dottyslashdottydot writes "CBC Marketplace recently ran a sting operation and discovered that most home computer repair technicians failed miserably at diagnosing a simple RAM failure. Many techs tried to sell unneccessary software or upgrades. (or even a new computer!) However, the worst offender was one guy who claimed that the hard drive had failed, and that the only remedy was to pay $2,000 to have a special facility with a clean room recover the data."Read more of this storyat Slashdot.
An anonymous reader writes "Here's a story about what can happen to any enterprise IT department that overestimates the intelligence of its users. Only in this case, the enterprise in question is the U.S. Department of Homeland Security. The spokesman says there's no Jack Bauer mentality. No kidding!"Read more of this storyat Slashdot.
Kelson writes "The Internet Explorer team has updated the installer for IE7. Mostly they've adjusted a few defaults and updated their tutorials, but one change stands out: The installer no longer requires Windows Genuine Advantage validation. Almost a year after its release, IE7 has yet to overtake its predecessor. Was WGA holding back a tide of potential upgrades, or did it just send people over to alternative browsers?"Read more of this storyat Slashdot.
m-stone writes "Online auction house eBay recently did a threat assessment to better understand the forces ranging against them. The company is keeping the fine details under wraps, but the biggest source of danger for the company is apparently botnets. You're never going to guess who was running them. '[Dave Cullinane, eBay's chief information and security officer] noticed an unusual trend when taking down phishing sites. 'The vast majority of the threats we saw were rootkitted Linux boxes, which was rather startling. We expected Microsoft boxes,' he said. Rootkit software covers the tracks of the attackers and can be extremely difficult to detect. According to Cullinane, none of the Linux operators whose machines had been compromised were even aware they'd been infected. Because Linux is highly reliable and a great platform for running server software, Linux machines are desired by phishers, who set up fake websites, hoping to lure victims into disclosing their passwords."Read more of this storyat Slashdot.
Technical Writing Geek writes with the news that the retail industry is getting mighty fed up over credit card company policies requiring them to store payment data. The National Retail Federation (NRF) has gone to bat for store owners, asking the credit industry to change their policies. The frustration stems from payment card industry (PCI) standards and new security measures going into place across the retail experience. Retailers are now trying to point out that many of the elements of the standard would not be a requirement if they didn't have to store so much payment data. "Even if the NRF's demands were immediately met, it would take several years before retailers could purge their systems and applications of credit card data, he said. Over the years, retailers have collected and stored credit card data in myriad systems and places -- including relatively old legacy environments -- and they are just now realizing the data can be a challenge, he said. Purging it can be a bigger headache because the data is often inextricably linked to and used by a variety of customer and marketing applications; simply removing it could cause huge disruptions."Read more of this storyat Slashdot.
An anonymous reader writes "The Ecuador Tax Agency (SRI) has closed Microsoft branch offices for seven days. 'We have twice requested balances, payment reports and complete tax information, but the company hasn't given it to us, so in accordance with our laws we have proceeded with the closure,' the SRI official in charge of the proceeding said. Microsoft said it was a human mistake."Read more of this storyat Slashdot.
sjdurfey writes "Microsoft recently decided to open up IE7 to all users of Windows, not just the ones with legitimate copies of Windows. They claim it is in the 'end-users best interest'. As a result, Microsoft has decided to mark IE7 as a 'High-priority' update. This is essentially a forced update. Granted, its only a forced update if you are running Windows and have windows update set to automatically install all updates, but nevertheless, it's unnecessary. You can however uninstall IE7 from the Add/Remove Programs menu after its been installed. 'A blocking tool kit is still available for companies and organizations that don't use Windows Server Update Services and want to permanently prevent IE7 from automatically installing on PCs equipped with IE6.'" Update: 10/06 21:19 GMT by Z :Sorry if this seems a bit familiar.Read more of this storyat Slashdot.
dalektcalum writes "Dr. Ann Cavoukian, Canada's Information and Privacy Commissioner, recently gave a talk entitled Privacy by Design. The talk starts off by covering the basics of privacy, and privacy law, and then moves onto the important component: how to design software that properly protects users privacy. The majority of the talk is spent on design principles, but also examines specific technologies (such as Elliptical Curve Cryptography)." The site includes a flash video of the talk, but there are also several torrents for folks who want to avoid hammering their servers.Read more of this storyat Slashdot.
SkiifGeek writes "A survey carried out by McAfee and the NCSA found that while more than 90% of users believed that they were protected by antivirus or antimalware products that were updated at least once a week, only 51% actually were. 'Even with significantly growing awareness by everyday users of the need for efficient and effective antivirus / antimalware software, and the increasing market penetration achieved by the security industry, the nature of rapidly evolving Information Security threats means that the baseline of protection is outstripping the ability of users to keep up (without some form of extra help).' The study is available online in PDF format. What sort of an effect does this sort of thinking, and practice, have on the overall security of your systems, networks, and efforts to educate?"Read more of this storyat Slashdot.
jBubba writes "Windows XP SP3 build 3205 is the first official & authorized release of the next Windows XP service pack; and has been made available to testers as a part of the Windows Server 2008/Windows Vista SP1 beta program. NeoSmart Technologies has the run-down on the included 1,073 patches/hotfixes including security updates. Contrary to popular belief, Windows XP SP3 does ship with new features/components, most of which have been backported from Windows Vista. Some included features: 'New Windows Product Activation model: no need to enter product key during setup. Network Access Protection modules and policies have been brought to XP after being one of the more-well-received features in Windows Vista. New Microsoft Kernel Mode Cryptographic Module - the Windows XP SP3 kernel now includes an entire module that provides easy access to multiple cryptographic algorithms and is available for use in kernel-mode drivers and services. New "Black Hole Router" detection - Windows XP SP3 can detect and protect against rogue routers that are discarding data.'"Read more of this storyat Slashdot.
FlopEJoe writes "Ticketmaster claims that RMG Technologies is providing software to avoid security measures on their website - even to the point of utilizing bots to get large blocks of tickets. RMG says it just 'provides a specialized browser for ticket brokers.' From the New York Times article: 'The fact that tickets to popular events sell out so quickly -- and that brokers and online resellers obtain them with such velocity -- is clouding the business, many in the music industry say. It is enough, some longtime concertgoers say, to make them long for the days when all they had to do to obtain tickets was camp out overnight.'"Read more of this storyat Slashdot.
50Mat writes "Adobe has fessed up to a dangerous code execution vulnerability affecting software programs installed on millions of Windows machines. The flaw, publicly disclosed more than three weeks ago, could allow hackers to use rigged PDF files to take control of Window XP computers with Internet Explorer 7 installed. It affects Adobe Reader, Adobe Acrobat Standard, Professional and Elements and Adobe Acrobat 3D."Read more of this storyat Slashdot.
PMcGovern writes "Deadline for nominations for SysAdmin of the Year 2007 is this Friday Oct. 12. The award is sponsored by Slashdot, SourceForge, Digg, Usenix, Lopsa, Splunk, and Naspa. The first 2500 sysadmins nominated win a free SysAdmin Rockstar tee shirt. Prizes include a MacBook Pro, a non-bricked Apple iPhone, Gibson guitar, Splunk license, a full-paid trip to the LISA conference, cases of Red Bull, and more. If you know a sysadmin that goes beyond the call of duty, nominate them."Read more of this storyat Slashdot.
theodp writes "Two years ago, Robert X. Cringely wrote that Google was experimenting with portable data centers built in standard shipping containers. The idea, Cringely explained, wasn't new and wasn't even Google's, backing up his claim with a link to an Internet-Archive-in-a-Shipping-Container presentation (PDF, dated 11-8-2003) that was reportedly pitched to Larry Page. Google filed for a patent on essentially the same concept on 12-30-2003. And on Tuesday, the USPTO issued the search giant a patent for Modular Data Centers housed in shipping containers, which Google curiously notes facilitate 'rapid and easy relocation to another site depending on changing economic factors'. That's a statement that may make those tax-abating NC officials a tad uneasy."Read more of this storyat Slashdot.