is being done in a context of a recently suggested case, in that Trustwave set adult a man-in-the-middle CA. Trustwave sole a CA certificate to another [...]]]></description>
			<content:encoded><![CDATA[<p>	<!-- RSPEAK_STOP --><br />
	<span class="pic_right"><br />
		<img src="http://www.itsecuresite.com/wp-content/plugins/RSSPoster_PRO/cache/5668d_crypto_or_80-81decbf7c0a5c03c.png" width="80" height="80" alt="Crypto icon" /></span><br />
	<!-- RSPEAK_START --><br />
In an <a href="https://wiki.mozilla.org/CA%3ACommunications#February_17.2C_2012" rel="external">email</a> to acceptance authorities (CAs), a Mozilla Foundation has asked CAs not to emanate certificates for sub-CAs that can be used to guard encrypted data. The ask is being done in a context of a recently suggested case, in that Trustwave set adult a man-in-the-middle CA. </p>
<p>Trustwave sole a CA certificate to another association that enabled it to emanate current certificates for any server. This enabled a latter association to guard encrypted trade sent and perceived by a possess staff regulating what was effectively a man-in-the-middle attack. Trustwave has given revoked a CA certificate and has announced that it will, in future, no longer promote sub-CAs of this nature. </p>
<p>The letter, sealed by Kathleen Wilson, who is obliged for a CA procedure used in Mozilla software, requests that all CAs respond by 2 March and determine to devaluate any sub-certificates that capacitate third parties to eavesdrop on information trade by 27 April. Any analogous <a href="http://en.wikipedia.org/wiki/Hardware_security_module" rel="external">HSM</a>s and smartcards also have to be destroyed. </p>
<p>Mozilla baldly asserts that if any such sub-CAs are detected after a 27 April deadline, a substructure will take whatever stairs are necessary, including stealing a base certificate from Mozilla program if required. Wilson also intends to tell a CAs responses to her email. The email includes a couple to Mozilla&#8217;s <a href="http://www.mozilla.org/projects/security/certs/policy/WorkInProgress/" rel="external">rules</a> on including base certificates in a products – these manners are now being revised. </p>
<p>Mozilla developers have expelled a <a href="https://bugzilla.mozilla.org/show_bug.cgi?id=724929#c67" rel="external">patch</a> that outlines sub-CAs chaining to Trustwave CA as untrusted. The patch would seem to mislay a hazard of instituting a direct done by a reader of The H&#8217;s associates during <a href="http://www.heise.de/security" rel="external">heise Security</a> for a evident dismissal of Trustwave from a list of devoted CAs. Credit has clearly been given for a fact that Trustwave willingly disclosed a occurrence and has already revoked a certificate in question. </p>
<p>Mozilla is but creation it unambiguously transparent that it will not endure MITM CAs in future. It will be engaging to see what arrange of response it receives. On creation a disclosure, Trustwave suggested that it was customary use within a industry. Symantec, that owns CA Verisign, has not responded to an enquiry from heise Security as to either it issues CA certificates for monitoring purposes. </p>
<p>(<!--googleoff: index-->djwm)</p>
]]></content:encoded>
			<wfw:commentRss>http://www.itsecuresite.com/general/mozilla-takes-action-against-cas-issuing-man-in-the-middle-certificates.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

