Commentary

George Hulme
 

Security Is No Longer About The Operating System

Now that Adobe has updated its graphics and video software, a near ubiquitous security vulnerability has been fixed.

Now that Adobe has updated its graphics and video software, a near ubiquitous security vulnerability has been fixed.Just yesterday, Adobe released the most recent version of its Flash player, 9.0.124.0. And with it, vulnerabilities that could enable remote attackers to infiltrate systems running this software (and who doesn't?) have been remediated.

You can grab your copy of the update, and more information on the security flaws, right here. You'll be safe until the next round of flaws are uncovered, if they haven't been already.


More Security Insights

White Papers

More >>

Reports

More >>

Webcasts

More >>

Security news watchers will recognize one of the Adobe flaws as the flaw that enabled Shane Macaulay to win a laptop after gaining control of a Vista system during a hacking contest, PWN 2 OWN, at the CanSecWest conference in Vancouver.

I wasn't at this conference, but one of the interesting things I noted was that none of the systems "PWN'D" in the contest were done so through vulnerabilities in any of the core operating systems. That's right, during the first day of the contest, hacks were limited to attacks over the network directed at the operating systems. No one was successful.

So Vista was taken down through an Adobe flaw, and a small team of researchers went home with a MacBook Air and an extra $10,000 after exploiting a flaw in Safari 3.1.

This means the Microsoft vs. Apple "Which is more secure debate" is over. No one is attacking core operating system functionality anymore. Why? Because the operating systems have been sufficiently vetted and hardened. While we will still see vulnerabilities and attacks aimed at OSes, for certain, these won't be what marketers like to call "the sweet spot."

This means the browser you choose to use may have a profound impact on how secure you are while surfing the Internet. It's about Firefox vs. Explorer. QuickTime vs MediaPlayer. It's about not using anything but a fully hardened instant messaging client.


Related Reading




Currently we allow the following HTML tags in comments:

Single tags

These tags can be used alone and don't need an ending tag.

<br> Defines a single line break

<hr> Defines a horizontal line

Matching tags

These require an ending tag - e.g. <i>italic text</i>

<a> Defines an anchor

<b> Defines bold text

<big> Defines big text

<blockquote> Defines a long quotation

<caption> Defines a table caption

<cite> Defines a citation

<code> Defines computer code text

<em> Defines emphasized text

<fieldset> Defines a border around elements in a form

<h1> This is heading 1

<h2> This is heading 2

<h3> This is heading 3

<h4> This is heading 4

<h5> This is heading 5

<h6> This is heading 6

<i> Defines italic text

<p> Defines a paragraph

<pre> Defines preformatted text

<q> Defines a short quotation

<samp> Defines sample computer code text

<small> Defines small text

<span> Defines a section in a document

<s> Defines strikethrough text

<strike> Defines strikethrough text

<strong> Defines strong text

<sub> Defines subscripted text

<sup> Defines superscripted text

<u> Defines underlined text

InformationWeek encourages readers to engage in spirited, healthy debate, including taking us to task. However, InformationWeek moderates all comments posted to our site, and reserves the right to modify or remove any content that it determines to be derogatory, offensive, inflammatory, vulgar, irrelevant/off-topic, racist or obvious marketing/SPAM. InformationWeek further reserves the right to disable the profile of any commenter participating in said activities.

Disqus Tips To upload an avatar photo, first complete your Disqus profile. | View the list of supported HTML tags you can use to style comments. | Please read our commenting policy.
T-Shirt Giveaway T-Shirt Giveaway: Each week we're selecting one great comment from our readers. The author of the comment will receive an InformaitonWeek Community t-shirt. So get posting!
Subscribe to RSS

Resource Links