Live data from Hacker News

Not one Microsoft product on Kaspersky’s top 10 vulnerabilities list

thenextweb.com

71–80 of 137 posts

Re: Not one Microsoft product on Kaspersky’s top 10 vulnerabilities list

#72

If you're running Chrome please for the love of all that is holy enable Click-To-Play for all plugins. With it disabled it is like running without a pop-up blocker. You can do so in Settings -> Advanced Settings -> Content Settings -> Plug-Ins -> Click To Play. When you visit a site which has a plug-in you'll get a UI control similar to the pop-up blocker which allows you to add it to the exceptions list and or to al…

I'd go one step farther and just disable plugins. I have run without plugins for years and it really is a non-issue 95% of the time. If I absolutely need a plugin I will enable it for the time I need it and then disable it again.

Re: Not one Microsoft product on Kaspersky’s top 10 vulnerabilities list

#73
post #25

Earlier quoted context omitted.

It is inherently more secured in the same context. The JVM applet sandbox has to stand up to random code off the internet, whereas native code is almost only installed explicitly. Remember ActiveX and how it was worse than Java applets?

It seems to me that the only reason we put up with JVM applets (whereas anyone suggesting we put up with people ActiveX would rightfully be laughed down these days) is because of that steady monotonous stream of crap about how much better Java is for security. It has dropped our collective paranoia far too low.

Unfortunately places like Korea still require ActiveX support because it's used by all online shopping, government, etc pages (and is required by law in many cases)... http://www.koreaittimes.com/story/21504/internet-powerhouse-...

Re: Not one Microsoft product on Kaspersky’s top 10 vulnerabilities list

#74
post #41

Earlier quoted context omitted.

Now I wish Adobe would do the same thing.

They very much are, and have been, for awhile.

That doesn't apply until they start actually releasing out of band updates for very, very nasty flash/reader vulnerabilities.

Re: Not one Microsoft product on Kaspersky’s top 10 vulnerabilities list

#75

If you're running Chrome please for the love of all that is holy enable Click-To-Play for all plugins. With it disabled it is like running without a pop-up blocker. You can do so in Settings -> Advanced Settings -> Content Settings -> Plug-Ins -> Click To Play. When you visit a site which has a plug-in you'll get a UI control similar to the pop-up blocker which allows you to add it to the exceptions list and or to al…

Or better yet, switch YouTube to the HTML5 player: http://www.youtube.com/html5 One less site that needs Flash.

Every time I join the YouTube HTML5 trial it gets silently turned off and videos start playing in Flash again a week or two later. Does that happen to anyone else?

Re: Not one Microsoft product on Kaspersky’s top 10 vulnerabilities list

#76
post #41

Earlier quoted context omitted.

Now I wish Adobe would do the same thing.

They very much are, and have been, for awhile.

Remember this? http://www.gizmodo.com.au/2012/05/adobes-photoshop-security-...

They left Photo CS 5.5 users twisting in the wind, recommending customers pay to upgrade their one-year-old software to CS 6.

I don't know if it was the external pressure or a slow in-house process, but it took them a month to release a fix for CS 5.5 users: http://www.adobe.com/support/security/bulletins/apsb12-11.ht...

Re: Not one Microsoft product on Kaspersky’s top 10 vulnerabilities list

#77

Earlier quoted context omitted.

Or better yet, switch YouTube to the HTML5 player: http://www.youtube.com/html5 One less site that needs Flash.

Every time I join the YouTube HTML5 trial it gets silently turned off and videos start playing in Flash again a week or two later. Does that happen to anyone else?

Yes! I have turned that on many times and I always end up watching flash videos again. I wonder if it had to do with my session cookie expiring. Does anyone know how they toggle this experiment on/off for different users?

Re: Not one Microsoft product on Kaspersky’s top 10 vulnerabilities list

#78

Interesting to note that both Apple vulnerabilities listed exist only for their Windows software. (QuickTime: http://lists.apple.com/archives/security-announce/2012/May/m... iTunes: http://support.apple.com/kb/HT5485 ) I wonder if these are lower priority for Apple or if they perhaps just aren't as good when developing for Windows.

Quicktime on Windows is stuck at version 7, which is riddled with numerous problems. It's this old Quicktime codebase that is the source of the Quicktime and iTunes vulnerabilities on Windows.

The current version on Mac and iOS is Quicktime X. This version was a complete rewrite (that started on iOS and eventually migrated to the Mac). The complete rewrite allowed for a vastly more secure design (among other improvements).

Re: Not one Microsoft product on Kaspersky’s top 10 vulnerabilities list

#80
post #53
post #18

Is it getting safer to say that antivirus software may soon be a thing of the past?

My question is, would you run Windows 7/8 without any anti-virus software at all? Do you feel that comfortable? After years of Linux/OS X I can safely say that I won't use an OS that requires anti-virus ever again.

I used to run Security Essentials. When I upgraded to 8, it automatically uninstalled it. It's baked into the OS now, along with a constantly updated blacklist of known malware programs if you try to manually install something bad. You can get around it easily, but they don't make it intuitive to do so for users who are not comfortable clicking around and exploring.

Above and beyond being comfortable not using an AV on Windows 8, I would go as far as to say that if you are using an AV on Windows 8, you're being taken for a ride by your vendor of choice. And I say this as an information security professional. I've tried to get a virus on Windows 8 without doing anything more than what it takes to get a virus on Windows 7. I did not succeed.

Post reply on HN