In a crackdown that FBI claims to be about hunting down pedophiles, half of the onion sites in the TOR network has been compromised, including the e-mail counterpart of TOR deep web, TORmail. FreedomWeb, an Irish company known for providing hosting for Tor "hidden services" -- services reached over the Tor anonymized/encrypted network -- has shut down after its owner, Eric Eoin Marques, was arrested over allegations that he had facilitated the spread of child pornography. [more inside]
Barnaby Jack, a hacker and security researcher previously known for his hacks involving ATMs and insulin pumps, has died in San Francisco. He was 35. His death came just days before he was to give a presentation about techniques for hacking implanted heart devices, which could kill a person from 30 feet away.
PreCheck, a new program instituted by the TSA, will allow passengers to keep their shoes, jackets and belts during screening, as well as allow laptop computers and approved liquids to remain in bags for a fee of $85.
Bulletproof Security is a paramilitary security company. They have provided security to Habitat for Humanity and Empire CAT among others. [more inside]
The TSA has started an Instagram page showing confiscated items from TSA checkpoints in airports around the country.
Relive techno fears of yore ... malware aficionado Daniel White collects vintage computer viruses, infects his machines and records the results. See more examples at his YouTube channel.
Imagine two politicians: One preaches fear and excessive "security," while the other says terrorism is a negligible risk. They hold, like me, that risk is part of life, and that while some security is necessary, we should mostly just refuse to be terrorized and get on with our lives. Fast-forward 10 years. If I'm right and there have been no more terrorist attacks, the preacher of fear takes credit for keeping us safe. But if a terrorist attack has occurred, my government career is over.
Going back to at least 2011, it was believed that Facebook kept "shadow profiles" of users and non-users, accumulating information when users synchronize mobile phones, import personal data from e-mail providers, import personal information from instant messaging services, send invitations to friends or make search queries for other people on Facebook. In early 2012, four members of the U.S. House of Representatives Energy and Commerce Committee's Subcommittee on Oversight and Investigations demanded answers from Facebook (PDF) and were told that non-users didn't have "shadow profiles", but the contents of the reply were not made public. Just this past Friday, Facebook released an "Important Message" on a data leak they closed, in which information from members' "shadow profiles" could be obtained. [more inside]
Yahoo, on June 12, announced that it is releasing inactive IDs. Yahoo says they are "committed and confident," while others think it is a "spectacularly bad idea" and a "dirty trick."
The NFL announced a change to its bag policy Thursday and beginning with the 2013 season, only clear plastic, vinyl or PVC bags will be permitted inside NFL stadiums. [more inside]
The Pew Internet And American Life Project has a new report out on Teens, Social Media, and Privacy. danah boyd comments:
My favorite finding of Pew’s is that 58% of teens cloak their messages either through inside jokes or other obscure references, with more older teens (62%) engaging in this practice than younger teens (46%).[more inside]
Anatomy of a hack: How crackers ransack passwords like “qeadzcwrsfxv1331” Hackers get %90 of an MD5 password database using multiple analysis techniques including Markov chains, mask, combinator and hybrid attacks. These attacks combine dictionaries of previously-recovered passwords and passphrases with brute force and statistical analysis to expand the power of password cracking.
In southern Sweden, scene of recent sheep-killing incidents perpetrated by wolves, llamas are being introduced to see if they will kick wolf-butt and protect the sheep. In the US, the guard llama is becoming a more common "first line of defense" on ranches. [more inside]
Have you been looking for bike locks that work? Will only the best locks do? Perhaps you just need a secondary lock?
Practical Ethics: Enlightened Surveillance?
Surrendering on surveillance might be the least bad option – of all likely civil liberty encroachments, this seemed the less damaging and hardest to resist. But that’s an overly defensive way of phrasing it – if ubiquitous surveillance and lack of privacy are the trends of the future, we shouldn’t just begrudgingly accept them, but demand that society gets the most possible out of them.[more inside]
It’s not often that one has the opportunity to be the target of a cyber and kinetic attack at the same time. But that is exactly what’s happened to me and my Web site over the past 24 hours. On Thursday afternoon, my site was the target of a fairly massive denial of service attack. That attack was punctuated by a visit from a heavily armed local police unit that was tricked into responding to a 911 call spoofed to look like it came from my home. Well, as one gamer enthusiast who follows me on Twitter remarked, I guess I’ve now “unlocked that level.” ~ KrebsonSecurity
Meet the men who spy on women through their webcams - "If you are unlucky enough to have your computer infected with a RAT, prepare to be sold or traded to the kind of person who enters forums to ask, "Can I get some slaves for my rat please? I got 2 bucks lol I will give it to you :b" At that point, the indignities you will suffer—and the horrific website images you may see—will be limited only by the imagination of that most terrifying person: a 14-year-old boy with an unsupervised Internet connection."
Delta Airlines and other airline workers' unions have asked the TSA to reconsider their recent announcement to loosen security restrictions on airlines, effective April 25, that would allow passengers to carry small pocket knives, among other items. [more inside]
Twitter is experimenting with online shopping: "American Express card holders who connect their card numbers to their Twitter accounts can post on Twitter to trigger a purchase of select products, including discounted American Express gift cards, Kindle Fire tablets from Amazon.com Inc. and jewelry from designer Donna Karan. The program will roll out over the next few days." [more inside]
Silent Circle, a security start-up led by PGP creator Phil Zimmermann and two ex-Navy SEALs, has been teasing technology that purports to make mobile communications "virtually invulnerable to surveillance efforts" for a few months (previously). Now, they're pushing a "groundbreaking encrypted data transfer app that will enable people to send files securely from a smartphone or tablet at the touch of a button." The company has pledged not to comply with law enforcement surveillance requests, nor to provide backdoor access for the FBI.
What The Rails Security Issue Means For Your Startup summarizes the impact of recent arbitrary-code-execution security vulnerabilities in Ruby on Rails: "What Do We Do When Apocalyptically Bad Things Happen On Our Framework of Choice?"
It is June 2, 2010 and Mark Zuckerberg is sweating. He’s wearing his hoodie—he’s always wearing his hoodie—and he’s on stage and either the lights or the questions are too hot. … “Do you want to take off the hoodie?” asks Kara Swisher.The varied cultural resonances of an unassuming garment.
“I never take off the hoodie.”
The New York Times asks seven 'experts': Does makeup ultimately damage a woman’s self-esteem, or elevate it? [more inside]
(BBC) A security check on a US company has reportedly revealed one of its staff was outsourcing his work to China. [more inside]
The most-watched show in the history of the National Geographic Channel isn't Wild, Taboo or even the longest-running documentary series on cable tv: Explorer. It's Doomsday Preppers, a show that documents the "lives of otherwise ordinary Americans" as they prepare for the end of the world. [more inside]
Security experts agree that it’s only a matter of time before smartphones become the smart person’s murder weapon of choice.
Why 256 bit keys are long enough. A nice graphic explanation by Schneier why brute-force attacks against 256-bit keys will be infeasible until computers are built from something other than matter and occupy something other than space. [more inside]
Sumit Suman recently visited a site, did not sign up for anything, did not connect via social media, but got a personal email from the site the next day. Here’s how they did it.
The Mystery of the Phantom Likes. Bernard Meisler at Read Write Web is trying to find out why his dead friends are liking stuff on Facebook. [more inside]
Why Privacy Matters, Even If You Have Nothing To Hide, by Daniel J. Solove
The nothing-to-hide argument pervades discussions about privacy. The data-security expert Bruce Schneier calls it the "most common retort against privacy advocates." ... To evaluate the nothing-to-hide argument, we should begin by looking at how its adherents understand privacy. Nearly every law or policy involving privacy depends upon a particular understanding of what privacy is. The way problems are conceived has a tremendous impact on the legal and policy solutions used to solve them.[more inside]
"During his civil lawsuit against the People's Republic of China, Brian Milburn says he never once saw one of the country's lawyers. He read no court documents from China's attorneys because they filed none. The voluminous case record at the U.S. District courthouse in Santa Ana contains a single communication from China: a curt letter to the U.S. State Department, urging that the suit be dismissed. That doesn't mean Milburn's adversary had no contact with him." [China Mafia-Style Hack Attack Drives California Firm to Brink]
At least 112 workers died in Tazreen garments factory fire in Bangladesh. The reasons of the fire are the subject of investigation, but the firefighters put the blame for the tragedy on the lack of fire exits. Since 2006, over 500 garment factory workers died in Bangladesh fires caused often by poor safety standards and shoddy electrical installations. The garments made in the Tazreen factory were sold by C&A, among others. Clothing makes up 80 percent of the country's $24 billion in annual exports.
Last year saw the 100th anniversary of another such tragedy.
Last year saw the 100th anniversary of another such tragedy.
What does proper authorization to access a computer system mean? Robert Graham of Errata Security writes about the recent conviction of Andrew Auernheimer (aka weev) for “hacking” AT&T. Two years ago, weev discovered a bug in AT&T's website that exposed the email addresses of customers with iPads. According to weev, the flaw was reported as per responsible disclosure practices by first informing AT&T before bringing it public. However the FBI investigated and arrested him under the Computer Fraud and Abuse Act (CFAA). On 20th November 2012, he was found guilty of identity fraud and conspiracy to access a computer without authorization.
Mat Honan of Wired has a covetableTwitter username (@mat). Recently hackers tore his digital world apart in an attempt to commandeer it. Now he reflects: The age of the password has come to an end; we just haven’t realized it yet. And no one has figured out what will take its place. What we can say for sure is this: Access to our data can no longer hinge on secrets—a string of characters, 10 strings of characters, the answers to 50 questions—that only we’re supposed to know. The Internet doesn’t do secrets. Everyone is a few clicks away from knowing everything.
NASA will send you an email or text alert when the International Space Station is visible from your area. IBM scientists have recently made significant advances in nanotechnology. A mathematician thought a poorly-encrypted headhunting email from Google was testing him, but he had actually discovered a major security hole. All of this found via The Brief: A Daily Briefing of Technology News Worth Caring About from MeFi's own nostrich. [via mefi projects]
What are the most common and least common 4-digit PINs? Using data from recent password database leaks, an analysis of PINs. (via Schneier)
Steganographic information (account ID, a timestamp and the IP address of the current realm) is secretly embedded in World of Warcraft screen shots. Via Schneier.
"To aid the national security community in imagining contemporary threats, the Australian Security Research Centre (ASRC) is organising Australia’s Security Nightmares: The National Security Short Story Competition. The competition aims to produce a set of short stories that will contribute to a better conception of possible future threats and help defence, intelligence services, emergency managers, health agencies and other public, private and non-government organisations to be better prepared." (via)
A working, cross-platform Java 7 exploit is now in the wild. It's apparently a pair of bugs, working in tandem; neither, alone, would be enough to escape the Java sandbox, but together, any machine, be it Windows, Mac, or Linux, can be instantly and silently compromised, simply by viewing a malicious web page. Only Java 7 is vulnerable, but because of the way Oracle schedules patches, it may be unfixed until October. You can test your machine for the flaw; if vulnerable, you'll want to at least disable Java in your Web browser, if not remove it altogether. On Firefox, NoScript will provide a little protection, by not running Java code unless you click it, but the vulnerability remains.
Why passwords have never been weaker—and crackers have never been stronger. Ars weighs in on the amazing advances the bad guys have made in password cracking over the last few years. Think you know how to choose something that's safe? The probability is quite high that you don't, even if you're technically ept. [more inside]
At 5:00 PM, they remote wiped my iPhone. At 5:01 PM, they remote wiped my iPad. At 5:05, they remote wiped my MacBook Air.
Yes, I was hacked. Hard. Mat Honan, a tech journalist, had his iPhone and Mac remotely wiped and his gmail account deleted within the space of 5 minutes. Password cracked? No. Security question leak? No. Social engineering Apple tech support.
"We thought we were hosts like the queen is at a posh garden party, when actually we're hosts in the way that John Hurt is in Alien." As the Olympics approach, the scandals, inconveniences, mistakes and problems keep mounting, ranging from the frustrating through the comic to the tragic. For your appreciation, a picture of the London Olympics 2012. [more inside]