ifacethoughts

Vista Voice Exploit - Flaw Or Not?

Unless you are hiding in your basement fearing the Vista twister, you would have heard/read/seen about the Vista Speech Recognition remote execution flaw. There are various takes on it, some escalating it, some playing it down. The Mac enthusiasts are having a field day. However, what really nails it down is Mark’s sarcastic, but important input.

Microsoft finally adds speech recognition to Windows, but they skip the part about preventing the output from the speakers from being treated as input to the microphone (you know, like phones have done for 100 years).

I think even if the exploit scenario might seem fabricated, this fundamental flaw can help in allowing an attack targeted at an organization. One cannot rely on the assumption that the scenario is difficult, especially with quality of the peripherals increasing everyday. I think it is a flaw, and a critical one. Good thing is that Microsoft has acknowledged it and hopefully they will eliminate it soon. For some this can be a reason to not install Vista. I am still looking for one to install it.

Say your thought!

Who are you?

If you want to use HTML you can use these tags: <a>, <em>, <strong>, <abbr>, <code>, <blockquote>. Closing the tags will be appreciated as this site uses valid XHTML.

freshthoughts

freshcomments

contactme

Abhijit Nadgouda
iface Consulting
India
+91 9819820312
Y!: anadgouda
GTalk: anadgouda@gmail.com
MSN: anadgouda@hotmail.com
Skype: anadgouda
My bookmarks

currentproject

Complete Wellbeing

badgesand...

This is the weblog of Abhijit Nadgouda where he writes down his thoughts on software development and related topics. You are invited to subscribe to the feed to stay updated or check out more subscription options. Or you can choose to browse by one of the topics.

Twitter - Using Envy Code R and liking it. Thank you Damien. http://tinyurl.com/688mft