Showing posts with label security. Show all posts
Showing posts with label security. Show all posts

Monday, 18 November 2013

Trend Micro Titanium Maximum Security 2014

Pros Very good score for malware-blocking. Accurate spam and phishing detection. Firewall Booster aids Windows Firewall. Checks social media privacy settings, links. Online Guardian offers wide-ranging parental control. Password management, form filling. Encrypted file storage can be sealed remotely. Impressive full-featured online backup and file-sharing.

Cons Hard to install on malware-infested systems. Too-rigid behavior-based detection blocked valid programs. Limited parental control. More performance impact than many. Parental control system seriously flawed. Password management is awkward; form-filler not accurate. Bottom Line On top of the features in Trend Micro's entry-level suite, Trend Micro Titanium Maximum Security 2014 adds advanced parental control, password management, and online backup and file-sharing. However, only the backup system really shines.

By Neil J. Rubenking

There are two main reasons you'd choose to purchase a security suite rather than assemble a collection of individual security tools. First, it's generally a lot less expensive. Second, having all of your security components integrated into one product tends to reduce the overall impact on performance. Trend Micro Titanium Maximum Security 2014 ($89.95 per year direct, for three licenses) is definitely cost-effective, but it's not nearly as well-integrated as some of its competition.

Compare Selected

This product is closer to a security bundle than an integrated suite. With a few exceptions, the main suite portion is identical to Trend Micro Titanium Internet Security 2014 ($79.95). For $10 more, the mega-suite adds Trend Micro DirectPass for password management ($14.95), Trend Micro SafeSync for online backup and file sharing ($39.95), and parental control from Trend Micro Online Guardian for Families ($49.95). Those components would cost over $100 if purchased separately.

On the other hand, DirectPass, SafeSync, and Online Guardian each require a full, separate installation process. Getting the whole suite installed took significantly longer than most. In addition, the four installations ate up an impressive amount of disk space—over a gigabyte!

Good at Blocking Malware Attack
The antivirus protection in this suite is precisely the same as what's offered by Trend Micro Titanium Antivirus+ 2014, so you'd do well to read that review first. For this review, I'll simply summarize my findings.

Trend Micro earned an impressive 9.2 out of 10 points in my malware blocking test. Of all products tested using my current collection of malware samples, only AVG Internet Security 2014 and Ad-Aware Pro Security 10.5 scored higher, both with 9.4 points. For more on how I perform and score this test, see How We Test Malware Blocking.

Related Story

Trend Micro Titanium Maximum Security 2014 malware blocking chart

SecurityWatch

Trend Micro was also especially effective at blocking access to dangerous websites; it blocked 95 percent of those I tried. It didn't do as well when challenged to clean up a dozen malware-infested systems. Just getting it installed took a lot of back and forth with tech support. It scored 5.8 points overall, just so-so. Best scores in this test went to Bitdefender Total Security (2014), AVG, and Norton 360 (2014)with 6.6, 6.4, and 6.3 points respectively. The article How We Test Malware Removal explains how my malware removal test works.

Related Story

Trend Micro Titanium Maximum Security 2014 malware removal chart

Trend Micro skips traditional antivirus lab tests, but participates with the more innovative tests performed by AV-Test and AV-Comparatives. It gets good marks, especially in the whole-product real-world test by AV-Comparatives. The chart below summarizes recent test results; for more information about the tests, see How We Interpret Antivirus Lab Tests.

Related Story

Trend Micro Titanium Maximum Security 2014 lab tests chart


View the original article here

Friday, 27 September 2013

iOS 7 security update patches lockscreen flaw

September 27, 2013 09:16 AM ETNetwork World - Apple yesterday released an iOS 7 software update that fixes a security flaw that let users bypass the iPhone lockscreen to access a range of onboard information and online accounts.

IOS 7.0.2 seems to be mainly a security patch, but the update screen also says there is a new Greek alphabet keyboard option for entering a passcode.

A day after iOS 7 was released earlier this month, Forbes' Andy Greenberg reported that a U.S. soldier had somehow uncovered a rather complex series of actions that let him bypass the lockscreen, at least on existing iPhones that updated to the new firmware.

[MORE iOS7:iOS 7 tips and tricks you need to learn]

[NEWS:Quick look: The interesting rise and quick fall of Blackberry]

The actions involved swiping upwards on the lockscreen to bring up the iOS Control Center, then opening the alarm clock app, then holding down the power button to show the "power off" and "cancel" options, then tapping "cancel," and finally quickly double-clicking the home button to bring up the multitasking screen for various apps.

According to Greenberg's account, the user could then access the phone's camera and stored photographs and, more importantly, the ability to share the photos via various associated accounts, and therefore access them: including email, Twitter, Facebook and Flickr.

John Cox covers wireless networking and mobile computing for Network World.Twitter: http://twitter.com/johnwcoxnwwEmail: john_cox@nww.com

Read more about software in Network World's Software section.

Reprinted with permission from NetworkWorld.com. Story copyright 2012 Network World, Inc. All rights reserved.

View the original article here

Thursday, 26 September 2013

McAfee Internet Security 2014

Pros CleanBoot rescue CD solved many installation problems. Very good score in our hands-on malware blocking test. SiteAdvisor toolbar identifies and blocks dangerous websites. Smart firewall won't hassle you. Accurate spam filter can even process webmail. Mozy-powered backup. Shredder, remote management, vulnerability scanner, system tuneup.

Cons So-so score in our hands-on malware cleanup test. Antispam processing noticeably slowed email download. Parental control system is limited and awkward. Bottom Line With its smart firewall, effective malware blocking, and accurate spam filter, McAfee Internet Security 2014 can be a good security suite choice. Just don't rely on it for parental control.

By Neil J. Rubenking

The 2014 security suites just keep rolling in, many accompanied by a standalone antivirus and a feature-packed mega-suite. McAfee Internet Security 2014 ($79.99 direct for three licenses) comes equipped with all the expected suite features as well as a few interesting bonuses.

Compare Selected

Like McAfee's entry-level antivirus, the suite features a main window dominated by big, touch-friendly buttons. In fact, the only real difference in layout is that the suite adds a button dedicated to the parental control system. Also like the antivirus, the suite offers a separate Navigation Center, a simple list with links to all security components. Other Navigation Center links let you view reports and security history, manage your subscriptions, and view security information on McAfee's website.

McAfee's entry-level antivirus includes quite a few security features more commonly found in suites. For full coverage of those features, please read my review of McAfee AntiVirus Plus 2014. I'll summarize my findings here.

Better Malware Blocking than Cleanup
On over half of my dozen malware-infested test systems, McAfee ran into installation problems. The impressive CleanBoot rescue CD fixed those problems. Post-scan difficulties on two systems required lengthy intervention by tech support, though.

McAfee and Trend Micro Titanium Internet Security 2014 both detected 75 percent of my pre-installed malware samples, which is on the low side. McAfee scored 5.9 points overall, beating Trend Micro's 5.8. Bitdefender Internet Security (2014) earned the best score among products tested with this malware collection, 6.6 points. For a detailed explanation of my malware removal test, see How We Test Malware Removal.

Related Story

McAfee Internet Security 2014 malware removal chart

McAfee was a lot more successful at blocking malware attacks on a system that started out clean. Like Trend Micro, it earned 9.2 points in my malware blocking test. Of all products tested with my current sample collection, only two scored higher. AVG Internet Security 2014 and Ad-Aware Pro Security 10.5 tied at the top with 9.4 points. To learn more about how I test malware blocking, see How We Test Malware Blocking.

Related Story

McAfee Internet Security 2014 malware blocking chart

SecurityWatch

McAfee participates in testing with all the labs that I follow and gets generally good marks. It averaged 14.25 of 18 possible points in the latest two tests from AV-Test and rated ADVANCED in recent tests by AV-Comparatives. If you'd like to know more about the labs and their tests, see How We Interpret Antivirus Lab Tests.

Related Story

McAfee Internet Security 2014 lab tests chart


View the original article here

Trend Micro Titanium Internet Security 2014

Pros Very good score for malware-blocking. Accurate spam and phishing detection. Firewall Booster aids Windows Firewall. Checks social media privacy settings, links. Can block transmission of private data. Secure deletion.

Cons Hard to install on malware-infested systems. Too-rigid behavior-based detection blocked valid programs. Somewhat limited parental control. More performance impact than many. Bottom Line Trend Micro Titanium Internet Security 2014 offers more features than many suites, but not all components are top-notch. It displayed more of an impact than many in my hands-on performance test.

By Neil J. Rubenking

There's a trend among some security vendors to enhance their entry-level antivirus product with features more commonly found in a security suite. Of course, doing so raises the bar for the company's actual security suite. Trend Micro Titanium Internet Security 2014 ($59.95 direct; $79.95 for three licenses) definitely rises to the challenge. It takes the full range of features found in Trend Micro's standalone antivirus and adds a significant collection of additional security components.

Compare Selected

The main window for this suite summarizes your security status with a great big icon, in most cases a green checkmark indicating full protection. If there's anything wrong with your security configuration, you just click a button to fix it. This window also summarizes recent security activity; additional tabs offer access to more security features. Three tabs labeled Privacy, Data, and Family house most of the suite-specific features.

If the product's appearance isn't to your liking, you can replace the main window's background. The product comes with eight widely varied background images, flowers, clouds, stars, and more. Or choose an image of your own to truly personalize the installation.

This suite shares the same antivirus protection found in Trend Micro Titanium Antivirus+ 2014, along with quite a few other security features. You'll definitely want to read that review for full details. I'll summarize my evaluation of the shared features here.

Better Defense than Cleanup
Getting Trend Micro installed on twelve test systems for malware removal testing took hours of back-and-forth with tech support, including quite a bit of remote control diagnosis and repair. Trend Micro earned two stars for installation experience and 5.8 points for malware removal. The best scores among products tested with my current malware collection went to Bitdefender Internet Security (2014), AVG Internet Security 2014, and Norton Internet Security (2014). For a full explanation of how I test malware removal, see How We Test Malware Removal.

Related Story

Trend Micro Titanium Internet Security 2014 malware removal chart

With 94 percent detection and 9.2 points, Trend Micro fared much better in my malware blocking test. Only AVG and Ad-Aware Pro Security 10.5 scored better against the same malware collection. Trend Micro also did a great job blocking access to malware-hosting websites. To learn just what goes into this test, please see How We Test Malware Blocking.

Related Story

Trend Micro Titanium Internet Security 2014 malware blocking chart

SecurityWatch

Like Symantec, Trend Micro downplays the value of old-fashioned static malware detection tests and praises dynamic, real-world tests. Trend Micro's technology took the highest rating in the whole-product dynamic test by AV-Comparatives, and it also did well in AV-Test's three-way certification test. To learn more about the testing labs summarized in the chart below, please read How We Interpret Antivirus Lab Tests.

Related Story

Trend Micro Titanium Internet Security 2014 lab tests chart


View the original article here

Saturday, 21 September 2013

AVG Internet Security 2014

Pros Very good scores in PCMag's hands-on malware removal and blocking tests. Encrypted storage plus secure deletion protect sensitive data. Accurate spam filtering. Smart firewall handles program control itself. Tiny performance impact.

Cons Tough time installing on malware-infested test systems. Dismal score in antiphishing test. Average scores from independent antivirus labs. Tune-up feature requires separate purchase. Bottom Line Getting AVG Internet Security 2014 installed on malware-infested systems was a challenge, but it did a good job in the end. A smart firewall, accurate spam filtering, and useful encryption system make up for less-than-stellar protection against phishing frauds.

By Neil J. Rubenking

Different security suites include different collections of security features, but they all must have antivirus and firewall protection. Most include spam filtering and parental control, though not all users need these components. AVG Internet Security 2014 ($54.99 direct; $69.99 for three licenses) includes all of the usual components except parental control, and adds tools to protect your sensitive data.

Compare Selected

The product's colorful main window looks almost identical to that of AVG's free standalone antivirus product. All of the same buttons are present: Computer, Web Browsing, Identity, Emails, and Firewall. The difference is, they're all fully functional in the suite. As in the free antivirus, a second row of buttons links to other products from AVG, most of which require a separate purchase.

AVG includes built-in links to a variety of support options. You can get simple questions answered by Julia the chat-bot, or go to the AVG Community forums for help from other users. If that's not enough you can contact support via phone, email, or live chat. And if you're willing to pay a little extra, you can help for any tech problem from AVG's Tech Buddy experts.

Antivirus Protection
The antivirus component in AVG's suite is exactly the same as what's found in AVG AntiVirus FREE 2014, so I'll just summarize my findings here. You can read the antivirus review for full details.

Getting AVG installed on my twelve malware-infested test systems was quite a chore. All but two ran into some degree of difficulty, and a few needed days of back-and-forth with tech support before I managed to install the product and run a full scan.

Once I got past installation hurdles, the product proved to be an effective malware remover. Its 6.4 point score beats Norton Internet Security (2014) by a tenth of a point. Only Bitdefender Internet Security (2014), with 6.4 points, scored higher among products tested with the same samples. For a full explanation of my hands-on malware removal test, see How We Test Malware Removal.

Related Story

AVG Internet Security 2014 malware removal chart

AVG was particularly effective at keeping malware from getting a foothold on a clean system. With 9.4 points for malware blocking, it tied with Ad-Aware Pro Security 10.5 for top score among recent products. Tested with my previous malware collection, Webroot SecureAnywhere Internet Security Plus 2013 earned a near-perfect 9.9 of 10 possible points. The article How We Test Malware Blocking explains in detail how I conduct and score this test.

Related Story

AVG Internet Security 2014 malware blocking chart

SecurityWatch

AVG doesn't participate in testing by ICSA Labs or West Coast Labs. In the last ten tests by Virus Bulletin, it missed receiving VB100 certification just twice. In both cases it didn't miss any malware from the test set, but it identified one valid program as malicious. In tests by AV-Test and AV-Comparatives, AVG earns scores that are good but not outstanding. To learn more about the independent labs whose reports I follow, see How We Interpret Antivirus Lab Tests.

Related Story

AVG Internet Security 2014 lab tests chart

Both the suite and the antivirus install AVG's toolbar for browser protection. The toolbar offers safe search, flags dangerous websites, and can optionally block ad networks from tracking your online activity.


View the original article here

Friday, 20 September 2013

Experts praise Pentagon's march to security standards

September 20, 2013 06:00 AM ETCSO - The Pentagon's decision to move its thousands of networks under a single security architecture is the right strategy to bolster defenses against hackers and malicious insiders, experts say.

The massive consolidation of the Defense Department's 15,000 networks into a "joint information environment" is expected to cut costs, as well as improve security against Edward Snowden-like leaks, National Defense magazine reported.

The former contractor took thousands of documents from the National Security Agency and distributed them to the media, which is driving a national debate on NSA surveillance of Americans.

Thwarting hackers is also behind the Pentagon's move to have all four branches of the military, defense agencies and overseas commands use the same network and security systems. The expected benefits include killing redundancies and making it easier to detect hacker-induced anomalies.

The transition away from the Pentagon's current mishmash of technology unique to the various government entities is expected to take years. However, experts contacted by CSOonline said the outcome will likely justify the time and expense.

"The better security comes from the lack of complexity," Ron Gula, chief executive and technical officer of Tenable Network Security, said.

Consolidating networks and standardizing systems mean less technology to monitor while making it easier to see when something has been compromised, Gula said.

The Pentagon has already started the transition. The U.S. European Command based in Stuttgart, Germany, was recently brought under a single security architecture. "We are building increments," Air Force Lt. Gen. Ronnie D. Hawkins Jr., head of the Defense Information Systems Agency, told National Defense.

The consolidation effort is likely to include having one data center in a region where there were multiple centers, said Jody Brazil, president and chief technology officer for network security management company FireMon. Having just one means "you now invest more heavily in securing that one data center."

"That's at least what I've heard them talk about and I think it makes sense," Brazil said. 

[In Depth: NSA surveillance controversy: Much ado about nothing new?]

Removing silos of technology spread throughout the Defense Department will make it much easier to monitor events across computer systems, Brazil said. In addition, performance data gathered from the systems will be easier to analyze for unusual occurrences. 

Sharing information across all entities will also be easier, because everyone will be able to understand the data, since it will come from the same systems. Brazil said.

For catching Snowden-like leakers, the Pentagon plans to standardize on identity access management technology used for fixed computers and mobile devices, Hawkins told National Defense. In addition, workers and contractors would be subject to "no notice inspections" to ensure they are complying with security standards.

No security architecture is bulletproof, particularly against the highly sophisticated, state-sponsored hackers the Defense Department is battling from countries like China. Experts acknowledged that breaching a standardized network could enable intruders to travel much deeper than they would if they had invaded a system unique to one agency.

However, having the same systems throughout means security pros will know the potential entry points. With different systems, those weaknesses are much more difficult to tract and monitor.

"I'd rather defend against a few knowns than defend against all the unknowns," Gula said.

The most difficult barrier the Pentagon is likely to face is the army of employees comfortable with the old computer systems, but who now have to march to something new.

"People as a species don't like change," Gula said. "They don't like to learn new things."

The Pentagon also will struggle to find enough experts to make the technical changes, administer the new systems and train employees to use them.

"That remains one of the bigger challenges," Brazil said.

Pentagon officials told National Defense that the transition will not require additional funding from Congress, but would come out of the Defense Department's cybersecurity budget.

This story is reprinted from CSO Online.com, an online resource for information executives. Story Copyright CXO Media Inc., 2006. All rights reserved.

View the original article here

Norton Internet Security (2014)

Pros Excellent blocking of malicious and fraudulent websites. Links to Identity Safe password manager and Norton Family parental control. Network Map monitors other Norton installations. Startup manager. Powerful, intelligent firewall. Accurate spam filtering. Minor impact on system performance.

Cons Some difficulty installing on malware-infested systems. Not compatible with some antivirus tests. Full-powered parental control requires separate purchase. Bottom Line All of the components in Norton Internet Security (2014) work well. The intelligent firewall and accurate antiphishing component especially stand out. Norton remains an Editors' Choice for security suites.

By Neil J. Rubenking

Back in days of yore, computer hobbyists would lovingly assemble a collection of best-in-breed security components, picking this company's antivirus, that company's firewall, and so on. But who has time for that these days? Modern users want one stop shopping, an all-in-one security suite that covers the whole gamut of security needs. Norton Internet Security (2014) ($79.99 per year direct for three licenses) is a perfect example—it does everything you need, and all of its components are effective.

Compare Selected

Just looking at the main window, the only way to tell the difference between this product and Norton's standalone antivirus is by the window title. Both products feature big buttons to launch a scan or check for updates. Another button switches to the advanced view, which offers easy on/off control of security components as well as links to important features. If you prefer the advanced view, you can pin it in place as the default.

The main window also links to a variety of other Norton products and services. You can click to get a mobile security QR code, or download the free Norton Zone file sharing tool. Another click will take you to Norton's online management tool. If you have a Norton Backup account you can quickly connect with it. And you can link to Norton Family, the source of this suite's parental control protection.

This suite's antivirus protection is exactly the same as what you get in Norton AntiVirus (2014), and the two products share a number of other features. I'll summarize my findings here; you'll want to read the antivirus review for full details.

Shared Antivirus Protection
Getting Norton installed on my twelve malware-infested test systems was a mixed experience. The product solved a few problems on its own; help from Norton Power Eraser and the Norton Bootable Recovery Tool solved others. But two systems ended up unbootable after malware cleanup. Getting those back to normal took hours of remote-access diagnostics and repair by tech support.

As far as independent lab testing, Symantec rejects many current test methodologies, static detection testing in particular. Norton includes layer upon layer of protection; they feel an accurate test should rate all layers. In fact, Norton earned an excellent score in the latest test by AV-Test, which includes both static and dynamic elements. The chart below summarizes recent results. For more about the labs, see How We Interpret Antivirus Lab Tests.

Related Story

Norton Internet Security (2014) lab tests chart

Norton also did well in my own hands-on malware removal test. It detected 81 percent of the samples and earned 6.3 points. Of products tested using my current malware collection, only AVG AntiVirus FREE 2014 and Bitdefender Internet Security (2014) have scored higher. The article How We Test Malware Removal explains how I conduct this test and score the results.

Related Story

Norton Internet Security (2014) malware removal chart

SecurityWatch

My malware blocking test relies in part on a product's ability to recognize static malware samples; just the kind of test Norton doesn't like. I do launch all the samples that aren't killed on sight, but to exercise the full range of Norton protection I'd have to start from the beginning by downloading and launching each sample, and that's not a test I can repeat on demand. Norton's Web-based detection did block every current sample whose URL is still valid, which is a good sign. Overall, though, its score of 8.5 points for malware blocking isn't the best. AVG and Ad-Aware Free Antivirus+ 10.5 scored best among current products, with 9.4 points each. For details on my hands-on malware blocking test, see How We Test Malware Blocking.

Related Story

Norton Internet Security (2014) malware blocking chart


View the original article here

Wednesday, 18 September 2013

Security company says Nasdaq waited two weeks to fix XSS flaw

A Swiss security company said the Nasdaq website had a serious cross-site scripting vulnerability for two weeks before being fixed on Monday, despite earlier warnings.

Ilia Kolochenko, CEO of the Geneva-based penetration testing company High-Tech Bridge, said he repeatedly emailed Nasdaq and warned of the XSS flaw.

[ The Web browser is your portal to the world -- and the gateway for security threats. InfoWorld's expert contributors show you how to secure your Web browsers. Download the free PDF today! | Stay up to date on the latest security developments with InfoWorld's Security Central newsletter. ]

"I can basically say I have spammed them," Kolochenko said in an interview.

Nasdaq.com lets users create accounts and build a profile to monitor stocks and news. Nasdaq said it did not believe the flaw was used by an attacker, and no personal data was compromised.

"We responded to his concerns immediately," Nasdaq said in an email statement. "We take all information security matters seriously. We work with leading security vendors and have a trained and professional team that evaluates all credible threats across our digital assets."

Cross-site scripting is an attack on a website in which a script drawn from another site is allowed to run that shouldn't. The attack can be used to steal information or potentially cause other malicious code to run.

Kolochenko said the flaw could have been used by an attacker in several ways, including stealing users' browser histories and their cookies. It could also have been used to inject HTML into a Web page and ask for people's personal details, a request that would appear to come from Nasdaq.

In another kind of attack, Kolochenko said the XSS flaw could be used to plant a link within the Nasdaq site to a malicious website.

Kolochenko said XSS flaws are common, and he has found ones in websites belonging to the BBC, Bloomberg and the Financial Times. Those organizations acknowledged the issues, but it was often a month or so before the websites were fixed, he said.

He found the Nasdaq flaw after noticing some suspicious URLs and conducting a harmless test. At that point, he stopped probing the website and notified Nasdaq by email on their support, abuse and security addresses.

"I didn't want to take it further," he said.

Nasdaq's trading halted on Aug. 22 after a technical problem with a core data feed that distributes market data for securities listed on its exchange. A connectivity issue degraded the ability of the Securities Industry Processor (SP) system to consolidate and disseminate quote and trade information on Nasdaq listed securities.

Send news tips and comments to jeremy_kirk@idg.com. Follow me on Twitter: @jeremy_kirk


View the original article here

Monday, 16 September 2013

Security company says Nasdaq waited two weeks to fix XSS flaw

September 16, 2013 12:55 PM ETIDG News Service - A Swiss security company said the Nasdaq website had a serious cross-site scripting vulnerability for two weeks before being fixed on Monday, despite earlier warnings.

Ilia Kolochenko, CEO of the Geneva-based penetration testing company High-Tech Bridge, said he repeatedly emailed Nasdaq and warned of the XSS flaw.

"I can basically say I have spammed them," Kolochenko said in an interview.

Nasdaq.com lets users create accounts and build a profile to monitor stocks and news. Nasdaq said it did not believe the flaw was used by an attacker, and no personal data was compromised.

"We responded to his concerns immediately," Nasdaq said in an email statement. "We take all information security matters seriously. We work with leading security vendors and have a trained and professional team that evaluates all credible threats across our digital assets."

Cross-site scripting is an attack on a website in which a script drawn from another site is allowed to run that shouldn't. The attack can be used to steal information or potentially cause other malicious code to run.

Kolochenko said the flaw could have been used by an attacker in several ways, including stealing users' browser histories and their cookies. It could also have been used to inject HTML into a Web page and ask for people's personal details, a request that would appear to come from Nasdaq.

In another kind of attack, Kolochenko said the XSS flaw could be used to plant a link within the Nasdaq site to a malicious website.

Kolochenko said XSS flaws are common, and he has found ones in websites belonging to the BBC, Bloomberg and the Financial Times. Those organizations acknowledged the issues, but it was often a month or so before the websites were fixed, he said.

He found the Nasdaq flaw after noticing some suspicious URLs and conducting a harmless test. At that point, he stopped probing the website and notified Nasdaq by email on their support, abuse and security addresses.

"I didn't want to take it further," he said.

Nasdaq's trading halted on Aug. 22 after a technical problem with a core data feed that distributes market data for securities listed on its exchange. A connectivity issue degraded the ability of the Securities Industry Processor (SP) system to consolidate and disseminate quote and trade information on Nasdaq listed securities.

Send news tips and comments to jeremy_kirk@idg.com. Follow me on Twitter: @jeremy_kirk

Reprinted with permission from IDG.net. Story copyright 2012 International Data Group. All rights reserved.

View the original article here

Thursday, 12 September 2013

Adobe issues critical security updates for Flash Player, Reader and Shockwave Player

Adobe released security updates for Flash Player, Adobe Reader and Shockwave Player on Tuesday to address critical vulnerabilities that could allow attackers to take control of systems running vulnerable versions of those programs.

The Flash Player updates address four memory corruption vulnerabilities that can lead to arbitrary code execution. The updates are version numbers 11.8.800.168 for Windows and Mac OS X; 11.2.202.310 for Linux; 11.1.115.81 for Android 4.x; and 11.1.111.73 for Android 3.x and 2.x.

[ InfoWorld's expert contributors show you how to secure your Web browsers in a free PDF guide. Download it today! | Learn how to protect your systems with Roger Grimes' Security Adviser blog and Security Central newsletter, both from InfoWorld. ]

Users of Google Chrome and Internet Explorer 10 on Windows 8 will automatically receive updates for the Flash Player plug-in bundled with those browsers through their respective update mechanisms.

The same Flash Player vulnerabilities were patched in Adobe AIR, a runtime for rich Internet applications that also bundles Flash Player. Adobe released version 3.8.0.1430 of AIR and AIR SDK (software development kit) for Windows, Mac OS X and Android.

New versions of Adobe Reader and Adobe Acrobat XI and X were released to address eight arbitrary code execution vulnerabilities: three memory corruption issues, two buffer overflows, two integer overflows and one stack overflow.

Users of Adobe Reader or Acrobat XI for Windows and Mac OS X are advised to upgrade to Adobe Reader XI (11.0.04) or Adobe Acrobat XI (11.0.04), respectively. Adobe Reader and Acrobat X for Windows and Mac have also been updated to version 10.1.8.

Adobe's Shockwave Player, an application required to display online content created with Adobe's Director software was updated to version 12.0.4.144 for Windows and Mac to address two memory corruption vulnerabilities that can lead to arbitrary code execution.

While not as popular as Flash Player, Shockwave Player is installed on 450 million Internet-enabled desktops, according to statistics from Adobe, which potentially makes it an attractive target for attackers.


View the original article here

Wednesday, 11 September 2013

Adobe issues critical security updates for Flash Player, Reader and Shockwave Player

Adobe released security updates for Flash Player, Adobe Reader and Shockwave Player on Tuesday to address critical vulnerabilities that could allow attackers to take control of systems running vulnerable versions of those programs.

The Flash Player updates address four memory corruption vulnerabilities that can lead to arbitrary code execution. The updates are version numbers 11.8.800.168 for Windows and Mac OS X; 11.2.202.310 for Linux; 11.1.115.81 for Android 4.x; and 11.1.111.73 for Android 3.x and 2.x.

[ InfoWorld's expert contributors show you how to secure your Web browsers in a free PDF guide. Download it today! | Learn how to protect your systems with Roger Grimes' Security Adviser blog and Security Central newsletter, both from InfoWorld. ]

Users of Google Chrome and Internet Explorer 10 on Windows 8 will automatically receive updates for the Flash Player plug-in bundled with those browsers through their respective update mechanisms.

The same Flash Player vulnerabilities were patched in Adobe AIR, a runtime for rich Internet applications that also bundles Flash Player. Adobe released version 3.8.0.1430 of AIR and AIR SDK (software development kit) for Windows, Mac OS X and Android.

New versions of Adobe Reader and Adobe Acrobat XI and X were released to address eight arbitrary code execution vulnerabilities: three memory corruption issues, two buffer overflows, two integer overflows and one stack overflow.

Users of Adobe Reader or Acrobat XI for Windows and Mac OS X are advised to upgrade to Adobe Reader XI (11.0.04) or Adobe Acrobat XI (11.0.04), respectively. Adobe Reader and Acrobat X for Windows and Mac have also been updated to version 10.1.8.

Adobe's Shockwave Player, an application required to display online content created with Adobe's Director software was updated to version 12.0.4.144 for Windows and Mac to address two memory corruption vulnerabilities that can lead to arbitrary code execution.

While not as popular as Flash Player, Shockwave Player is installed on 450 million Internet-enabled desktops, according to statistics from Adobe, which potentially makes it an attractive target for attackers.


View the original article here

Saturday, 7 September 2013

Salesforce.com mobile app developers gain security tools

Good Technology has integrated its Dynamics Secure Mobility Platform with Salesforce.com's Mobile SDK to help developers build mobile applications that are more secure and easily managed.

The growing popularity of smartphones and tablets combined with the BYOD (bring-your-own-device) trend presents several challenges to IT departments, including developing mobile applications and then efficiently managing and protecting them. Salesforce.com's Mobile SDK (software development kit) helps with the former and Good's Secure Mobility Platform offers the latter.

[ Learn how to work smarter, not harder with InfoWorld's roundup of all the tips and trends programmers need to know in the Developers' Survival Guide. Download the PDF today! | Keep up with the latest developer news with InfoWorld's Developer World newsletter. ]

The goal with the integration is to make it easier for Salesforce.com developers to build apps compatible with Good's containerization technology, which offers features such as app-level encryption as well as compliance and jailbreak detection. Enterprises can also put in place data loss prevention and automated actions that lock and wipe applications without impacting a user's device or personal data, according to Good.

The Mobile SDK, which is available for Android and iOS, is a key part of Salesforce.com's accelerating mobile push. It lets developers choose between building applications directly for Apple and Google's OSes, web applications or so-called hydrid applications -- which make it possible to embed HTML5 apps inside a native container.

Recently, Salesforce.com announced version 2.0 of the SDK, which added the SmartSync data framework allowing developers to create applications that work with data both off and online.

Good isn't the only mobile management tool vendor that's working with Salesforce. On Tuesday, competitor MobileIron announced Anyware. The hosted enterprise mobility management service lets administrators distribute mobile apps to employees as well as manage their devices from the Salesforce administration console, MobileIron said.

Send news tips and comments to mikael_ricknas@idg.com.


View the original article here

Salesforce.com mobile app developers gain security tools

IDG News Service - Good Technology has integrated its Dynamics Secure Mobility Platform with Salesforce.com's Mobile SDK to help developers build mobile applications that are more secure and easily managed.

The growing popularity of smartphones and tablets combined with the BYOD (bring-your-own-device) trend presents several challenges to IT departments, including developing mobile applications and then efficiently managing and protecting them. Salesforce.com's Mobile SDK (software development kit) helps with the former and Good's Secure Mobility Platform offers the latter.

The goal with the integration is to make it easier for Salesforce.com developers to build apps compatible with Good's containerization technology, which offers features such as app-level encryption as well as compliance and jailbreak detection. Enterprises can also put in place data loss prevention and automated actions that lock and wipe applications without impacting a user's device or personal data, according to Good.

The Mobile SDK, which is available for Android and iOS, is a key part of Salesforce.com's accelerating mobile push. It lets developers choose between building applications directly for Apple and Google's OSes, web applications or so-called hydrid applications -- which make it possible to embed HTML5 apps inside a native container.

Recently, Salesforce.com announced version 2.0 of the SDK, which added the SmartSync data framework allowing developers to create applications that work with data both off and online.

Good isn't the only mobile management tool vendor that's working with Salesforce. On Tuesday, competitor MobileIron announced Anyware. The hosted enterprise mobility management service lets administrators distribute mobile apps to employees as well as manage their devices from the Salesforce administration console, MobileIron said.

Send news tips and comments to mikael_ricknas@idg.com

Reprinted with permission from IDG.net. Story copyright 2012 International Data Group. All rights reserved.

View the original article here

Trust no one, advises security expert after NSA revelations

IDG News Service - The U.S. National Security Agency's efforts to defeat encrypted Internet communications, detailed in news stories this week, are an attack on the security of the Internet and on users' trust in the network, some security experts said.

The NSA and intelligence agencies in allied countries have found ways to circumvent much of the encryption used on the Internet, according to stories published by The New York Times, ProPublica and the Guardian. The NSA, the British GCHQ and other spy agencies have used a variety of means to defeat encryption, including supercomputers, court orders and behind-the-scenes agreements with technology companies, according to the news reports.

The reports, relying on documents provided by former NSA contractor Edward Snowden, show that many tech companies are collaborating with the spy agencies to "destroy privacy," said cryptographer and security specialist Bruce Schneier. "The fundamental fabric of the Internet has been destroyed."

The new revelations should raise major concerns from Internet users over who they can trust, Schneier added. "I assume that all big companies are now in cahoots with the NSA, cannot be trusted, are lying to us constantly," he said. "You cannot trust any company that makes any claims of the security of their products. Not one cloud provider, not one software provider, not one hardware manufacturer."

It doesn't appear that the NSA is defeating encryption by brute force but by "cheating" by attempting to build backdoors into systems and strong-arm companies into giving it information, Schneier said.

Digital rights group the Center for Democracy and Technology echoed some of Schneier's concerns, with CDT senior staff technologist Joseph Lorenzo Hall calling the NSA's encryption circumvention efforts "a fundamental attack on the way the Internet works."

The NSA has been working for years to build backdoor vulnerabilities into encryption standards and technology products, the stories said. A representative of the NSA didn't respond to a request for comment on the stories.

Hall criticized those efforts. "In an era in which businesses, as well as the average consumer, trust secure networks and technologies for sensitive transactions and private communications online, it's incredibly destructive for the NSA to add flaws to such critical infrastructure," he said in an email. "The NSA seems to be operating on the fantastically naA-ve assumption that any vulnerabilities it builds into core Internet technologies can only be exploited by itself and its global partners."

The New York Times story this week, citing a Guardian report from July, said Microsoft has worked with the NSA to provide the agency with pre-encryption access to Outlook, Skype and other products.

Microsoft has repeatedly denied helping the NSA break encryption on its products. The company complies with legal court orders for information on its customers and will provide agencies with unencrypted customer information residing on its servers if ordered by a court to do so, a spokeswoman said.

Reprinted with permission from IDG.net. Story copyright 2012 International Data Group. All rights reserved.

View the original article here

Tuesday, 27 August 2013

Kaspersky Internet Security (2014)

Pros Excellent antivirus lab test scores. Good score in hands-on malware removal test. Accurate phishing detection. Excellent spam filtering. Intelligent firewall blocks leak tests and exploits. Parental control system more complete than many suites. Safe Money feature adds layers of protection for sensitive online transactions.

Cons Just average score in hands-on malware blocking test. Some difficulty installing on malware-infested test systems. No remote management or monitoring with parental control. Bottom Line The 2014 edition of Kaspersky Internet Security includes everything you'd expect from a security suite, and all of the components work as they should. It doesn't score as well in my hands-on antivirus tests as in independent lab tests, but it's a good choice for protection.

By Neil J. Rubenking

The point of getting a security suite rather than a collection of individual security components is to have all elements of your security protection working together. Kaspersky Internet Security (2014) smoothly combines antivirus, firewall, phishing protection, antispam, parental control, and more. The components all do a good job; no slackers in this bunch! Do note that "(2014)" isn't actually part of the name, as Kaspersky has gone number-free. I include it simply to distinguish this version from others.

Compare Selected

The product's main window looks very, very similar to Kaspersky's standalone antivirus. It reports basic security status and offers quick access to four important components. The real visible difference comes when you click the up-arrow at bottom right to see the full component list; now you can see that the suite does more, a lot more.

Shared Antivirus
Kaspersky's protection against viruses, spyware, Trojans, and all other types of malware is the same as what you get in the standalone Kaspersky Anti-Virus (2014), so you'll want to read my review of that product for full details. I'll briefly summarize my findings here.

Getting the product installed on my twelve malware-infested test system took quite a bit of back-and-forth with tech support. It stretched into several days due to time-zone differences. In the end all of the problems were solved by use of Kaspersky's own ancillary security tools, which is good.

Kaspersky detected 81 percent of the malware samples and scored 6.1 points for removal. The best product among those tested with the same collection of samples was Bitdefender Internet Security (2014), which detected 83 percent and scored 6.6 points. For a full explanation of my hands-on malware removal test, see How We Test Malware Removal.

Related Story

Kaspersky Internet Security (2014) malware removal chart

In my malware blocking test, Kaspersky scored lower than many, with 86 percent detection and 8.2 points. That's decent, but Ad-Aware Pro Security 10.5 beat all others tested using this same sample set with 94 percent detection and an impressive 9.4 points. For details on how I perform the hands-on malware blocking test, see How We Test Malware Blocking.

Related Story

Kaspersky Internet Security (2014) malware blocking chart

SecurityWatch

Kaspersky always seems to score better with the independent labs than in my hands-on test; I give it credit for those good ratings. It earned top ratings in all the tests that I track from AV-Comparatives and averaged 15.8 of 18 possible points in AV-Test's three-fold evaluation. Only Bitdefender has earned consistenly higher scores. To learn more about the independent antivirus labs and their tests, please see How We Interpret Antivirus Lab Tests.

Related Story

Kaspersky Internet Security (2014) lab tests chart  

Other Shared Features
The same Web Anti-Virus technology that prevents accidental access to malware-hosting websites also serves to keep users away from fraudulent (phishing) websites. Like all truly effective antiphishing solutions, Kaspersky uses a combination of cloud-based lookup for known phishing sites and heuristic analysis of unknowns. When I tested it using extremely fresh phishing URLs, Kaspersky's detection rate was just one percentage point behind that of consistent phishing champ Norton Internet Security (2013). For an explanation of how I locate the newest phishing URLs and perform this test, see How We Test Antiphishing.

Related Story

Kaspersky Internet Security (2014) antiphishing chart

As with the standalone antivirus, Kaspersky's suite builds tech support right into the product. Both also offer a useful collection of security-related bonus tools, including a bootable Rescue Disk, a vulnerability scanner, and tools to wipe traces of computer and Internet use.


View the original article here

Saturday, 24 August 2013

10gen CEO: NoSQL has come far, but still needs better security, management

10gen CEO: NoSQL has come far, but still needs better security, management
Credit: iStockPhoto

While NoSQL has made great strides, it will need improvements in multiple areas in order to gain wider acceptance, Max Schireson, the CEO of MongoDB NoSQL database vendor 10gen, said.

NoSQL databases are known for being able to handle great amounts of data that does not necessarily fit well into the relational model, but there is work to be done in areas such as security and manageability in order for NoSQL to gain more adoption, said Schireson at the recent NoSQL Now 2013 conference in San Jose, Calif. "There's lots of work to do before NoSQL as a sector can win."

The NoSQL ecosystem, he said, needs to mature before it can go from a 15- to 20-percent usage level to being used across all organizations with large-scale IT needs. NoSQL needs security improvements like encryption of data and integration with Kerberos and LDAP. It also needs improvements in manageability and integration. Problems like fragmentation and lack of standardization also need to be addressed, Schireson said, noting that NoSQL needs to be made more accessible for users and that it should be easier to do queries and to query different things in new ways.

He also stressed NoSQL vendor priorities, saying that "we need to value user success over short-term monetization." For example, free, open source downloads need to be well-tested and solid. Vendors also must understand what their products can do better than anything else out there and build a product ecosystem, Schireson said.

Improvement already is being seen in the number of persons with NoSQL skills, but it is still a small number, Schireson said. He cited the presence of 50,000 developers with MongoDB skills listed on their LinkedIn accounts. "[The] skill base is growing rapidly." NoSQL already has been embraced by large IT companies like IBM and Microsoft, Schireson noted, further predicting that relational databases will continue to be a big part of the market, but not as dominant as they are today.

This story, "10gen CEO: NoSQL has come far, but still needs better security, management," was originally published at InfoWorld.com. Get the first word on what the important tech news really means with the InfoWorld Tech Watch blog. For the latest developments in business technology news, follow InfoWorld.com on Twitter.


View the original article here

Mozilla 'Plug-n-Hack' project aims for tighter security tool integration

Mozilla is developing a protocol that aims to let security tools and Web browsers work better together.

Configuring a Web browser to work with a security tool involves writing platform and browser-specific extensions, a nontrivial process that discourages people with less experience, wrote Simon Bennetts, a security automation engineer with Mozilla, on Thursday.

[ InfoWorld's experts show you how to safeguard your browsers in the "Web Browser Security Deep Dive" PDF guide. Download it today! | For a quick, smart take on the news you'll be talking about, check out InfoWorld TechBrief -- subscribe today. ]

The proposed standard, called "Plug-n-Hack," will define how security extensions can work with a browser in a more usable way, Bennetts wrote. PnH will allow the security tool to "declare the functionality that they support which is suitable for invoking directly from the browser."

Under the current arrangement, if a user wants to, for example, intercept HTTPS traffic, a user must configure proxy connections through the tool and browser correctly and import the tool's SSL (Secure Sockets Layer) certificate, Bennetts wrote.

"If any of these steps are carried out incorrectly then the browser will typically fail to connect to any website -- debugging such problems can be frustrating and time-consuming," Bennetts wrote.

Users may also have to switch often between the tool and their browser to intercept an HTTPS request.

"PnH allows security tools to declare the functionality that they support which is suitable for invoking directly from the browser," Bennets wrote. "A browser that supports PnH can then allow the user to invoke such functionality without having to switch to and from the tool."

The PnH protocol is being designed to be browser and tool independent. The implementation for Firefox has been released under the Mozilla Public License 2.0 and can be incorporated into commercial products for free, Bennetts wrote.

The next phase of the project is being planned, but it is expected it will allow browsers to "advertise their capabilities to security tools," he wrote.

"This will allow the tools to obtain information directly from the browser, and even use the browser as an extension of the tool," Bennetts wrote.

Send news tips and comments to jeremy_kirk@idg.com. Follow me on Twitter: @jeremy_kirk


View the original article here

Friday, 23 August 2013

10 security tips for customer support and service

CSO - What every company hopes dearly to avoid is the customer facing security incidents especially those involving compromise of customer information. While the issues related to retail customer information usually get primetime coverage, there is also the significant issue of B2B interactions with our corporate customers and partners.

Companies involved with software and system delivery projects often require customer service, sales and support staff to be deeply engaged with the customers. Often a single employee maybe dealing with multiple customers.

It is quite possible in this situation for an employee to accidentally send email with information for customer A to customer B. We're human, mistakes will happen. In my experience the more we can move to secure systems and processes, the less we need to depend on the busy employee to not make an honest mistake.

Below are top 10 tips for security organizations to implement for their support and services delivery organizations:

Move customer information out of email or local storage

Customer information should be maintained in a separate access controlled system with regular security reviews of access and usage. Customer passwords, account information etc should not be sitting in personal email accounts which can be compromised or accidentally mis-directed.

Strongly discourage storage of company data on personal accounts on public cloud systems. This cloud storage also exposes the company to high risk when such systems are hacked or compromised as in the case of Evernote earlier this year

Clearly separate out internal versus external customer content very explicitly

If you have to keep customer data in email or other local systems, and then make sure you put in as much system controls as possible to prevent accidental disclosure. If you are working on a customer issue that has an internal company thread, create separate folders for all customer communication and another separate folder for the internal thread. These separate folders ensures that you do not accidentally forward an internal thread to the customer. Mark all internal threads as 'INTERNAL'

Keep an eye on the training material and process

Employees will often create ad hoc material for one off training and sometimes will include customer data in this training material. Be very clear that no customer information is to be moved into training material at any time. Do not copy customer data into non-protected locations, spreadsheets or documents for training or other purposes. This information can be accidentally distributed to unauthorized recipients

Watch the new hires

New hires especially project managers or customer representatives may not fully get the implications of a data disclosure. They may not have enough time to understand the details of the systems before their first customer interaction, Make sure they get adequate new hire training on information security processes and data disclosure implications.

Follow a double check process

Ask employees to follow a 'double-check' process with customer communication. Every employee should check and check again all outgoing communication to the customer prior to sending. Verify that there is no confidential information going through.

Follow a simple data classification process

Mark email or documents as confidential when needed. This adds an additional layer of review.

Guard the customer data closely, even from the customer

Do not communicate customer login and password information via email to anyone including the customer. Customer staff or contractors may not be authorized to have the information/access level. Provide information based on the account setting only.

Be careful about what you sign and agree to with the customer

Do not sign any NDAs or security agreements without the approval of the Legal team

Change Customer system with caution

Some of our teams have actual access to customer systems to troubleshoot. Do not change settings or data on a customer system without communication in writing and (preferably) a backup

Encrypt hard drives

All Support and services staff should have encrypted hard drives whether they be USB sticks or laptop hard drives. Encryption reduces the risk of disclosure when the drive is lost.

George Viegas, CISSP, CISA is Director of Information Security at a leading multinational information and media company based in Los Angeles.

This story is reprinted from CSO Online.com, an online resource for information executives. Story Copyright CXO Media Inc., 2006. All rights reserved.

View the original article here

Wednesday, 21 August 2013

Security expert kick-starts fund to pay Facebook bug finder a $10K bounty

Computerworld - After a Palestinian researcher was denied a bug bounty by Facebook, Marc Maiffret, CTO of BeyondTrust, kicked off a crowd-sourced fund yesterday to come up with a reward.

The researcher, Khalil Shreateh, expressed his gratitude today to Maiffret and others who have contributed to the fund. "Thank you so much. I never imagined what they will do for me," Shreateh said in a telephone interview.

Seventy-nine people have contributed nearly $9,000 in the last 24 hours to an account that will be handed over to Shreateh once it reaches the goal of $10,000.

Maiffret seeded the fund with $3,000 of his own money after appearing on CNN to talk about the Facebook vulnerability that Shreateh found.

Earlier this month Shreateh reported a vulnerability to Facebook's bug bounty program, saying that he had found a way to post content to any user's timeline, even when not on a victim's friends list. Facebook rebuffed him in return emails and ultimately claimed his discovery wasn't a bug.

Frustrated, Shreateh took matters into his own hands and planted a message on CEO Mark Zuckerberg's Facebook timeline.

That got the attention of Facebook's security engineers, who quickly locked Shreateh out of his account. After restoring his access, Facebook said it would not pay him a bounty.

"The more important issue here is with how the bug was demonstrated using the accounts of real people without their permission," said Facebook software engineer Matt Jones in a Sunday entry on Hacker News. "Exploiting bugs to impact real users is not acceptable behavior for a white hat."

Jones did acknowledge that Facebook should have asked Shreateh for more information before dismissing his report, but he also ticked off a list of reasons, including the fact that Facebook receives "hundreds of reports each day" and the lack of detailed proof in Shreateh's original report. He also intimated that Shreateh's poor English skills had been a problem.

In an interview on CNN Monday, Maiffret took exception to Facebook's decision not to reward Shreateh.

"Ultimately, he helped kill a bug that could have been used by pretty bad guys out there to do things against Facebook users," said Maiffret. "Ultimately, he did a great thing and I don't think that should be lost in all this."

The vulnerability was certainly worth money to criminals, Maiffret asserted. "It would have been something that was very useful to folks in the underground to be able to post different content on celebrity sites or whatever it might have been, to be able to lure people to websites that would then attack them," he said. "With the nature of the severity, it would be good for Facebook to pay the guy."

How Cloud Communications Reduce Costs and Increase ProductivitySmall and midsize businesses are moving to the cloud to host their communications capabilities. Learn how enterprise-quality phone benefits, online management, conferencing, auto attendant, and ease of use are built into a system that is half the cost of a PBX.

Read now.


View the original article here

VMware, Citrix and Microsoft virtual desktops get encryption security

Network World - AFORE Solutions today announced encryption software aimed at securing data in virtualized environments where Microsoft Windows applications are used, including virtualized desktop infrastructure deployments based on VMware, Citrix or Microsoft VDI.

AFORE's CypherX software can be used by either cloud providers on behalf of their customers or directly by the enterprise users in a private cloud deployment, according to the security firm's chairman and chief strategy officer, Jon Reeves. "This is intended for secure storage in the cloud," Reeves said about CypherX. "It sits between the application and the operating system itself in order to lock down applications. It encrypts all information flowing in and out, the file system, and the network or the clipboard."

7 IT security skills certifications on the rise

Using standard AES 256-bit encryption, CypherX works on A multiple hypervisors, including VMware vSphere, Microsoft Hyper-V and Xen and KVM. It supports multiple desktop virtualization platforms, including VMware's Horizon View, Citrix XenDesktop, and Microsoft's VDI.

CypherX has an App Lockdown feature that acts as a virtual container for applications, and so-called "CypherZones" can be set up to extend security between groups of protected applications. CypherX Manager, which can be integrated with Active Directory and RSA Data Protection Manager, is used to provide centralized control of security policy across virtual machines.

"You pick which applications need to be secured, say a hosted medical record, and it's set up as a trusted application and everything coming in or out is encrypted," Reeves says. CypherX allows the security manager to establish a control process in which only authorized users on validated machines can access an application certified as trusted. Reeves says CypherX in some regards can be compared to information rights management systems from Microsoft or Oracle in its functionality.

Ottawa, Canada-based AFORE's other product, CloudLink Secure VSA, is a virtual storage appliance used for encryption in VMware Vblock infrastructures.

Now in beta tests with a number of cloud providers, CypherX starts at $150 per seat, though less based on volume, and is expected to be generally available in the October timeframe.

Ellen Messmer is senior editor at Network World, an IDG publication and website, where she covers news and technology trends related to information security. Twitter: MessmerE. E-mail: emessmer@nww.com

Read more about data center in Network World's Data Center section.

Reprinted with permission from NetworkWorld.com. Story copyright 2012 Network World, Inc. All rights reserved.

View the original article here