Adobe released security updates for Flash Player, Adobe Reader and Shockwave Player on Tuesday to address critical vulnerabilities that could allow attackers to take control of systems running vulnerable versions of those programs. The Flash Player updates address four memory corruption vulnerabilities that can lead to arbitrary code execution. The updates are version numbers 11.8.800.168 for Windows and Mac OS X; 11.2.202.310 for Linux; 11.1.115.81 for Android 4.x; and 11.1.111.73 for Android 3.x and 2.x. The same Flash Player vulnerabilities were patched in Adobe AIR, a runtime for rich Internet applications that also bundles Flash Player. Adobe released version 3.8.0.1430 of AIR and AIR SDK (software development kit) for Windows, Mac OS X and Android. <more>
Saturday, September 14, 2013
Saturday, September 7, 2013
Windows 8 Picture Passwords CrackABLE
The "picture passwords" used in Windows 8 machines are more vulnerable than Microsoft hoped, a research team claims. An analysis of more than 10,000 picture passwords found that a significant percentage could be cracked - due to the predictable "points of interest" that users chose. The "gesture" passwords allow users to pick points in an image, instead of using a text-based password. People tend to choose faces, colourful points and eyeglasses, so it's often possible to "guess" such passwords, the team from Arizona State University and Delaware State University said. The team developed algorithms which could crack picture passwords with a high success rate. In a paper presented at the Usenix Conference, "On the Security of Picture Gesture Authentication," the reseearchers, computer science doctoral student Ziming Zhao and computer science master's degree student Jeong-Jin Seo, along with Hongxin Hu, now an assistant professor of at Delaware State University, found that people's choice of "gesture" password tended to follow patterns. <more>
Heartbeat is NOW your Password!!!
Our heartbeats could be used instead of traditional passwords to unlock smartphones, tablets and cars using a new device being developed by Canadian company Bionym. Passwords scrawled on a scrap of paper are easily lost, jumbled letters and numbers are quickly forgotten and, with "password" still the most popular password, it's no wonder that identity theft has become a million-dollar enterprise. But now security experts may have hit upon a type of identification that can't be lost, forgotten, or stolen: your heart. With usernames and passwords fast becoming unreliable, companies are now turning towards our internal features as an authentication alternative. One of the new developments in this line of research is the Nymi wristband being developed by Canadian firm Bionym. The hi-tech gadget monitors the unique pattern of the wearer's heartbeat, which can be used to wirelessly unlock smartphones, tablets, gaming consoles, and cars. It may even be used to pay for shopping, or act as a replacement for your credit card PIN number. <more>
Subscribe to:
Posts (Atom)