Language Selection

English French German Italian Portuguese Spanish

RSS, Spyware’s next frontier.

Filed under
Security

Richard Stiennon VP of Threat Research at anti-Spyware company Webroot Software, Inc earlier this year announced his predictions for 2005 in relation to security vulnerabilities and Spyware problems. Most of the predictions were fairly predictable like:

The number of new Microsoft vulnerabilities will grow.

Which isn’t a surprise to anyone in the IT industry and probably a good many people that aren’t. Other predictions like: The US and European nations will pass anti-spyware laws, and the number of different types of spyware will double to 3,000 are not exactly unexpected either.

However at least one of the predictions causes a pause for further thought. In short one prediction that RSS syndication will soon be used as a tool to distribute advertising, Spyware and other malicious code. RSS is basically just XML so the medium isn’t potentially dangerous by itself, but flaws that target specific RSS readers could conceivably result in the transfer of Spyware. RSS is already being used to distribute advertising so that one isn’t a surprise either. RSS has most of the benefits of E-mail and that means it also has most of the problems. One of those problems is that malicious parties can use social engineering tricks to get people to follow links in RSS to download malicious content, which is probably what Mr Stiennon meant. The problem with that theory is that a user must first subscribe to an RSS feed to be at risk at all, which makes it considerably less reliable a method of transferring malicious content then E-mail or web pages.

One other prediction Mr Stiennon made was that Firefox would become the target of Spyware sometime in the first half of this year. I’m not so sure about this one because it is mostly the more techie users that have become hooked on Firefox and they would not be particularly good targets for Spyware since they are also the kind of users most likely to have anti-Virus and anti-Spyware software running, if they are using Windows that is.

Source.

More in Tux Machines

Q4OS 1.6, Orion

The significant Q4OS 1.6 'Orion' release receives the most recent Trinity R14.0.3 stable version. Trinity R14.0.3 is the third maintenance release of the R14 series, it is intended to promptly bring bug fixes to users, while preserving overall stability. The complete list and release notes you will find on the Trinity desktop environment website. New Q4OS 1.6 release includes set of new features and fixes. The default desktop look has been slightly changed, Q4OS 'Bourbon' start menu and taskbar has been polished a bit and has got a few enhancements, for example the icons size varies proportionally to the system panel. Native Desktop profiler tool has got new, optimized 'software to install' list. Read more

Learning More About Explicit Fencing & Android's Sync Framework

With the sync validation framework leaving the staging area in Linux 4.9 and other work going on around the Android sync framework and explicit fencing, this functionality is becoming a reality that ultimately benefits the Linux desktop. Collabora developer Gustavo Padovan presented at this week's LinuxCon 2016 conference about explicit fencing support in the mainline kernel with a "new era of graphics." Read more

Ubuntu Leftovers

Leftovers: Software Development

  • fakecloud
  • A new version of pristine-tar
  • Getting RSS feeds for news websites that don’t provide them
    On the technical side, this seems to be one of the most stable pieces of software I ever wrote. It never crashed or otherwise failed since I started running it, and fortunately I also didn’t have to update the HTML parsing code yet because of website changes. It’s written in Haskell, using the Scotty web framework, Cereal serialization library for storing the history of the past articles, http-conduit for fetching the websites, and html-conduit for parsing the HTML. Overall a very pleasant experience, thanks to the language being very convenient to write and preventing most silly mistakes at compile-time, and the high quality of the libraries.
  • Quick Highlight
    Martin Blanchard put together a new “quick highlight” plugin for Builder this last week. It was a great example of how to submit a new feature, so I just wanted to highlight it here. Post to bugzilla, attach a patch, and we will review quickly and help with any additional integration that might be necessary.