Mar 16 2010
We’ve been hearing about the Aurora attacks on Google and a host of other companies since early January. So why is it that NSS Labs is finding that the majority of the End Point Protection (aka AV) companies aren’t protecting against the vulnerability yet? And why is AVG upset with NSS Labs and their testing methods? To answer these questions and many more, Rich and Martin were joined tonight by Vikram Phatak, the CTO of NSS Labs. Vik gave us some of the back story on why they were testing AV products and some of the surprising discoveries they made. It’s not easy being an independent testing company and sometimes you’re going to annoy people despite your best efforts. And sometimes people are going to be annoyed with you no matter what.
One point Vik wanted to make that didn’t make it into the podcast is that the 0day that was used in the Aurora attack is not just being used against corporate targets. It’s being used against consumers as well, so it’s important that the average home user be aware that their AV product may not be protecting them at this point. What is part of the podcast is a discussion of how many AV vendors are trying to protect against the payload that malware is attempting to deliver, not the exploit itself. Both are important points people need to be aware of.
- Vulnerability-based protection and the Google “Operation Aurora” attack
- NSS Labs’ Questionable Report – Note that the screen shot shown is of the Firefox browser, not IE in any form
- AVG & The Aurora Exploit
- Questionable Questions (and some answers)
- 7th Annual ISSA Security Conference
- Please take our short listener survey to help us create a better podcast!