Security researchers at North Carolina State University led by Xuxian Jiang (who had previously discovered
12 malicious Android applications sold through Google's Android Market) have
uncovered holes in how the permissions-based security model is enforced on numerous Android devices. Called "leaks", these vulnerabilities allow new and existing malicious applications to eavesdrop on calls, track the user's location, install applications, send SMS messages, delete data from the device, and more. (
via)
posted by Blazecock Pileon
on Dec 5, 2011 -
30 comments
The
Haystack application aims to use
steganography to hide
samizdat-type data within a larger stream of innocuous network traffic. Thus, civilians in Iran, for example, could more easily evade Iranian censors and provide the world with an
unfiltered report on events within the country. Haystack earned its creator
Austin Heap a great deal of positive coverage from the media during the 2009 Iranian election protests. The BBC described Heap as
"on the front lines" of the protesters' "Twitter revolution", while The Guardian called him an
Innovator of the Year. Despite the laudatory coverage, however, the media were never given a copy of the software to examine. Indeed, not much is known about the software or its inner workings. Specialists in network encryption security were not allowed to perform an independent evaluation of Haystack, despite its distribution to and use by a small number of Iranians, possibly at some risk. As interest in the project
widens and criticisms of the media coverage and software continue to
mount, Heap has currently asked users to
cease using Haystack until a security review can be performed.
posted by Blazecock Pileon
on Sep 13, 2010 -
31 comments
"[C]omputer design is being dictated not by electronic design rules, physical layout requirements, and thermal issues, but by the wishes of the content industry." By deliberately breaking audio and video functionality, opening up new avenues for debilitating malware, and reversing performance gains in desktop PCs and third-party components, Peter Gutmann argues
"the Vista Content Protection specification could very well constitute the longest suicide note in history."
posted by Blazecock Pileon
on Dec 23, 2006 -
132 comments