Showing posts with label security. Show all posts
Showing posts with label security. Show all posts

Thursday, June 2, 2011

the most secure version of Windows



{SLICK}

At this time, the most secure client version of Windows is the 64-bit version of Windows 7.

I've tried to edit the following to something that is as easily understood as possible...

================================

An Introduction to Kernel Patch Protection

The kernel is the lowest-level, most central part of a computer operating system and one of the first pieces of code to load when the machine starts up. The kernel is what enables the software of the machine to talk to the hardware and is responsible for basic OS housekeeping tasks such as memory management, launching programs and processes, and managing the data on the disk. All applications and even the graphical interface of Windows run on a layer on top of the kernel. The performance, reliability, and security of the entire computer depend on the integrity of the kernel.

The kernel is the most carefully coded piece of the entire operating system. Since all other programs depend upon it, a glitch in the kernel can make all other programs crash or perform unexpectedly. You're probably also familiar with the term, "Blue Screen of Death" (BSoD). This is the result of an error in the kernel or in a driver running in the kernel that is so severe that the system can't recover from it. The BSoD is bad, so we want to do everything we can to keep customers from seeing it. One of the ways we can do that is to maintain the integrity of the kernel by restricting what software is allowed to run in and interact with it.

"Kernel patching" or "kernel hooking" is the practice of using unsupported mechanisms to modify or replace kernel code. Patching fundamentally violates the integrity of the Windows kernel and is undocumented, unsupported and has always been discouraged by Microsoft.  Kernel patching can result in unpredictable behavior, system instability and performance problems—like the Blue Screen of Death–which can lead to lost user productivity and data...

...Kernel Patch Protection was first supported on x64 (AMD64 and Intel EMT64T) CPU architecture versions of Microsoft Windows including Microsoft Windows Server 2003 SP1 and Windows XP Microsoft Windows XP Professional x64 Edition. (Patch protection is currently not supported on x86 or ia64 architectures.)

======================================

{SLICK}

So, the lesson here is:  whenever possible, use software and hardware designed for the (64-bit version of the) operating system that you are using.

=====================================


The Windows 7 Software Logo Program

The ‘Compatible with Windows 7 logo’ helps customers make better purchase decisions by identifying products that have passed Microsoft designed tests for compatibility and reliability on Windows 7. The logo provides the ultimate seal of approval...

======================================


The Windows 7 Application Compatibility List for IT Professionals is a Microsoft Office Excel-based spreadsheet listing software applications which have met Windows 7 Logo Program testing requirements for compatibility with 32-bit and 64-bit Windows 7, and have thereby earned the right to display the Windows 7 Logo Program logo with the application. These products are identified with the compatibility status “Compatible – Windows 7 Logo.”

...this list includes applications with the following compatibility statuses: “Compatible,” “Free Update Required,” “Paid Update Required,” “Future Compatibility,” and “Not Compatible.” These statuses are based upon the software publishers’ statements of compatibility. These products have not met the Windows 7 Logo Program testing requirements. For an explanation of the various compatibility statuses, please see the Release Notes for the Windows 7 Application Compatibility List on the first tab of the Excel spreadsheet.

For the latest catalog of compatible applications and hardware devices, please visit the Windows 7 Compatibility Center and select a region and language from the drop-down menu at the top of the page. You can also leave feedback on compatibility and suggest new products to get added in future reports.




Thursday, August 12, 2010

FCC SEEKS PUBLIC COMMENT ON NATIONAL BROADBAND PLAN

Comments Due:  September 23, 2010

"...the Federal Communications Commission’s (FCC or Commission) Public Safety and Homeland Security Bureau (PSHSB) seeks public comment on the creation of a Cybersecurity Roadmap to identify vulnerabilities to communications networks or end-users and to develop countermeasures and solutions in preparation for, and response to, cyber threats and attacks in coordination with federal partners.  The FCC’s Cybersecurity Roadmap was recommended as an initial step forward in the area of cybersecurity as part of the Commission’s National Broadband Plan (NBP)...

"...commenters could offer responses to: What are the most vital cybersecurity vulnerabilities for communications networks or users?  How can these vulnerabilities be addressed?  What role should the Commission play in addressing them?  What steps should the Commission take, if any, to remediate them?  If the FCC does not play a role in addressing these vulnerabilities and problems, what agency or entity would fulfill that role?  How should the Commission coordinate its efforts with other agencies of government?"

http://hraunfoss.fcc.gov/edocs_public/attachmatch/DA-10-1354A1.doc

http://hraunfoss.fcc.gov/edocs_public/attachmatch/DA-10-1354A1.pdf

Friday, May 21, 2010

PeeWee software for ages 3 to 6 years old


PeeWee KIT: Pre-Kindergarten is software for ages 3-6 that is supplied on a USB flash drive. The letter that accompanied the USB drive that was sent to me states there are three versions available, but did not indicate the configurations of the other two...

The software I received is:
Bailey's Book House
("...explore the sounds and meanings of letters, words, rhymes,
and stories...")
Sammy's Science House
("...activities introduce essential ideas like patterns and sorting,
weather and seasons, animal habitats, and classifications in the natural world...")
Thinkin' Things Toony The Loon's Lagoon
("...activities that focus on memory development, logic,
visual and spatial thinking, musical memory, and problem solving...")
Trudy's Time & Place House
("...From telling time to understanding maps to building a sense of
direction, this whimsical time-and place adventure presents challenging concepts...")
Millie’s Math House
("...explore numbers, shapes, sizes, quantities, patterns,
sequencing, addition, and subtraction...")


After obtaining the PeeWee Kit, an address of an internet website will be available from which the security software can be downloaded.

-------------------------------------------------------------------

With PeeWee Patrol you can capture: keys pressed, programs used, websites visited...as well as have screenshots taken at intervals.

When in Stealth Mode, it will not display it's Graphical User Interface (GUI)...and will remove itself from the Windows Application list. If anyone knew how to try to make the program visible, it will require a password to access the controls (and information).

From the "help" file that was created after PeeWee Patrol was installed...

"...monitor your computer while you are away, retrieve lost information, or monitor your children's activity..."

"This program contains a built in email engine that can email you a copy of the current capture log at scheduled intervals...

"The program includes a scheduler that lets you schedule simple tasks to be completed at a given time or interval. The following tasks can be automated: Start Capture...Stop Capture...Email Capture Log (The current Log will be emailed to you as an text file)...

"Encryption: When selected, the contents of your log files will be encrypted so that they cannot be opened by text editors like Notepad, WordPad, or Micsoft Word.

"Run at Startup: When selected, the program will run automatically each time you start your computer..."

------------------------------------------------------------------

According to the "help" file for PeeWee Privacy:

This software will hide your sensitive files so that they can't be seen or accessed. Files stay hidden even if you turn on 'View Hidden Files'. Even links in your recent documents menu won't be able to find your hidden files!

For extra security, use a password to prevent anyone from accessing your files. You can run this software in stealth mode so that no one knows it's there, and hide or show your sensitive files using hotkeys.

Features:
Add as many folders to the program as you want for quick hiding
Hide or Show individual folders or all folders at once
Prevents all file access, even from the command prompt, and even from hackers
Folders are removed from Windows Explorer entirely
Files in folders cannot be accessed, even from shortcuts or recent document lists
Run at Windows startup
Runs in stealth mode and doesn't show up in the Applications tab when you press
Control-Alt-Delete
Hotkey for bringing the program out of Stealth Mode
Hotkey for hiding all folders
Hotkey for showing all folders
Password protection when program is opened
Password protection when program is brought out of stealth mode
Password protection when hotkeys are used to hide or show all folders

----------------------------------------------------------------------

The USB drive that was sent to me did not work with a one-foot (USB) extension cord: the USB drive must be connected directly to the computer.

Based on my past experiences with USB flash drives that contained U3 and Ceedo software, I assumed that when I connected the drive to my computer...I would be able to immediately use the software directly from the drive; the software needed to be installed, and I did not want to install the software to the computer I was using.

I chose a different computer to install it on for testing. I have nothing unusual to report about it...the installation of the software was as normal as any.

-----------------------------------------------------------------

I decided to try to install the software from the USB stick, into the USB stick.

The "2 GB" USB memory stick had a total of 1.86 GB of usable space, and 243 MB was being used (by the installation software that was provided is on the drive).

(Using a different computer than the one I installed the software onto) I installed the software onto the USB stick (to "{driveletter}:\Program Files\Riverdeep\"). Now 583 MB of space is being used. As I assumed would happen, icons were installed on the computer by default (because the installation procedures do not give options to not install them).

I disconnected the USB drive from the computer, restarted the computer, and (in Windows Vista) "uninstalled" the programs from Programs and Features.

Using the best computer I have (an Alienware Area 51 M9750), I connected the USB flash drive to the port on the right side of the computer...and the drive was not recognized. I don't have this issue with other USB drives...

I connnected the USB drive to a port on the left side of the computer, and it was mounted. The programs will now run from the USB flash drive (just launch their executable files from within the folders of the installed programs).

====================================



=====================================

I am VERY impressed with PeeWee Patrol and PeeWee Privacy...in my opinion, those two programs are worth the cost of the entire package.

Thursday, February 5, 2009

CNN installed P2P software on PC's during inauguration!

...people who watched live streaming video of the inauguration of U.S. President Barack Obama on Jan. 20 may not realize that their PC was used to send the video to other PCs...Clicking "yes" to a CNN.com dialog box installed a peer-to-peer (P2P) application that uses your Internet bandwidth rather than CNN's to send live video to other viewers...

Octoshape's dialog box warns that playing a live video "requires" installing new software...if you click "no" to Octoshape, you can play the feed using the streaming video capability built into Windows Media Player or Adobe's Flash Player...

The Octoshape EULA doesn't become available until after the user is required to select "yes" or "no" to install the app...

Any Web site you visit that is "Octoshape aware" can invoke the application. If a security vulnerability is discovered in the Octoshape software, hackers could exploit the weakness.

read more | digg story

Thursday, August 14, 2008

software to erase hard drives

Darik's Boot and Nuke ("DBAN") deletes the contents of any hard disk that it can detect.

(DBAN cannot be started from within Microsoft Windows.) It can be installed to a USB flash device, and...if the computer supports it...computers can boot to it. You will need at least a 2 GB drive...

A DBAN CD-R disc can be created from an ISO file.

read more | digg story

Thursday, July 10, 2008

Tuesday, January 15, 2008

router Universal Plug and Play can allow access

(I found this article to be interesting...)

"...Universal Plug and Play can be combined with simple XSS attacks in order to create a powerful mechanism for remotely reconfiguring vulnerable routers without any means of authentication or authorization with the targeted device...UPnP can be exploited across the Web without the need of XSS...

"...the attacker can change the primary DNS server of the target router...

"...99% of home routers are vulnerable to this attack...

"The only way to protect yourself is to turn off UPnP...your skype or msn wont work as flawlessly as before..."

Thursday, September 6, 2007

your phone rats you out

In a cell phone's internal memory, communication exchanged between the phone and its server remain...