Last week in security

By Steven Musil, CNET News.com
Monday, January 16, 2006 10:51 AM

A new version of Apple Computer's popular iTunes software is prompting complaints from privacy advocates for sending information about computer users' playlists back to Apple.

The new music software includes a "MiniStore" window, which provides recommended links to Apple's music download service when listeners click on songs in their personal playlist, including songs that haven't been purchased from the iTunes store.

To provide those recommendations, the software sends information about the selected song, such as artist, title and genre, back to Apple. But the software also transmits a string of data that is linked to a computer user's unique iTunes account ID, computer experts have found. Because iTunes users typically sign up for the music store with an e-mail address and a credit card number, the account ID number could in theory be linked to that information as well as a customer's purchase history.

Apple also warned about serious security flaws in QuickTime, saying that vulnerabilities in the media player put computers running Windows and Mac OS X at risk of being commandeered by an outsider. An attacker could exploit the flaws by tricking the user into opening a malicious file.

Apple released QuickTime 7.0.4 to address the vulnerabilities. The French Security Incident Response Team, a commercial security monitoring and research outfit, described the problems as "critical," its highest risk rating.

Meanwhile, Symantec released an update to its popular Norton SystemWorks to fix a security problem that could be abused by cybercriminals to hide malicious software. In the PC-tuning application, a feature called the Norton Protected Recycle Bin creates a hidden directory on Windows systems. The feature is meant to help people restore modified or deleted files, but the hidden folder might not be scanned during scheduled or manual virus scans.

Symantec's alert has echoes of Sony BMG Music Entertainment's recent PC security fiasco. The record label was found to be shipping copy-protected compact discs that planted so-called rootkit software on the computers that played them. The rootkit technology also offered a hiding place for malicious software.


WORTHWHILE?

0

0 votes
Blog

Talkback 0 comments

There are currently no comments for this post.


Tech Jobs Now!

Search for your ideal tech job:

Keep IMAP e-mail messages locally using OfflineIMAP

Open Source

Vincent Danen discusses the uses of OfflineIMAP for synchronizing local and remote IMAP mailboxes and providing a good method for backing up e-mail.


Read more »



Lift-and-shift: Resurgence or flame-out

Blog thumbnail

Lift-and-shift has been the backbone of many of the outsource solutions for a number of years.

This allowed many buyers to achieve significant cost savings by taking advantage of..... by Michael Rehkopf

Read more »

Tags

  1. attack
  2. authentication and encryption
  3. blog
  4. data security
  5. e - mail
  6. hacking
  7. internet
  8. malware
  9. microsoft corp.
  10. network
  11. network security
  12. pc security
  13. researcher
  14. security
  15. security management
  16. software
  17. spam and phishing
  18. symantec corp.
  19. viruses and worms
  20. web