Close
  • Latest News
  • Artificial Intelligence
  • Video
  • Big Data and Analytics
  • Cloud
  • Networking
  • Cybersecurity
  • Applications
  • IT Management
  • Storage
  • Sponsored
  • Mobile
  • Small Business
  • Development
  • Database
  • Servers
  • Android
  • Apple
  • Innovation
  • Blogs
  • PC Hardware
  • Reviews
  • Search Engines
  • Virtualization
Read Down
Sign in
Close
Welcome!Log into your account
Forgot your password?
Read Down
Password recovery
Recover your password
Close
Search
Logo
Subscribe
Logo
  • Latest News
  • Artificial Intelligence
  • Video
  • Big Data and Analytics
  • Cloud
  • Networking
  • Cybersecurity
  • Applications
  • IT Management
  • Storage
  • Sponsored
  • Mobile
  • Small Business
  • Development
  • Database
  • Servers
  • Android
  • Apple
  • Innovation
  • Blogs
  • PC Hardware
  • Reviews
  • Search Engines
  • Virtualization
More
    Subscribe
    Home Cybersecurity
    • Cybersecurity

    Web Heroics Wanted

    Written by

    Jim Rapoza
    Published July 31, 2006
    Share
    Facebook
    Twitter
    Linkedin

      eWEEK content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More.

      Tina Turner once said that we dont need another hero, but I dont know if I agree. I know that Ive been looking for a hero in my ongoing trials and tribulations with Internet security.

      What form would this hero take? Would he or she be a hero who takes on the trends and attitudes that lead to software vendors releasing sloppy and poorly secured code that the bad guys take advantage of?

      In addition to making sure that vendors didnt release code full of bugs, this kind of hero would make sure that software makers would act quickly to address any problems that did arise and not hide the problem from users.

      In recent months, a person has been positioning himself as this kind of hero: security researcher HD Moore. Moore, famous for creating the open-source penetration testing tool Metasploit (and for creating controversy in the vulnerability testing community), has recently launched a few high-profile projects to expose serious vulnerabilities on the Internet.

      One of these was his Month of Browser Bugs project, in which he released information on one active security flaw in a popular Web browser every day for the month of July. Also in July, Moore created a search engine on top of Google that made it possible to look for Trojans and other malware publicly available on Web sites.

      While Moores projects have angered some vendors, security researchers and (according to Moore) black-hat hackers, I think they are a good thing, for the most part.

      To me, a flaw that has been publicly outed is much better than one that a vendor has kept hidden—you know that the bad guys are already using these flaws, and, by knowing about them, you can protect yourself. And Moores search engine application will make it easier for many sites to find Trojans and other bad code that they may not even know is on their site.

      /zimages/6/28571.gifFor advice on how to secure your network and applications, as well as the latest security news, visit Ziff Davis Internets Security IT Hub.

      All that said, I dont think Moore qualifies as a full-fledged hero.

      A person worthy of the cape, though, would be someone who could get people to actually take basic precautions when it comes to Web browsing and e-mail use. Peoples steadfast and totally ridiculous refusal to do so is one of the things that makes it so easy for viruses and Trojans to spread across the Internet.

      /zimages/6/28571.gifHD Moore, creator of Metasploit, releases a search engine that finds live malware samples by using Google. Click here to read more.

      For years now, Ive been trying every method I can think of to get through to these Gomer Pyles—from shaming them to laughing at their idiocy to appealing to their common sense. But, still, viruses and Trojans spread through attachments and phishing techniques that shouldnt fool a monkey. But then I saw a headline on the news site Ars Technica that made me think that, finally, the right kind of hero would come through to make people use the Internet safely: “Jack Bauer promotes common sense Internet safety.” Yes!

      When it comes to getting people to be smart about using the Internet, who better than Jack Bauer of “24”? I mean, if the guy can intimidate presidents, he can handle Joe in marketing.

      Think about it: There you are, sitting at your desk, irresponsibly opening any e-mail attachment that comes your way, surfing questionable Web sites, loading software sent to you from a Syrian e-mail address—just having a grand old irresponsible time. But then Jack Bauer walks over, grabs you by the collar and says, “You can start using the Internet safely now, or you can start using the Internet safely later. But later is going to hurt a lot more.”

      Yikes! Youd be virus scanning and ignoring attachments in no time.

      But it turns out that the headline above was referring to the fact that actor Kiefer Sutherland, who plays Jack Bauer on “24,” is promoting safe Internet usage for teens at the site commonsense.com—a worthy cause, but it wont help too much at stopping strange-attachment lovers.

      So, I guess I wont have Jack Bauer around to break the fingers of irresponsible Internet users. And while I applaud Moores projects, he alone wont change the culture of many software vendors that dont rank security as a top priority. Well just have to keep doing our best to educate those around us and to secure our systems. To quote David Bowie, “We can be heroes.”

      Labs Director Jim Rapoza can be reached at [email protected].

      /zimages/6/28571.gifCheck out eWEEK.coms for the latest security news, reviews and analysis. And for insights on security coverage around the Web, take a look at eWEEK.com Security Center Editor Larry Seltzers Weblog.

      Jim Rapoza
      Jim Rapoza
      Jim Rapoza, Chief Technology Analyst, eWEEK.For nearly fifteen years, Jim Rapoza has evaluated products and technologies in almost every technology category for eWEEK. Mr Rapoza's current technology focus is on all categories of emerging information technology though he continues to focus on core technology areas that include: content management systems, portal applications, Web publishing tools and security. Mr. Rapoza has coordinated several evaluations at enterprise organizations, including USA Today and The Prudential, to measure the capability of products and services under real-world conditions and against real-world criteria. Jim Rapoza's award-winning weekly column, Tech Directions, delves into all areas of technologies and the challenges of managing and deploying technology today.

      Get the Free Newsletter!

      Subscribe to Daily Tech Insider for top news, trends & analysis

      Get the Free Newsletter!

      Subscribe to Daily Tech Insider for top news, trends & analysis

      MOST POPULAR ARTICLES

      Artificial Intelligence

      9 Best AI 3D Generators You Need...

      Sam Rinko - June 25, 2024 0
      AI 3D Generators are powerful tools for many different industries. Discover the best AI 3D Generators, and learn which is best for your specific use case.
      Read more
      Cloud

      RingCentral Expands Its Collaboration Platform

      Zeus Kerravala - November 22, 2023 0
      RingCentral adds AI-enabled contact center and hybrid event products to its suite of collaboration services.
      Read more
      Artificial Intelligence

      8 Best AI Data Analytics Software &...

      Aminu Abdullahi - January 18, 2024 0
      Learn the top AI data analytics software to use. Compare AI data analytics solutions & features to make the best choice for your business.
      Read more
      Latest News

      Zeus Kerravala on Networking: Multicloud, 5G, and...

      James Maguire - December 16, 2022 0
      I spoke with Zeus Kerravala, industry analyst at ZK Research, about the rapid changes in enterprise networking, as tech advances and digital transformation prompt...
      Read more
      Video

      Datadog President Amit Agarwal on Trends in...

      James Maguire - November 11, 2022 0
      I spoke with Amit Agarwal, President of Datadog, about infrastructure observability, from current trends to key challenges to the future of this rapidly growing...
      Read more
      Logo

      eWeek has the latest technology news and analysis, buying guides, and product reviews for IT professionals and technology buyers. The site’s focus is on innovative solutions and covering in-depth technical content. eWeek stays on the cutting edge of technology news and IT trends through interviews and expert analysis. Gain insight from top innovators and thought leaders in the fields of IT, business, enterprise software, startups, and more.

      Facebook
      Linkedin
      RSS
      Twitter
      Youtube

      Advertisers

      Advertise with TechnologyAdvice on eWeek and our other IT-focused platforms.

      Advertise with Us

      Menu

      • About eWeek
      • Subscribe to our Newsletter
      • Latest News

      Our Brands

      • Privacy Policy
      • Terms
      • About
      • Contact
      • Advertise
      • Sitemap
      • California – Do Not Sell My Information

      Property of TechnologyAdvice.
      © 2024 TechnologyAdvice. All Rights Reserved

      Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.