The main thing is not to install Flash!
Written by Mat on Tuesday, March 2, 2010 9:19 - 0 Comments
[via DownloadSquad by Jay Hathaway]
With the Pwn2Own hacking contest coming up at Vancouver’s CanSecWest security conference later this month, Italian computer security blog OneITSecurity took some time to interview Charlie Miller. Miller, in case you’re not familiar, is a security expert who has won Pwn2Own two years running by hacking Apple’s Safari browser with incredible speed. Safari isn’t the only target — this year, all major browsers and a selection of mobile operating systems will serve as Pwn2Own challenges – but it’s fair to say that Miller knows a thing or two about keeping your browser secure.
Here are the highlights from Miller’s interview:
He thinks Windows 7 will prove more secure than OS X Snow Leopard this year, in part because it doesn’t have Java and Flash enabled by default. Windows’ full ASLR (address space layout randomization) also gives it a security advantage.
When asked what he thought would make the safest OS and browser combo, he opted for Chrome or IE8 on Windows 7, with no Flash installed, although “there probably isn’t enough difference between the browsers to get worked up about.”
For my money, the juiciest quote from the interview was “The main thing is not to install Flash!”
On the mobile side, Miller guessed that the iPhone 3GS would be more easily exploitable than the Motorola Droid, mainly because the iPhone’s been around longer, and has been subjected to more extensive security research.
You can check out Miller’s full answers (in English or Italian!) at OneITSecurity.
SocialStuff
Quick Lists
- Art Institute of Las Vegas
- IMD123: Program Logic »
- IMD213: Intermediate Scripting (SP09) »
- IMD223: Advanced Scripting (SU08) »
- IMD322: Dynamic Design (WI09) »
- IMD325: User Centered Design (WI09) »
- IMD335: Usability Testing (SP09) »
- IMD335: Usability Testing (SP08) »
- IMD345: UCD Integration (SU08) »
- IMD375: Databases (FA09) »
- IMD402: Server-Side Technology (WI09) »
- Independent Studies (SU08) »
- University of Nevada, Las Vegas
- INF400: Web Security »
- INF340: Web Design Concepts »
- IMD213: Intermediate Scripting
- IMD322: Dynamic Design
- IMD335: Usability Testing
- Save UNLV Informatics
- Why Can't Programmers Program?
- Designer, Developer or Deity?
- Top Ten Mistakes in Web Design
Yummy Delicious
Meanwhile on Flickr ... [Design//Diseño Pool]
Reading Recommendations
- Art & Science of CSS by Jonathan Snook, Steve Smith, Jina Bolton, Cameron Adams & David Johnson
- Everything You Know About CSS is Wrong! by Rachel Andrew and Kevin Yank
- The Long Tail (updated version) by Jason Baeird
- Beautiful Web Design by Chris Anderson
- The Future of the Internet and How to Stop It
by Jonathan Zittrain - The Namesake by Jhumpa Lahiri
- The Overcoat and Other Short Stories
by Nikolai Gogol - We The Living by Ayn Rand
- Everything is Miscellaneous by David Weinberger
- Danny The Champion of the World by Roald Dahl
- Successful Freelancing by Miles Burke
- PHP for the World Wide Web by Larry Ullman
- Advanced PHP for the World Wide Web
by Larry Ullman



















Leave a Reply