A new version of Google's JavaScript rendering engine and security fixes land in Google Chrome 14.0.794.0 dev today, available for download for Windows, Mac, Linux. The latest rough version of the browser improves secure HTTP support in several ways, updates the V8 JavaScript engine to version 3.4.3.0, and tightens security when installing Web apps from the Chrome Web Store. . The security changes are small but nevertheless could have a positive effect on your browser's security. Chrome 14 dev supports DNSSEC authentication for HTTPS, which strengthens the secure Web protocol, and Chrome 14 dev for Macs fixes invalid server certificate errors that were being generated for some secure sites that had untrusted roots certificate authorities. The Chrome Web Store now prompts with a native confirmation dialog box when installing a Web app, which streamlines how the Web store appears to integrate with your computer. SSL v3 server connectivity issues have been fixed, which will prevent some connections from being lost. Google is taking HTTPS issues quite seriously and has taken steps to address mixed secure site scripting conditions in Chrome 14 dev. Just after announcing that Gmail will always load in HTTPS, the company has ensured that mixed secure site scripting conditions are blocked by default in Chrome 14 dev. The first is a command line flag that actually landed in Chrome 13 dev called --no-running-insecure-content for advanced users who want to help clean up sites with mixed secure scripts. Another flag is available that will block the display of insecure content, --no-displaying-insecure-content, but Google stated in the above-linked blog post that it will not block displaying insecure content by default since it's not as dangerous a use-case. The link for this article located at CNET is no longer available. . Firefox 92 brings substantial privacy upgrades such as enhanced tracking protection and streamlined password management features.. Chrome 14,Browser Security,HTTPS Improvements,Web App Safety. .LinuxSecurity.com Team
A round-up of articles leading up to and live coverage from Black Hat USA 2010, July 24 to 29, Las Vegas . > > Security Pros Feel Underpaid, But In Some Cases Would Take A Pay Cut New survey shows value IT security professionals place on job security, training, quality of life; authors to discuss career issues at Black Hat > > Researcher Says Home Routers Are Vulnerable Black Hat presentation will demonstrate hacks that could work on many existing routers > > Researcher 'Fingerprints' The Bad Guys Behind The Malware Black Hat USA researcher will demonstrate how to find clues to help ID actual attackers, plans to release free fingerprinting tool > > 'Robin Sage' Profile Duped Military Intelligence, IT Security Pros Social networking experiment of phony female military intelligence profile fooled even the most security-savvy on LinkedIn, Facebook, Twitter -- and also led to the leakage of sensitive military information > > 'BlindElephant' To ID Outdated Or Unknown Web Apps, Plug-Ins New freebie tool fingerprints out-of-date apps > > SAP, Other ERP Applications At Risk Of Targeted Attacks Black Hat Europe researcher demonstrates techniques for inserting 'backdoors' into popular enterprise resource planning apps that aren't properly secured > > New Hack Pinpoints Cell Phone User's Location, Personal And Business Relationships Researchers demonstrate a technique that exploits the cell phone infrastructure to compromise cell user's privacy The link for this article located at Dark Reading is no longer available. . > > Security Pros Feel Underpaid, But In Some Cases Would Take A Pay Cut New survey shows value IT se. round-up, articles, leading, coverage, black. . Alex
The best way to determine if your IT infrastructure is secure is to have a hacker try to break into your corporate systems.. . .. The best way to determine if your IT infrastructure is secure is to have a hacker try to break into your corporate systems. Short of that, software that simulates attacks is the next best thing. Wednesday, Sanctum rolled out an automated audit tool that analyzes Web applications, points to security glitches, and provides advice on how to fix any vulnerability. The link for this article located at TechWeb is no longer available. . Assess your digital framework's defenses by executing simulated cyber intrusions using automated software that uncovers weaknesses.. Automated Security Tools, Penetration Testing, Web Application Assessment. . Anthony Pell
Get the latest Linux and open source security news straight to your inbox.