Dennis Fisher

PGP Opens Up Encryption Source Code

Newly formed PGP Corp. took a big step Monday toward endearing itself to cryptography enthusiasts and privacy advocates by releasing the source code for its flagship line of encryption products. The code for the entire PGP 8.0 line—which was also introduced Monday—is available on the companys Web site for free download. This move is a […]

RealPlayer Still Vulnerable to Attack

Nearly two weeks after posting a faulty patch for several security vulnerabilities in its ubiquitous RealPlayer and RealOne software, Real Networks Inc. has yet to release a working fix for the problems. And, a security researcher said Tuesday that he has discovered five more vulnerabilities in the media players. Mark Litchfield of Next Generation Security […]

Security Firm Deserts Users

A company that once promised to find stolen corporate laptops is now itself missing in action. And left behind are countless customers stuck for the prepaid service and saddled with a software agent that not only resists being disabled but can still transmit sensitive data over the Internet. Lucira Technologies Inc. has been defunct since […]

Liberty Alliance Waves White Flag at Passport

A growing rift among members of the Liberty Alliance authentication project is placing the technologys future in question. At the core of the problem is exactly where to target the single-sign-on technology in the face of stiff and growing client-side competition from Microsoft Corp.s Passport service. Officials at the Liberty Alliances founder and chief sponsor, […]

Open-Source Software Takes Lead as Major Source of Security Flaws

Thanks to several high-profile vulnerabilities and an overall increase in the number of flaws this year, open-source software has taken over Microsoft Corp.s position at the bottom of the security heap. A research note from two analysts at Aberdeen Group Inc. issued last month calls open-source software and Linux distributions the “2002 poster children for […]

ISS Goes Public With Vulnerability Disclosure Guidelines

Internet Security Systems Inc. on Monday released to the public the vulnerability disclosure guidelines that its internal X-Force research team uses in identifying flaws and notifying vendors and the public. The guidelines are fairly standard and include a provision that is becoming more and more common among security vendors that also do vulnerability research. The […]

Hackers Fight Censorship, Human Rights Violations

A hacker group on Tuesday released a novel license agreement that gives end-users the power to enforce the agreement and sue governments and other entities that misuse software covered by the license. The Hacktivismo Enhanced-Source Software License Agreement (HESSLA) is designed to prevent governments, corporations and other organizations from using Hacktivismos applications to censor Internet […]

Zone Labs Gives Admins More Control With Integrity Upgrade

Zone Labs Inc. last week announced the first major upgrade to its Integrity client protection software, adding centralized management and deployment tools. Integrity 2.0 gives administrators more granular control over the rules and policies in place on each desktop, making the product more like a traditional network firewall. Integrity 2.0 comprises a central management console […]

Crossbeam Appliance Taps Flow-Sequencing Technology

Crossbeam Systems Inc. this week will unveil the latest version, 3.5, of its X40S security appliance, which adds a slew of new features in an effort to stay a step ahead in the rapidly growing appliance market. The biggest addition to the appliance is Crossbeams new flow-sequencing technology, which enables administrators to customize the path […]

Availability of Patches Stirs Controversy

An apparent delay in the availability of patches for the vulnerabilities in BIND that were disclosed earlier this month is highlighting the seemingly endless debate over when and to whom vulnerability data should be released. Internet Security Systems Inc.s X-Force research team on Nov. 12 released an advisory warning of three newly discovered vulnerabilities in […]