Allegedly owned by someone that attended the DEFCON Shoot event where gun powder was transferred to the package, tipping a dog doing a random search in the Forums.
+ the pencil @ $99 and the smart keyboard at $169. > $1k for the entry level model to be comparable with the Surface Pro 3 at ~$930 (which starts at 64GB, btw).
> but DISA can't enforce STIGs across the entire government can they?
No, with a small caveat: If that civilian agency (say DHS) is connected to the GIG[1], then DISA has a say-so and can threaten to disconnect them for failing security audits.
Something to keep in mind is that the STIGs are merely implementation guides to secure a system. Therefore, different agencies have different interpretations. In some cases specific secure implementations break systems and applications (mostly legacy ones), so they avoid securing those particular settings all together.
I don't disagree. Unfortunately, this all falls on DoD-DISA. The NSA works with DISA to write the policy for how to secure systems (called STIGs) and also has 'Red Teams', but they aren't the arm that certifies these systems before coming online, nor are they the ones the ensure the systems stay secured as new vulnerabilities are found and patched -- that's DISA again.
Yes, both can be disabled. However, I'm not sure if it's dependent upon which 'edition' though. For example, you can turn it off in Enterprise, but not Professional.
This is really great, but the real question is will users actually see this on a default Lenovo OS build? Can anyone confirm that Defender doesn't get disabled in favor or say... McAfee or Symantec?
Microsoft informed us that a fix was planned for the January patches but has to be pulled due to compatibility issues. Therefore the fix is now expected in the February patches.
So, they met the deadline and fixed the vulnerability, but due to compatibility issues had to pull it before being released through Windows Update.
Depends on the IE Zone settings. I believe that if you set the a zone to 'Low', a web page can execute a VBSCript code, with or without ActiveX being enabled.
> Specifically, it related to Microsoft Secure Channel, known as Schannel, Microsoft's software for implementing secure transfer of data.
I'm confused... The article says this research relates to the SChannel vulnerability being patched this month and cites IBM Researchers[1] finding it, but the link to the blog post showing the work is towards OLE and not SChannel. Also, Microsoft has mentioned that they found[2] the SChannel vulnerability through an internal audit. To me, it seems the research is talking about CVE-2014-6332[3], which shows the patch as MS14-064. MS14-066 is the patch for the SChannel vulnerability.
Either BBC is confused on which patch they're trying to report on, or I am.
I fail to see how the two are even remotely the same. Google continuously scans email content to sell ads; while Microsoft does it once and admits it so they can catch someone stealing trade secrets.
While I agree that the Scroogled campaign does tread slightly into the hyperbole, I can't agree that this the double-standard that most are making it out to be.