Criminals Pay High Price To Keep Security Vulnerabilities Hidden
The annual "X-Force" report, recently released by Internet Security Systems (ISS), part of IBM Corp., says 6,437 security flaws were acknowledged in 2007 by network and software vendors, down 5.4 percent from 2006. (Source: com.au)
While computer security vulnerabilities decreased last year, security researchers are cautioning that there has been no improvement in web safety.
ISS Chief Technology officer Chris Rouland said that in at least 10 years of counting he had not seen that figure drop. Rouland suggests that the 2007 number of vulnerabilities reported would have been higher if a black market willing to pay up to $100,000 (68,766 euros) to computer experts who find such threats and sell the information to criminal gangs eager to exploit them hadn't emerged.
Richard Jacobs, Chief Technology officer of Sophos PLC, questioned how much difference undisclosed vulnerabilities make for companies, governments and everyday computer users since corporate technology staffs often take months or years to patch even widely publicized holes.
Toby Weiss, CEO of Application Security Inc., said the drop in total vulnerabilities was less important than ISS's findings that critical security holes that let an outside attacker do the most damage on a computer network increased by 28 percent in 2007. Weiss noted that counting the total number of vulnerabilities is old-school thinking.
Some security researchers are afraid that software vendors are buying information on the vulnerabilities themselves so they can fix them without anyone noticing. "It is profitable not to publicly report a vulnerability" says Rouland. Consequently, there is no way to tell how many security vulnerabilities go undocumented.
Visit Bill's Links and More for more great tips, just like this one!
Most popular articles
- Which Processor is Better: Intel or AMD? - Explained
- How to Prevent Ransomware in 2018 - 10 Steps
- 5 Best Anti Ransomware Software Free
- How to Fix: Computer / Network Infected with Ransomware (10 Steps)
- How to Fix: Your Computer is Infected, Call This Number (Scam)
- Scammed by Informatico Experts? Here's What to Do
- Scammed by Smart PC Experts? Here's What to Do
- Scammed by Right PC Experts? Here's What to Do
- Scammed by PC / Web Network Experts? Here's What to Do
- How to Fix: Windows Update Won't Update
- Explained: Do I need a VPN? Are VPNs Safe for Online Banking?
- Explained: VPN vs Proxy; What's the Difference?
- Explained: Difference Between VPN Server and VPN (Service)
- Forgot Password? How to: Reset Any Password: Windows Vista, 7, 8, 10
- How to: Use a Firewall to Block Full Screen Ads on Android
- Explained: Absolute Best way to Limit Data on Android
- Explained: Difference Between Dark Web, Deep Net, Darknet and More
- Explained: If I Reset Windows 10 will it Remove Malware?
My name is Dennis Faas and I am a senior systems administrator and IT technical analyst specializing in cyber crimes (sextortion / blackmail / tech support scams) with over 30 years experience; I also run this website! If you need technical assistance , I can help. Click here to email me now; optionally, you can review my resume here. You can also read how I can fix your computer over the Internet (also includes user reviews).
We are BBB Accredited
We are BBB accredited (A+ rating), celebrating 21 years of excellence! Click to view our rating on the BBB.