application security

Doctorow: Fearing an Internet of Things That Do As They’re Told

In-brief: In an essay for O’Reilly Radar, Cory Doctorow argues that remote management features that allow carriers to disable mobile phones are a mistake – taking technology owners’ autonomy and control over their data away in the name of preventing muggings and other crimes. 

Update: Superfish is the Real End of SSL

In-brief: Outrage over Lenovo’s promotion of privacy busting adware continued to grow amid lawsuits and more spying revelations. The big question: is this the final – final straw for the beleaguered Secure Sockets Layer (SSL) technology?  (Updated to add comment from Kevin Bocek of Venafi.)

Who gets to talk to your Fridge? | O’Reilly Radar

In-brief: an article on O’Reilly’s Radar site raises important questions about what kinds of connections and data sharing should be allowed on the Internet of Things – and how consumer privacy can be protected.

Ghost Vulnerability Replays Third Party Code Woes

In-brief: The security firm Qualys is warning of a serious and remotely exploitable vulnerability in a function of the GNU C Library (glibc) known as gethostbyname. The security hole raises more questions about dangers lurking in legacy, open source software. 

FTC Report on Internet of Things Urges Security and Privacy Protections

In-brief: The FTC issued a report on Tuesday that provides guidance to U.S. businesses on protecting consumers’ privacy and security in the design and deployment of “Internet of Things” devices.