Google
 

Aardvark Daily

New Zealand's longest-running online daily news and commentary publication, now in its 23rd year. The opinion pieces presented here are not purported to be fact but reasonable effort is made to ensure accuracy.

Content copyright © 1995 - 2017 to Bruce Simpson (aka Aardvark), the logo was kindly created for Aardvark Daily by the folks at aardvark.co.uk



Please visit the sponsor!
Please visit the sponsor!

Microsoft Deja Vu

10 May 2017

You don't have to cast your mind back far to recall the era when every day that passed would bring news of a new zero-day exploit which placed your computer at risk of being hijacked by a virus or malware -- if you run a version of Windows.

Fortunately, Microsoft eventually woke up to the importance of providing a secure environment and in more recent times, Windows has become a platform that delivers reasonable (although not outstanding) levels of protection against such malevolence online.

The resilience of Windows has grown to such an extent that now the hacker community seems to be spending more time targeting Android and Apple platforms, much to the relief of those who still bash away at a Windows-based desktop PC.

Sadly however, it looks as if (at least temporarily) the bad times are back and everyone running MS Windows is now wide-open to having control of their system stolen from them by something as simple as an email or a compromised webpage.

Fortunately, Microsoft has announced it will be releasing an emergency security update to address the issue -- not that they really had much choice.

Smart folk will be making sure that their Windows systems are patched ASAP but I suspect that a lot of others will not be so diligent and this vulnerability opens the door to the creation of even bigger and more powerful botnets and other malware.

Days like today remind me why I'm a Linux user.

No, Linux is not immune to such vulnerabilities and there are plenty of dangers out there for those of us who choose to shun Microsoft and Apple -- but at least I feel like a much smaller target that is less likely to attract the attention of the evil little sods who are often behind such attacks.

This news is also a very timely reminder to everyone that backups are not optional, they are essential -- as is paying rigorous attention to keeping your systems patched and up to date.

This latest announcement is perfect proof that, no matter how mature and solid a system appears to be, there can always be yet another vulnerability just waiting to be found.

What worries me is that the NSA hadn't already found this one and built some surveillance technology around it -- or had they? Well at least at the time their secrets were spilled to the world it seems that even they didn't know about this one.

I wonder what happens if/when the next massive vulnerability is discovered by a group of black-hat hackers who decide to mount an asserted attack on all the world's computers using the affected platform. If they did the job properly, using their existing botnets to scan and infect every machine they could find, such a project could effectively bring huge swathes of the world's computing resources to their knees.

I recall the "Code Red" worm which swept across the face of the web like a wildfire back at the turn of the century -- imagine that multiplied by several orders of magnitude -- that is what a modern zero-day-exploit, carefully crafted worm could produce.

The global loss of productivity would be phenomenal and the effects of such a disaster would echo for a very long time. Perhaps the only safe refuge would be the cloud -- unless the worm exploited the platforms on which such services run, in which case the cloud would remain a hub of infection.

Ah, isn't it great that we live in such interesting times?

How much of a role does the security of an environment play in your decision-making process?

What strategies do you have in place to help mitigate the risk and what recovery procedures have you designed to allow a timely and effective recovery if your platform was ever compromised?

Please visit the sponsor!
Please visit the sponsor!

Have your say in the Aardvark Forums.

PERMALINK to this column


Rank This Aardvark Page

 

Change Font

Sci-Tech headlines

 


Features:

Beware The Alternative Energy Scammers

The Great "Run Your Car On Water" Scam

 

The Missile Man The Missile Man book

Recent Columns

A trip down (very expensive) memory lane
Last night I took a couple of hours (well three hours actually) out of my normally busy evening to watch some TV...

A million eyes for China
Drones are big and in the world of drone manufacturing, China is the clear global leader...

Where is our $7K ECEV?
If you've got the money, you can pick up a pretty tidy used-car in NZ for under $10K...

Goodbye Kim
Today I am going to pick up where I left off last week, with more on the battle between the world's two most two badly coiffured leaders (or is that "covfefed"?)...

Stupidium and the big bang theory
No, I'm not talking about the TV series or the origin of the universe...

An interesting case study in "duh!"
Recently the NoPetya attack crippled computer systems around the world...

Why old-school is still important
We've got so many fantastic new technologies that have come from the advancement of electronics and computers that sometimes it's hard to imagine living without these bits of hi-techery...

SkyTV in its death throes
I've already written about the lunacy which is the management of SkyTV but today, in the wake of a recent event, I must again focus my beady eyes on the future of this broadcaster...

Four decades later...
I started playing around with computers about 40 years ago -- back in 1977...

It's happening already
There have been a number of predictions that robots will take over almost half the jobs currently performed by people within the next decade or so...

British Government wants back doors
In another move, designed to completely destroy the right to privacy, the British government has effectively said that it wants technology companies who provide end-to-end encryption services, to provide back doors...