Biometric Device for Secure Access
The plusID device from Privaris (www.privaris.com) is the world’s first personal, mobile fingerprint fob. The device transforms biometric security as we know it today by providing access to multiple facilities, computers and networks with just one secure wireless device, while eliminating the need for employees to use multiple access cards and passwords. The plusID works with existing, installed security infrastructure, making deployment quick and affordable.
The plusID incorporates features not available in other biometric security products:
• plusID protects its user’s personal privacy by retaining all fingerprint information in a secure processor in the device, not in a “centralized” biometric database.
• plusID is the first implementation of the Broadcom BCM5890 secure processor, the world’s most advanced secure processor with contactless technology, specifically designed to secure personal authentication and eliminate security vulnerabilities.
• As a mobile, self-contained authentication device, plusID increases user convenience and privacy while eliminating the need for disparate, expensive, biometric security systems.
The device, which is Bluetooth, proximity RF and USB enabled, includes a fingerprint sensor, buttons for application selection, LED status indicators, an LCD for one-time password display, a USB connector, on-board fingerprint processing, cryptographic services, a rechargeable battery, and credential transmission capability at multiple RF frequencies. The device will begin shipping in August 2006, with full production in October 2006.
No More Support for 98 and ME
As of July 11, more than 70 million Windows users were no longer eligible for software security updates. Microsoft has ended support for Windows 98, Windows 98 Special Edition (SE) and Windows Millennium Edition (ME). Users of these older Windows versions no longer have the ability to obtain security patches from Microsoft. There is a risk that some hackers may now actively search for flaws in these operating systems in order to exploit these exposed PCs.
To be fair, Microsoft had originally planned to stop supporting the older versions of its operating system in January 2004. However, even with the support extension, analyst firm IDC stated that at the end of 2005 about 48 million computers were still running licensed versions of Windows 98 and 25 million were running Windows ME. It is expected that the loss of support will probably push users to abandon the machines running these systems and encourage them to purchase new computers.
Fuzzing Joins Phishing and Pharming
Secure Computing Corporation is warning that artificial intelligence (AI) software used in testing by a small number of software developers is now being widely used by hackers to find formerly undiscovered vulnerabilities.
These AI tools use a methodology referred to as “Fuzzing.” This is an automated methodology for testing applications for bugs by checking allowed input for a given application and trying to force abnormal responses to see if unexpected results (bugs) can be generated. Once a bug is found, further research can determine if the bug can be exploited as a vulnerability and then be packaged as an exploit. Hackers are sharing their Fuzzing results in a collaborative effort in chatrooms and in news groups to rapidly develop new threats. The large increase in application vulnerabilities that have recently been reported are thought to be a direct result of the use of Fuzzing tools.
“Fuzzing will clearly accelerate the ability for hackers to discover new vulnerabilities in software applications,” said Paul Henry, VP, Strategic Accounts for Secure Computing. “Software vendors were already struggling to keep up with patches for software bugs; the use of Fuzzing tools by hackers and the flood of newly discovered vulnerabilities may overwhelm software vendors’ ability to respond with patches.”
Additionally, to aid the hackers in their criminal activity, Secure Computing has discovered that the previously hidden malware search capabilities within Google, which were heralded as a tool reserved only for Anti Virus and Security Research firms have fallen into the hands of hackers. The key to finding malware in Google lies in having the signature for the specific malware program. Hackers are now sharing these signatures openly on the Internet, making it easy to search Google for the signature of a specific piece of malware. Websites now catalog these signatures and allow users to simply enter the malware program name and they return the signature for the malware from their database. Users of these signature catalogs are encouraged to submit new malware so the site owners can quickly generate a signature for the malware for their community of users.
“Why bother creating a new virus, worm or Trojan when you can simply find one and download it using Google,” said Henry. “Unskilled hackers can use this previously unknown capability of Google to download malware and release it on the Internet in targeted attacks as if they wrote it themselves to try to impress their peers with their skills.”

