The security software, available in a public beta version, by default allows applications that use the Java Virtual Machine or have a digital signature to connect to the Internet.------------------------------------------------------------------------------------------
Like any blanket security-bypass rule, these default settings are a bad idea, said Mark Curphey, vice president at vulnerability management specialist Foundstone, a part of McAfee.
"Any firewall, any security device should have a default deny," Curphey said in an interview Tuesday. "Any door should always be closed."
Curphey discovered the issue when running software on his wife's computer, on which he had installed OneCare. He informed Foundstone security consultant Roger Grimes, who subsequently blogged about it on the InfoWorld Web site. Grimes also blasted the default bypass settings.
"It just invites malicious hackers and other malware goons to exploit it," Grimes wrote.
Software giant Microsoft has it in its paws to fix a potential virus nightmare for its customers, but is sitting on the patch.Microsoft is slower, and never trust them. Talk about Microsoft's determination to provide better security?
Tomorrow the Kama Sutra worm will overwrite Office documents on infected PCs, as viruses do. It will do this again next month.
Many computer users do not know what is firewall, antivirus etc. Microsoft will probably be bundling it with Windows Vista, and it will help many people. (Like, so many people still using IE because it comes bundled; computer illiterate people usually ignore other software)Originally posted by chanff8:Was reading about the OneCare news a while ago. Never trust Microsoft. MS is better doing what it does best, developing Windows, instead of wandering into the internet security arena! They'll only make things worse...
Don't know the virus clever enough to notice or not....Originally posted by FireIce:we change the date to 4 feb today loh
Mac?Originally posted by the Bear:asshats Microsoft have the patch but will not release it until the virus has caused enough havoc
read about it here => Kama Sutra worm to delete computer files February 3, but Microsoft refuses to release patch before February 14
i think i'll get an Apple iMac next
You got the virus?Originally posted by bo liao:hmm..so far so good lea...
Or its bcos i never go see my doc for work?Mayb already all disappeared?![]()
wtf Microsoft is pissing me off...Originally posted by the Bear:asshats Microsoft have the patch but will not release it until the virus has caused enough havoc
read about it here => Kama Sutra worm to delete computer files February 3, but Microsoft refuses to release patch before February 14
i think i'll get an Apple iMac next