Second Life and Qucktime security.
Thanks to Vint I have now read an uninformed rant over at the register. “Second Life from a security perspective is horribly broken," Greg Hogland sais to The register, and continues "When you look at Second Life, you know in your bones they simply did not think about security when they developed this application. It's broken from the inside." Yes in many ways he is correct, but the quicktime hole is not the a good example of this. A quicktime, or os problem is nothing Second life can protect it self from. The new fixes from Linden is quite useless if you like to hack a Second life users account using quick time. Make the attack vector a little different, but doesn't and cant protect the user. Sort of eliminating the end users computer is all transactions, which isn't practical. Linden labs can't do anything. With eliminating the computer a good second hard ware like a good online banking have. Where you enter what you like to have done and get a security token from that. Yes you need to enter least the value and to how to pay for the protection to be good, so for each linden or item you transfer you enter it's value/uuid/name into a box togeather with the name of the person to get is and get a security token so the transfer can proceed. All this have to happened on some other secured hardware than the computer. It's will make the system unusable, so you have to risk some lindens.
I personally think Linden have done more that needed to secure it's customers computers. Yes it's trivial to install a root kit on a machine that takes internet data and have a local exploit. The next problem can be in the operating system, in the gfx driver for once. Anything that during a second life sessions receives and processes data from the net is a potential problem for us users. Also many of us uses services as slx or onrez, this includes the normal web-browser, if you have offline IM's the email program is also a possible program. However to put the blame on linden labs for problems with these as quick time. Is putting the blame where it doesn't belong.
If someone can get your computer compromised anyway the current design, for any online game (and many internet shops, banks, etc) can't protect you. Make sure that all programs you use on your computer is updated, when a know hole is spotted (at least). This is much work and needs much attention especially in windows and mac os as none of these have a central code collections to install and update against.
Popularity: 3% [?]
Additional comments powered by BackType
Senaste inläggen
Flattr
Balp Skiver Om allt och alla...
Blandat
Blogroll
Politik
- (title unknown)
- Aningen udd
- Anna Troberg
- Att arbeta som eskort
- Basic personligt
- Blogge Bloggelito – regeringsblogg
- Copyriot
- deep|edition
- Enligt Min Humla » Made my day
- Erik Josefsson
- Farmorgun i Norrtälje
- Frihet, Fildelning och Feminism
- futuriteter
- gretagarbo
- Isabella Lund
- Isobels text och verkstad
- Jan Lindgren
- Johanna Sjödin
- Karl Sigfrid
- Kryssa Mattias
- louisep.com | frihetspropaganda
- Mark Klamberg
- opassande
- Oscar Swartz :: Texplorer
- Oväsentligheter mm…..Μη σημαντικός
- Piratpartiet Västra Distriktet
- Rick Falkvinge (PP)
- Spectrial
- Stenskott
- syrrans granne
- Thomas Tvivlaren
- xor
Second Life
Teknik
- Adrian Cockcroft's Blog
- Basic tech stuff
- Engadget
- IDG.se – 100 senaste
- paf's blog
- Planet Debian
- Slashdot
- Tommy k Johanssons blogg om datorer & Internet
- Wired Top Stories
Etiketter
Senaste kommentarer
- lastactionseo | lastactionseo - der letzte SEO om Vilken karttjänst är den bästa?
- Tweets that mention Keep on Balping » AFK Lagar skall gälla -- Topsy.com om AFK Lagar skall gälla
- Digitalmannen om AFK Lagar skall gälla
- Jan-Olof Flink om AFK Lagar skall gälla
- Keep on Balping » AFK Lagar skall gälla om Att göra en Streisand.
Arkiv
- mars 2011
- januari 2011
- december 2010
- november 2010
- oktober 2010
- juni 2010
- maj 2010
- april 2010
- mars 2010
- februari 2010
- januari 2010
- december 2009
- oktober 2009
- september 2009
- augusti 2009
- juli 2009
- juni 2009
- maj 2009
- april 2009
- november 2008
- oktober 2008
- september 2008
- augusti 2008
- juli 2008
- juni 2008
- april 2008
- mars 2008
- februari 2008
- januari 2008
- december 2007
- november 2007
- oktober 2007
- september 2007
- augusti 2007
- juli 2007