Alexa's Blog

Reliable $1 Web Hosting by 3iX

Reliable $1 Web Hosting by 3iX

SoMuch.com: Internet Links Directory



Again, Google, Yahoo, Facebook Extensions Put Millions of Firefox Users At Risk

May 30th, 2007

As stated by Ryan Singel on his post on Wired Blogs, the Firefox extensions provided by those companies (and probable others too) have a serious flaw in the update routines.

When starting the browser, those extensions check for new version on the provider servers.The point is that the check should be done over a Secure Connection Layer (SSL) which encrypt all the data sent over the network and stop any sniffer to catch the request.

Those extensions made the check using a standard unencrypted connection, which allow a possible attacker to intercept the request and send back a malicious update, which once installed in your browser can monitor and steal any information you enter into your browser.This include any url you type and any value entered by you in the forms of html pages INCLUDING ones opened over an SSL connection.Remember that the encryption is used only in the communication protocol and that happen after you have completed a payment form for example and the browser send the collected data to the server.

Well, this was a matter of time. What upset me most is the fact that almost all the time the bigger treats are coming from big software providers which don´t bother to check the most basics tutorials about how to handle the updates in a secure way.

Millions of users are using those extensions from a very long time and they where exposed all the time to this treat.Worse is that there is the posibility to be already hijacked even if the hole was made public right now.Those are the exploits used by spammers and other bad guys to stole your private data.

Be very careful when choosing your Firefox extensions and look first what other people are saying about them.Having all kind of toolbars and buttons in Firefox might help you for your daily tasks, but can be a serious problem when you do private tasks or working with very sensitive data.

If you need more, read the Ryan´s story on Wired Blogs.

Take Care and Watch Yourself!

Google buys anti-malware browser virtualization startup

May 29th, 2007

Well, is looking that Google has been starting to make his way to the desktop antivirus and protection market using anti-malware software as their first step.This might be an important step but I really hope to be delivered as a standalone application not bundled with their toolbar which personally I don´t like at all.

However, another good thing might be a decrease of the prices on products in this category which if you ask me should be provided for free. If the price will not be affected, let´s hope that at least we can see more better products on the market.

See more about this acquisition on Ryan Naraine post here.

Wan a job ? Then snag one!

May 29th, 2007

Hi fellows,

Because many people are asking about home data entry jobs on my previous Data entry jobs war post, I come across the snagajob.com website. I think is a good place to start and searching for your job. They have a good list of opportunities and the registration is free so you get a good list of possible jobs without paying the subscription of the many scam websites that at the end will offer you the same thing.I can´t tell you more because I am already employed, but give it a try because all you have to loose are a few minutes from your time.
Go and snag your job and come back to let me know the results.Your experience is valuable to others and it is your contribution to make the job searching much safer for other people.

Good Hunting!

Next Page »
Your Ad Here