Microsoft heeft gisteren informatie vrijgegeven over een ernstige fout in Windows, welke aanvallers in staat stelt SSL-certificaten te beschadigen of verwijderen. Hierdoor kunnen Administrator-accounts, beveiligde verbindingen en gecodeerde bestanden onbruikbaar worden gemaakt. De certificaten kunnen niet worden aangepast, de aanvaller kan dus geen ongewenste toegang verkrijgen via deze exploit. Het lek kan misbruikt worden via een ActiveX component op een website; een simpel bezoek aan een kwaadwillende site is voldoende. Een HTML-format e-mail met het component aan boord heeft hetzelfde effect. Microsoft raadt alle gebruikers van de betrokken Windows-versies (98, Me, NT, 2000 en XP) aan onmiddelijk de patch te downloaden:
All versions of Windows ship with an ActiveX control known as the Certificate Enrollment Control, the purpose of which is to allow web-based certificate enrollments. The control is used to submit PKCS #10 compliant certificate requests, and upon receiving the requested certificate, stores it in the user’s local certificate store.
The control contains a flaw that could enable a web page, through an extremely complex process, to invoke the control in a way that would delete certificates on a user’s system. An attacker who successfully exploited the vulnerability could corrupt trusted root certificates, EFS encryption certificates, email signing certificates, and any other certificates on the system, thereby preventing the user from using these features.
Verwijderd nam de tijd om ons een linkje te sturen
All versions of Windows ship with an ActiveX control known as the Certificate Enrollment Control, the purpose of which is to allow web-based certificate enrollments. The control is used to submit PKCS #10 compliant certificate requests, and upon receiving the requested certificate, stores it in the user’s local certificate store.
It is currently being tested in some versions of its service and launched a version of its discount Internet service CompuServe with Netscape technology. "We've been testing the browser and it's been gaining great momentum," he said. "We feel we have the wind in our sales. Netscape is alive as well."
The IT specialists who are in charge of security at an organization are typically not the same people who handle networking, so having both types of functions on the same device could lead to some infighting, he warned. "Security folks in particular tend to be control freaks," Passmore said. "The idea that they're going to give up control of the firewall and let the networking guys stick it within the networking switch may not go down well with them." But integrating network and security hardware into one box has its benefits, Russell said. It would let customers put security services to work throughout their networks--for instance, a customer could set up a dynamic, multipoint VPN (virtual private network) service, instead of the typical point-to-point VPN connection, Russell said.


"You know, on our current work at Id right now we're still pushing really hard to make Doom run well on various high end desk top cards. So it's pretty startling to be able to fire it up on a laptop and see it run at a really pretty startling good pace."
Males make up 72 percent (6.5 million) of wireless Internet users, compared with overall Internet usage, where 48 percent are men and 52 percent are women, according to comScore's studies of adult Internet use. The survey also found that 53 percent of online wireless users are between the ages of 18 and 34, while 42 percent are between 35 and 54. Just 4 percent of people over age 55 have joined the trend. The figures again contrast with general Internet usage via computer, television and other outlets, where 40 percent of Internet users are between 18 and 34, 46 percent are between 35 and 54 and 14 percent are 55 and older, comScore said.
Legislation, rather than an arms race with spammers, is needed to curb spam, Linford said.
Accompanied by the old CPUs, D815EFV, D815EEA2 and D815EPEA2 mainboards for Socket 370 processors based on i815 will be discontinued. Apparently, Socket 423 D850MD and D850MV powered by i850 will also be cancelled. As for the novelties, Intel will unveil its D845GVAD2 mainboard that seems to be the first to make use of i845GV core-logic. I will remind you that the mentioned chipset is the successor of i845GL, featuring 400/533MHz Quad-pumped bus and up to 2GB of PC2700 memory support. The board itself will have no AGP slot, 4 PCI slots, integrated Ethernet adapter and USB 2.0 controller.
According to IDC’s report, the market research firm estimated a 21.6% compound annual growth rate (CAGR) for mobile PCs during the 2001-2006 period, 16.5% higher than that of desktop PCs. The firm attributed the high growth rate of mobile PCs to increasing m-commerce demand from enterprises, some m-commerce demand from individuals and the demand from individuals for a second computer.

Overall, we were very impressed with the Hercules 3D Prophet 9000. It not only provides performance that is far superior to that of both the GeForce 4 MX440 and SiS Xabre 400 chipsets, but also features full DirectX 8.1 support, meaning that it should have no problem running upcoming games such as Doom 3. Furthermore, at a price of around $US130, the card should be well within reach for most users. The bottom line is, if you are on a budget and looking at purchasing a high performance, feature-rich graphics chipset, you will not be disappointed with the Hercules 3D Prophet 9000.
De Clie bevat een USB aansluiting, een infrarood poort en een memory stick slot. Synchronisatie met de pc gebeurt via HotSync software. Vermits er geen build-in speaker is, dient men een speciale audio-adapter te kopen voor zo'n slordige 12.850,- yen (€ 110,-). Verder staat er nog een hele hoop applicaties op zoals drie spelletjes, een tekenprogramma, een e-book reader, een gepreïnstalleerd e-book, Clie Paint en PictureGear Pocket v2.1. Tenslotte zijn er nog een aantal accessoires beschikbaar zoals een USB-cradle, een AC-DC adaptor en een draagtasje. De Clie PEG-SJ30 zal vanaf 14 september in de Japanse winkels liggen":
In het licht van de recente zaken met betrekking tot ongeoorloofd gebruik van GPL-code is het opvallend dat deze General Public License nog nauwelijks juridisch getest is. De meeste overtredingen worden tussen de developers afgehandeld, eventueel middels een bericht op de website van het Open Source-product. Het bekendste conflict dat voor de rechtbank kwam is de ruzie tussen twee ontwikkelaars van MySQL. Het belangrijkste onduidelijke punt in de licentie zit in de vraag in hoeverre het gebruik van GPL-software mag gaan. Volgens de licentie moeten programma's die aan GPL-software linken ook onder de GPL verkrijgbaar zijn, maar door de vele mogelijke manieren van linken is er een grijs gebied waarin mensen verschillende meningen hebben over de toelaatbaarheid van het linken. Overigens speelt dit geen rol in de zaak van CD Ripper, dat zelf het volgende in de licentievoorwaarden heeft staan:
With this single interface across several systems, companies can more easily move data around their systems or allocate storage capacity to individual departments or even single applications, such as Microsoft's Exchange e-mail system. The Sentinel also complies with industry standards designed by the Storage Networking Industry Association, a group of storage companies such as EMC, IBM and Hitachi that is working to make storage software interoperable across different systems.