It's not often that we take a moment to think about what we in security are grateful for. And as we approach the time of year when all the security gurus bring out their crystal balls and prognosticate what the Big Bad of the coming year will be, I would like to take a moment to think about things that have happened in the past year that have been improvements. As I found so much news from this year to be grateful for, this represents my top five security-specific developments:
The end of Windows XP support
It's not a good thing for security when people are using an operating system that is over a decade old. Windows XP was much beloved, and a lot of people had a very hard time letting it go, despite its many security issues. Microsoft ended support for XP this April, prompting people to (slowly but surely) finally get off the antiquated operating system. At the time of writing, the XP market share finally sank below 20 percent; and by web-usage, it now represents just over 11 percent. As the holiday shopping season approaches, I expect that we will continue to see its market share decrease.
Major bugs lead to improvements
Discovering major vulnerabilities is not generally good news. But if it brings to light years-old bugs and prompts people to fix them, it can be an improvement on the whole. We had three doozies this year: Heartbleed, Shellshock and Poodlebleed. The Heartbleed bug was the most recently introduced; it was only three-years-old. Shellshock, on the other hand, included versions of bash from 1989. Poodlebleed was a bug in 15-year-old software that was still in common use. These vulnerabilities existed for quite some time, and we don't know how many times those bugs were used to attack people before this became common knowledge. But because of the massive outreach and coverage surrounding these events, a lot of people stopped using or supporting some seriously antiquated and vulnerable software.
EMV adoption speeds up
Last year's Target breach was very bad news; as many as one-third of Americans were affected. But on the plus side, because this happened in such close proximity to other major breaches as well as a looming milestone for adopting EMV, this seems to have changed the prevailing attitude from dread to enthusiasm. In October, the White House announced the BuySecure initiative that unveiled tools to help consumers protect their payment card data. This included an announcement by Home Depot, Target, Walgreens and Walmart that they would start activating EMV terminals by January 2015, nine months in advance of the deadline. But major vendors are not the only ones at risk for card data theft. So as not to leave smaller vendors behind, in July Square announced that it is working on a version of its popular card reader that will accept EMV cards.
Sign up for Computerworld eNewsletters.