Tuesday, March 14, 2006

More urgent than Microsoft's patches today 

Today's a relatively quiet Patch Tuesday from Microsoft, with the most dangerous problem being one that could let someone take over your computer by giving you a booby-trappped Excel spreadsheet.

But there's a really dangerous non-Microsoft problem you should fix ASAP.

You know those annoying spinning and flashing ads on some web pages? They're an abuse of a (potentially) useful and legitimate technology called Flash. There's a display program on your computer that starts an animation on your screen directed by a file on the website you're viewing.

Flash files are complicated and so is the display program. Sometimes there are security bugs. Sometimes these bugs are so severe they allow for taking over your computer. This is really bad because you're downloading Flash files all day long from strangers and even from (gasp) advertisers. Your chances of hitting a booby-trapped file from someone malicious are worryingly high.

This is dangerous no matter what web browser you use.

Fortunately the patch is alread out. Secunia has the list of download locations for fixed Flash player programs.

All well and good but what about the next bug? This wasn't the first.

I personally use a Firefox extension called FlashBlock. It stops the animations from getting played and replaces them with a button you can click if you actually want to play one. Don't laugh, in the last several years I've seen two or three valuable and helpful applications of Flash technology. The other 99.99% of the time you're protected from toxic Flash files because they don't even get loaded.

|

This page is powered by Blogger. Isn't yours?