Independent

ComputerWorldIndependent

The case against knee-jerk installation of Windows patches

Credit to Author: Woody Leonhard| Date: Mon, 17 Jun 2019 03:10:00 -0700

Heresy. Yes, I know. Any way you slice it, from my point of view anyway, Windows Automatic Update is for chumps.

Just like the “users must be forced to change their passwords frequently” argument that’s no longer au courant, the “users must get patched immediately” argument is based on old, faulty, and totally unsubstantiated claims that make security people feel better — and little else.

With a few notable exceptions, in the real world, the risks of getting clobbered by a bad patch far, far outweigh the risks of getting hit with a just-patched exploit. Many security “experts” huff and puff at that assertion. The poohbahs preach Automatic Update for the unwashed masses, while frequently exempting themselves from the edict.

To read this article in full, please click here

Read More
ComputerWorldIndependent

WWDC: Apple’s iOS 13 NFC improvements are good for business

Credit to Author: Jonny Evans| Date: Thu, 13 Jun 2019 07:08:00 -0700

Apple will make NFC much more useful in iPhones running iOS 13, and these enhancements will impact the retail, medical, government and security industries.

What is Apple changing?

Apple already uses NFC to support Apple Pay and the Apple Pay Express Transit system which is rolling out at this time.

While it has incrementally extended the tasks NFC supports over the years, the company has limited its NFC support to the NDEF standard until now, but extends this with support for new standards in its Core NFC Framework in iOS 13.

To read this article in full, please click here

Read More
ComputerWorldIndependent

Microsoft is better at documenting patch problems, but issues abound

Credit to Author: Woody Leonhard| Date: Thu, 13 Jun 2019 03:55:00 -0700

I don’t know about you, but I’ve given up on Microsoft’s ability to deliver reliable patches. Month after month, we’ve seen big bugs and little bugs pushed and pulled and squished and re-squished. You can see a chronology from the past two years in my patching whack-a-mole columns starting here.

For the past few months, though, we’ve seen some improvement. Microsoft has started identifying and publicly acknowledging big bugs, shortly after they’re pushed. Consider:

To read this article in full, please click here

Read More
IndependentKrebs

Microsoft Patch Tuesday, June 2019 Edition

Credit to Author: BrianKrebs| Date: Wed, 12 Jun 2019 13:26:21 +0000

Microsoft on Tuesday released updates to fix 88 security vulnerabilities in its Windows operating systems and related software. The most dangerous of these include four flaws for which there is already exploit code available. There’s also a scary bug affecting all versions of Microsoft Office that can be triggered by a malicious link or attachment. And of course Adobe has its customary monthly security update for Flash Player.

Read More
ComputerWorldIndependent

Save yourself a headache: Make sure Windows automatic update is off

Credit to Author: Woody Leonhard| Date: Mon, 10 Jun 2019 04:22:00 -0700

Read More
ComputerWorldIndependent

WWDC: Get to know Apple’s 11+ new privacy tools

Credit to Author: Jonny Evans| Date: Fri, 07 Jun 2019 05:22:00 -0700

Apple introduced an array of additional privacy protections at WWDC 2019. Many of these both offer protection and help us better understand how our privacy is undermined.

Why does this matter?

Apple CEO Tim Cook is passionate about the need to protect user privacy and this is by no means a one man mission.

Speaking with Vector, Apple’s VP Software Technology, Bud Tribble stressed the need to educate people into the needs and benefits of privacy, a topic he believes is much more” widely discussed now than before.

To read this article in full, please click here

Read More
ComputerWorldIndependent

Mozilla makes anti-tracking the Firefox default

Credit to Author: Gregg Keizer| Date: Thu, 06 Jun 2019 12:43:00 -0700

Mozilla this week began to switch on an aggressive anti-tracking technology in Firefox that it has touted since 2015.

With a June 4 update to Firefox 67, Mozilla turned on Enhanced Tracking Protection (ETP) by default for new users. Existing customers simply updating their browsers may enable ETP themselves. The default-of-on will be extended to those users “in the coming months,” Mozilla said, apparently activating it in stages as a last-step quality control.

Mozilla also used the update to Firefox 67.0.1 to trumpet other privacy- and security-centric enhancements, including an add-on that brings its Lockwise password manager to the desktop browser and an improved Facebook Container, an extension designed to keep the social network behemoth from tracking users elsewhere on the web.

To read this article in full, please click here

Read More
ComputerWorldIndependent

NSA, Microsoft implore enterprises to patch Windows' 'BlueKeep' flaw before it's too late

Credit to Author: Gregg Keizer| Date: Wed, 05 Jun 2019 13:16:00 -0700

The U.S. National Security Agency (NSA) on Tuesday called on IT administrators to apply security updates issued by Microsoft three weeks ago, adding to a chorus of voices urging haste.

“The National Security Agency is urging Microsoft Windows administrators and users to ensure they are using a patched and updated system in the face of growing threats,” the NSA said in a June 4 advisory.

The agency’s advice followed by several days that of Microsoft itself. On Thursday, May 30, a company official reminded users of the updates – which the company released May 14 – and implied that time is short. “We strongly advise that all affected systems should be updated as soon as possible,” Simon Pope, the director of incident response at the Microsoft Security Response Center (MSRC), wrote in a blog post.

To read this article in full, please click here

Read More