Subscribe For Free Updates!

We'll not spam mate! We promise.

mardi 24 février 2015

Systems and software flaws: who is most vulnerable?

Systems and software flaws: who is most vulnerable?

The publisher of software and security solutions for businesses GFI has developed a list of vulnerabilities for operating systems and software. In a blog post he points increased flaws and the fact that all publishers are concerned even if the list is not exhaustive. The analysis is based on the flaws identified by the NVD (National Vulnerability Database) of the US government.

The figures show that 2014-seems been a difficult year for software vendors who have to tackle to fill many gaps. From 4258 in 2010 and with a shy evolution in the following years, we move to 7038 vulnerabilities identified in 2014.
Systems and software flaws: who is most vulnerable?

However, it appears that increasing the number of vulnerabilities considered important more measured. The number is still below the 2010 figures. On the other hand we can see that flaws are detected primarily in software (83%) and then in operating systems (13%) while the problem directly related to hardware are lower (4%).
Systems and software flaws: who is most vulnerable?

Concerning Apps, browsers are the most targeted according to the list, Mozilla Firefox is doing better even if the number of faults is important. GFI says that browsers are top of the list for years because it's the most popular means of access to spread malware.
Systems and software flaws: who is most vulnerable?

The list is as surprising about operating systems, including the division of OS versions. Mac OS X was down list and Microsoft Server 2008 and Windows 7 took the first places. The trend has been reversed and Mac OS X and Apple iOS are now top of the list while Microsoft systems seem to have known less difficulty.
Systems and software flaws: who is most vulnerable?

The non-exhaustive figures do not say it is safer to use a particular system or application over another. However, they give two very important information for user: no one is immune to whatever the system and updates that correct these faults are a good way to guard against security problems.

vendredi 7 novembre 2014

We can hack passwords by... filming users


Imagine that you are in a cafe with your tablet. You enter the secret code to reach one of your favorite online services. You are using a software anti-spyware protection. There is no risk for anyone to see what you type, is not it? Error! Five security researchers have recently shown that it is possible to guess the letters which a user types just by filming a few meters, and this with basic equipment such as a webcam or a smartphone.

Indeed, scientists have developed a method of image analysis that allows them to identify with sufficient precision the place where the fingers landing on the touch screen then, by comparison with a pre-established scrim, to infer the characters. And that, whatever the angle of shooting.


Researchers carried a series of tests in "natural environment". At a distance of two meters, the detection is made with 100% success. This rate down to 80% between three and four meters, then becomes 50% beyond.


How to protect themselves against this type of attack? Easy, say the researchers, it is necessary to systematize the use of virtual keyboards where the location of the keys is random, as it already exists on some banking applications. Well, of course, to write a text, it is not convenient, but to enter a password that is acceptable.


Below, The analysis of five researchers: