Skip to navigation
   
Davey Winder's Blog

Olympic flash of gold for Microsoft

By Davey Winder in Editorial

Posted in Adobe, Internet, Microsoft on August 18, 2008 at 3:01 pm

Permalink | Author Profile

Silverlight has, to be fair, not exactly set the world on fire. Microsoft was obviously hoping it would, and there’s nothing majorly wrong with the Silverlight 2 Beta to prevent it. Other than the market share enjoyed by Adobe Flash of course.

Ay, there’s the rub. And while quoting from Hamlet, I might as well drag out some of the words that follow that, as they seem to apply so well to Microsoft with regards to Silverlight: what dreams may come?

As it turns out, those dreams were in Chinese.

Could it really be that the Beijing Olympics are the Saviour of Silverlight? Well I’m pretty damn sure the Games of the XXIX Olympiad are not going to do it any harm in the getting the word out stakes.

Or more precisely the ‘getting Silverlight installed’ stakes. Whoever managed to pull off the deal with NBC to drive the online video coverage of the Olympics deserves a medal, a big shiny gold one at that. Not that I suspect it took too much negotiating considering how the two have worked so well before. MSNBC ring any bells?

The Silverlight ability to adaptively stream the video data depending upon the available bandwidth, together with certain copy protection promises, seemed to do the trick.

So just how much of a success has the NBC Olympics coverage been for Silverlight? Ah, Microsoft isn’t actually saying. It would appear to be sticking to its standard ‘up to 1.5 million downloads a day’ line that has been spun out since, well, almost forever. At least it seems that way from here.

However, some reports suggest that the real figures are a whole heap of beans higher.

How does 25 million unique visitors for NBCOlympics.com via MSN during the Games so far grab you? Or how about the fact that more than half the visitors in recent days have already got Silverlight installed?

With 22 million videos streamed so far, that’s a pretty impressive showcase for what was looking like a near-miss technology just a few weeks ago…

12345
Rated: 100% (1 votes)
Loading ... Loading ...

 

Chaos Computer Club explodes Adobe PDF security bomb

By Davey Winder in Editorial

Posted in Adobe on January 5, 2007 at 1:32 am

Permalink | Author Profile

Adobe Reader has been pretty much single handedly responsible for ensuring PDF has become the de facto portable document publishing format on the web. It could also single handedly allow a universal cross scripting (XSS) exploit to compromise your website and your business. How serious is this particular vulnerability? Well, how serious does the fact that any site hosting a .pdf file could be at risk from attack.

As Stefano Di Paola and Giorgio Fedon revealed at the Chaos Computer Club in Berlin, the open parameters feature of the Adobe Reader browser plug-in allows for the arbitrary execution of JavaScript code on the client side, and that code could easily come with malicious intent. Indeed, Symantec has gone as far as stating in its security response blog that the “ease in which this weakness can be exploited is breathtaking” and they are not wrong. In the past such XSS attacks have had to rely upon a server-side flaw, but this is client-side and a hugely popular client-side application at that. It changes the rules of engagement, and changes the threat landscape.

Other than upgrading to Adobe Reader 8 while waiting for Adobe to hit the patch distribution trail, it would seem the only other mitigating solution might be to force such files to open in the full Acrobat client and not the Reader browser plug-in by removing the Adobe Reader filetype associations for your browser. Assuming, that is, your browser is Firefox or a version of IE before 7 as only these clients are thought to be at risk. I’d recommend disabling the Reader plug-in and making sure JavaScript filtering at the IDS or firewall is implemented on your network.

12345
Not yet rated
Loading ... Loading ...

 

   
Tag cloud

e-commerce payment server web Health remote debian policy banking Funny The Federation Research ecommerce black hat surveys christmas BSI web 2.0 network Jesus Phone Top 500 China Google banks social networking Yahoo privacy HPC Hack virtual world transactional security Internet second life Bill Gates fraud gaming environment linkedin Paris Hilton Adobe students documentation stupid Steve Jobs universe AMD ASUS Government workplace millions Rant Business Trojan security Windows code chips Flash hacking patch management outsourcing Texas Instruments broadband trust data protection politics hubdub shopping theft NBC ID Theft scan standards technology Lotus virus Twitter crime computer economics OCR Noro Facebook copyright survey MSNBC archiving help NASA Zango iPhone office USA rootkits museum iPhone 3G world of warcraft migration remote working Gartner Supercomputer Finjan Space Microsoft betting botnet data Ballmer digitise Windows 7 Kill Switch science CAPTCHA stupidity payments exploit Deal staffing library books computing phishing MessageLabs Texting size mobile Software Eee PC terrorism FBI Eee IDC fool news man-in-the-middle prison Firefox XP development open source Energy virtual machine Olympics hypervisor worker SMS VPN IP Blogging report green productivity Battery service Performance computing printing global adware hacker compromise OS ISPA teleworking Web Development Mars work email sick search holidays tech carbon copy Big Brother dumb scam Rumour Linux graphics MiniBook IBM MSN BOFH storage Application Digg InfoSec credit card fraud spam fun Obama Apple Silverlight Programming Video xmas scareware SSL statistics Microchip biometrics avatar hardware Vista home DNS money worm VM Russia Mobile Phone Death Project symantec malware
Advertisement
Advertisement
Advertisement