Showing posts with label microsoft. Show all posts
Showing posts with label microsoft. Show all posts

9/06/2011

Microsoft: Stolen SSL certs can't be used to install malware via Windows Update


Updates also code-signed by separate certificate that Microsoft controls

By Gregg Keizer, Computerworld
September 06, 2011 11:47 AM ET


Microsoft said Sunday that a digital certificate stolen from a Dutch company could not be used to force-feed customers malware through its Windows Update service.
The company's assertion came after a massive theft of more than 500 SSL (secure socket layer) certificates, including several that could be used to impersonate Microsoft's update services, was revealed by Dutch authorities and several other affected developers.
"Attackers are not able to leverage a fraudulent Windows Update certificate to install malware via the Windows Update servers," said Jonathan Ness, an engineer with the Microsoft Security Response Center (MSRC), in a Sunday blog post. "The Windows Update client will only install binary payloads signed by the actual Microsoft root certificate, which is issued and secured by Microsoft."
Seven of the 531 certificates now known to have been fraudulently obtained by hackers in July were for the domains update.microsoft.com and windowsupdate.com, while another six were for *.microsoft.com.

According to Microsoft, the certificates issued for windowsupdate.com couldn't be used by attackers because the company no longer uses that domain. (Windows Update is now at windowsupdate.microsoft.com..) However, those for update.microsoft.com -- the domain for Microsoft Update -- and the wildcard *.microsoft.com could be.
As Ness said, updates delivered via Microsoft's services are signed with a separate certificate that's closely held by the company.
Without that code-signing certificate, attempts to deliver malware disguised as an update to a Windows PC would fail.
Other vendors, including Apple, also sign software updates with a separate certificate.
The certificates for the various Microsoft domains were issued by DigiNotar, a Dutch company that last week admitted its network had been hacked in mid-July .
The company initially believed it had revoked all the fraudulent certificates, but later realized it had overlooked one that could be used to impersonate any Google service, including Gmail. DigiNotar went public only after users reported their findings to Google.
Criminals or governments could use the stolen certificates to conduct "man-in-the-middle" attacks, tricking users into thinking they were at a legitimate site when in fact their communications were being secretly intercepted.
Microsoft has added its voice to the chorus from rival browser makers, notably Google and Mozilla, about the seriousness of the situation. Like its competitors, Microsoft will also permanently block all DigiNotar certificates.
"We are in the process of moving all DigiNotar owned or managed [certificate authorities] to the Untrusted Root Store, which will deny access to any website using DigiNotar certificates," said Dave Forstrom, a director in the Microsoft Trustworthy Computing group, in an emailed statement Sunday.
Forstrom did not set a date by when Microsoft would block all DigiNotar certificates, including those used by the Dutch government, which has been a major customer of the company.
Google updated Chrome on Saturday to block all DigiNotar certificates, while Mozilla plans to do the same on Tuesday for Firefox.
However, Microsoft's partial ban of DigiNotar certificates -- which it instituted last week -- and the complete sanction now in the works only protects users running Windows Vista, Windows 7, Windows Server 2008 and Windows Server 2008 R2.
Customers still on Windows XP or Windows Server 2003 must wait for an update specific to those operating systems; Ness said only that that update would "be available soon."
Until that Windows XP update is available, users can protect themselves by manually deleting the DigiNotar root from the list of approved certificate-issuing authorities. Microsoft has posted lengthy instructions for doing that on its "Security Research & Defense" blog.

Source: NetworkWorld and ComputerWorld

4/22/2009

Pay-as-you-go services could cut software piracy, Microsoft exec says


Research chief Craig Mundie: Usage-metering payment plans would cut upfront costs, encourage more legitimate purchases


Craig Mundie, who heads Microsoft Corp.'s research efforts, said in China today that the company may be able to reduce its losses from software piracy by expanding the use of pay-as-you-go computing plans similar to ones it has tested in some developing countries.

Charging users based on the time they spend accessing online services, instead of an upfront purchase fee, could "take some of the pressure off of the purely licensed model of software," Mundie said in an interview in Beijing.

3/27/2009

The Future of Cloud Computing

The Future of Cloud Computing
— As new offerings like Amazon's CloudFront, Microsoft's Azure, and VMware's vCloud are rolled out, the worldwide cloud computing momentum continues to grow. Here, SYS-CON's Cloud Computing Journal surveys a globe-girdling network of leading infrastructure experts, IT industry executives and technology commentators for their views on The Shape of Cloud Computing To Come.


3/18/2009

Microsoft and Open Source

Are you looking for a web site where you can discuss about open source? Why not try this one? The Port25 was created by Open Source Software Lab of Microsoft Corp. Its a place where you can find an open conversation dedicated Linux, Windows and open source interoperability.

Brazil - Porta 25

US - Port25


2/23/2009

A new Web browser from Microsoft

Microsoft researchers are developing a new web browser with stronger security. Good for the market, good for the users. The new browser called "Gazelle" was built on C#. Still a prototype, sure. But the researchers said their approach brings more reliability and better security.

Gazelle intends to consider each part of a Web site, such as iframes, subframes and plugins, as separate elements.

Read more in this recently published paper.