Skip to main content

Home/ Future of the Web/ Group items tagged in need

Rss Feed Group items tagged

Paul Merrell

Did NSA, GCHQ steal the secret key in YOUR phone SIM? It's LIKELY * The Register - 0 views

  • The NSA and Britain's GCHQ hacked the world's biggest SIM card maker to harvest the encryption keys needed to silently and effortlessly eavesdrop on potentially millions of people. That's according to documents obtained by surveillance whistleblower Edward Snowden and leaked to the web on Thursday. "Wow. This is huge – it's one of the most significant findings of the Snowden files so far," computer security guru Bruce Schneier told The Register this afternoon. "We always knew that they would occasionally steal SIM keys. But all of them? The odds that they just attacked this one firm are extraordinarily low and we know the NSA does like to steal keys where it can." The damning slides, published by Snowden's chums at The Intercept, detail the activities of the as-yet unheard-of Mobile Handset Exploitation Team (MHET), run by the US and UK. The group targeted Gemalto, which churns out about two billion SIM cards each year for use around the world, and targeted it in an operation dubbed DAPINO GAMMA.
  • Gemalto's hacking may also bring into question some of its other security products as well. The company supplies chips for electronic passports issued by the US, Singapore, India, and many European states, and is also involved in the NFC and mobile banking sector. It's important to note that this is useful for tracking the phone activity of a target, but the mobile user can still use encryption on the handset itself to ensure that some communications remain private. "Ironically one of your best defenses against a hijacked SIM is to use software encryption," Jon Callas, CTO of encrypted chat biz Silent Circle told The Register. "In our case there's a TCP/IP cloud between Alice and Bob and that can deal with compromised routers along the path as well as SIM issues, and the same applies to similar mobile software."
  • On Wednesday the UK government admitted that its intelligence agencies had in fact broken the ECHR when spying on communications between lawyers and those suing the British state, so GCHQ might want to reconsider that statement.
Paul Merrell

Germany Fires Verizon Over NSA Spying - 0 views

  • Germany announced Thursday it is canceling its contract with Verizon Communications over concerns about the role of U.S. telecom corporations in National Security Agency spying. “The links revealed between foreign intelligence agencies and firms after the N.S.A. affair show that the German government needs a high level of security for its essential networks,” declared Germany’s Interior Ministry in a statement released Thursday. The Ministry said it is engaging in a communications overhaul to strengthen privacy protections as part of the process of severing ties with Verizon. The announcement follows revelations, made possible by NSA whistleblower Edward Snowden, that Germany is a prime target of NSA spying. This includes surveillance of German Chancellor Angela Merkel’s mobile phone communications, as well as a vast network of centers that secretly collect information across the country. Yet, many have accused Germany of being complicit in NSA spying, in addition to being targeted by it. The German government has refused to grant Snowden political asylum, despite his contribution to the public record about U.S. spying on Germany.
Paul Merrell

Are processors pushing up against the limits of physics? | Ars Technica - 0 views

  • When I first started reading Ars Technica, performance of a processor was measured in megahertz, and the major manufacturers were rushing to squeeze as many of them as possible into their latest silicon. Shortly thereafter, however, the energy needs and heat output of these beasts brought that race crashing to a halt. More recently, the number of processing cores rapidly scaled up, but they quickly reached the point of diminishing returns. Now, getting the most processing power for each Watt seems to be the key measure of performance. None of these things happened because the companies making processors ran up against hard physical limits. Rather, computing power ended up being constrained because progress in certain areas—primarily energy efficiency—was slow compared to progress in others, such as feature size. But could we be approaching physical limits in processing power? In this week's edition of Nature, The University of Michigan's Igor Markov takes a look at the sorts of limits we might face.
Paul Merrell

'Shadow Brokers' give away more NSA hacking tools - 0 views

  • The elusive Shadow Brokers didn't have much luck selling the NSA's hacking tools, so they're giving more of the software away -- to everyone. In a Medium post, the mysterious team supplied the password for an encrypted file containing many of the Equation Group surveillance tools swiped back in 2016. Supposedly, the group posted the content in "protest" at President Trump turning his back on the people who voted for him. The leaked data appears to check out, according to researchers, but some of it is a couple of decades old and focused on platforms like Linux. If anything, the leak might backfire. Edward Snowden notes that while the leak is "nowhere near" representing the NSA's complete tool set, there's enough that the NSA should "instantly identify" where and how the kit leaked. This doesn't mean the Shadow Brokers themselves are about to face capture. However, this may give the agency info it needs to both connect the dots (how much of a role did NSA contractor Harold Thomas Martin III play in the online leak, for instance?) and prevent a repeat incident.Does this open a can of worms? It's hard to say -- researchers are still combing over the data. If there are any hacks that can be made useful, though, this could be problematic for server operators worried about cybercrime. If nothing else, it shows that the Shadow Brokers didn't reveal their full hand.
Paul Merrell

Trump administration pulls back curtain on secretive cybersecurity process - The Washin... - 0 views

  • The White House on Wednesday made public for the first time the rules by which the government decides to disclose or keep secret software flaws that can be turned into cyberweapons — whether by U.S. agencies hacking for foreign intelligence, money-hungry criminals or foreign spies seeking to penetrate American computers. The move to publish an un­classified charter responds to years of criticism that the process was unnecessarily opaque, fueling suspicion that it cloaked a stockpile of software flaws that the National Security Agency was hoarding to go after foreign targets but that put Americans’ cyber­security at risk.
  • The rules are part of the “Vulnerabilities Equities Process,” which the Obama administration revamped in 2014 as a multi­agency forum to debate whether and when to inform companies such as Microsoft and Juniper that the government has discovered or bought a software flaw that, if weaponized, could affect the security of their product. The Trump administration has mostly not altered the rules under which the government reaches a decision but is disclosing its process. Under the VEP, an “equities review board” of at least a dozen national security and civilian agencies will meet monthly — or more often, if a need arises — to discuss newly discovered vulnerabilities. Besides the NSA, the CIA and the FBI, the list includes the Treasury, Commerce and State departments, and the Office of Management and Budget. The priority is on disclosure, the policy states, to protect core Internet systems, the U.S. economy and critical infrastructure, unless there is “a demonstrable, overriding interest” in using the flaw for intelligence or law enforcement purposes. The government has long said that it discloses the vast majority — more than 90 percent — of the vulnerabilities it discovers or buys in products from defense contractors or other sellers. In recent years, that has amounted to more than 100 a year, according to people familiar with the process. But because the process was classified, the National Security Council, which runs the discussion, was never able to reveal any numbers. Now, Joyce said, the number of flaws disclosed and the number retained will be made public in an annual report. A classified version will be sent to Congress, he said.
Gonzalo San Gil, PhD.

Skype Workarounds on Linux - 0 views

  •  
    "Skype on Linux is a much debated topic that unfortunately remains largely unchanged. Skype is something that most people just have to use, but the client's official support for Linux is pathetic to say the least. The client version is old, buggy, and only available in 32-bit. Add the fact that the API is closed-source, and we are left with no alternatives as there can be no open source implementation that will allow us to chat with our Skype friends. However, there are some workarounds that can work for Linux users depending on the particular system used and the specific needs."
munna1357

Crocodile Attack on food people screem around the way. - YouTube - 1 views

  •  
    Crocodiles are brilliant animals. They have been around since the season of the dinosaurs, and they have taken this opportunity to consul themselves into a definitive executing machines. They are bosses of disguise, solid, and if necessary they can abandon sustenance for quite a while. They are the animals of numerous individuals' bad dreams. However, when you are cautious around crocodile domain, you don't need to dread them, you can simply appreciate them for what they are, the guardians of the waterways. What's more, please add to crocodile protection.  The entire group of various species is known as the 'crocodilians'. This incorporates salt-water crocodiles, new water crocodiles, gators, gharials and caimans. At present there are 23 unique types of crocodilians around the globe. The majority of these are imperiled however, in light of the fact that human development is gradually assuming control over their region. This implies lodging improvements are worked around the waterways where they live, and crocodilians are pursued out. This is a disgrace, and unbalances the entire eco-frameworks of these waterways. Numerous other creature species have adjusted to the crocodiles around them, and crocs live by the tenet of the fittest will survive. They eat feeble and wiped out creatures. Crocodile protection is critical and merits much more consideration than it as of now gets.
Gonzalo San Gil, PhD.

Top 50 Open Source VoIP Apps - 1 views

  •  
    "by The StudyWeb.com Team 20 Comments For many businesses, open source VoIP programs and apps offer a great way to save thousands of dollars every year in telephony costs. Better yet, open source programs are fully customizable to a business' specific needs, making them a popular solution that often just can't be beat. "
Paul Merrell

Who Needs CISPA? FBI Has a Non-Profit Workaround - Slashdot - 1 views

  • "What has been left out of the CISPA debate thus far is the FBI's long time workaround for information sharing with private industry: 'In 1997, long-time FBI agent Dan Larkin helped set up a non-profit based in Pittsburgh that "functions as a conduit between private industry and law enforcement."
Gonzalo San Gil, PhD.

Home | SiteCheckr | Firefox Validator Addon - 1 views

  •  
    "Home SiteCheckr is a Firefox-Addon, which analyzes websites with your custom ruleset. When to use SiteCheckr You can use SiteCheckr when other validators do not fulfill your needs. Strict or lax checking - it's in your hands: create your own rules as XPath or CSS-selector. Enforce strict codestyle: Use SiteCheckr when the official W3C validator isn't strict enough - e.g. when you want to enforce a special coding style. Grant exceptions: Use SiteCheckr when you have to allow code, that does not conform to standards - e.g. you have to embed some code snippets provided by third party."
Gonzalo San Gil, PhD.

How to Setup Your Own Web Proxy Server For Free with Google App Engine [Video Tutorial] - 1 views

  •  
    "Do a Google search like "proxy servers" and you'll find dozens of PHP proxy scripts on the Internet that will help you create your own proxy servers in minutes for free. The only limitation with PHP based proxies is that they require a web server (to host and run the proxy scripts) and you also need a domain name that will act as an address for your proxy site."
Paul Merrell

Secret Trans-Pacific Partnership Agreement (TPP) - 1 views

  •  
    The text is leaked for the latest secretly negotiated atrocity against the Open Web and FOSS, and against much more. Note that in the U.S., treaties bypass review by the House of Representatives, needing approval only of the Senate for ratification. 
Gonzalo San Gil, PhD.

4.0 - CC Wiki - 1 views

  •  
    "Goals and objectives Creative Commons staff, board, and community have identified several goals for the next version of its core license suite, tied to achieving CC's goal and mission. These include: Internationalization - further adapt the core suite of international licenses to operate globally, ensuring they are robust, enforceable and easily adopted worldwide; Interoperability - maximize interoperability between CC licenses and other licenses to reduce friction within the commons, promote standards and stem license proliferation; Long-lasting - anticipate new and changing adoption opportunities and legal challenges, allowing the new suite of licenses to endure for the foreseeable future; Data/PSI/Science/Education - recognize and address impediments to adoption of CC by governments as well as other important, publicly-minded institutions in these and other critical arenas; and Supporting Existing Adoption Models and Frameworks - remain mindful of and accommodate the needs of our existing community of adopters leveraging pre-4.0 licenses, including governments but also other important constituencies. "
Gonzalo San Gil, PhD.

Solving The Bandwidth Problem - Forbes - 0 views

  •  
    "Ed Sperling, None 1/04/2010 @ 6:00AM Solving The Bandwidth Problem For every giant step forward in technology there is a bottleneck that needs to be solved. It isn't exactly a step backward, but it does slow down the rate of progress."
Gonzalo San Gil, PhD.

MP3 Decoding Patent Is Expiring, Linux Distro Could Integrate It by Default - Softpedia - 0 views

  •  
    "The patent legislation is extremely complicated and unclear The MP3 decoding patent is one those things that seems pretty harmless and present in pretty much any device around us, but it's actually something that generates tons of money per unit for Fraunhofer and Thompson. Linux distributions need to offer this feature and it means integrating a proprietary solution, although there is some hope now that the patent seems to have expired."
Gonzalo San Gil, PhD.

Here's How an Attacker Can Bypass Your Two-Factor Authentication - 0 views

  •  
    "Two-factor authentication systems aren't as foolproof as they seem. An attacker doesn't actually need your physical authentication token if they can trick your phone company or the secure service itself into letting them in."
Gonzalo San Gil, PhD.

Reasons Why Users Don't Like Ubuntu Software Center - Softpedia - 0 views

  •  
    "Here is why people don't like Ubuntu Software Center The majority opinion in the Ubuntu community seems to be that the Ubuntu Software Center is a terrible piece of software and that it needs to be replaced or fixed urgently. We compiled a list of reasons why users don't like the application and why they think Canonical should really consider a change."
Gonzalo San Gil, PhD.

New way to curate research | Opensource.com - 1 views

  •  
    Shauna Gordon-McKeon " Now that doesn't mean that the journal article format is obsolete-many inventions much older are still in wide use today. But after a third of a millennium, it's only natural that the format needs some serious updating."
Gonzalo San Gil, PhD.

Linux Security - How Can Your Linux Be Hacked Using Malware, Trojans, Worms, Web Script... - 0 views

  •  
    " Is it possible that Linux can be infected with viruses? Probably, you heard of this in some debates. But here are some facts that you need to know to better understand how Linux is secured and what things can damage a Linux system. See how "
Gonzalo San Gil, PhD.

Some Pirate Sites Have Little Respect For Their Users - TorrentFreak [#! Note] - 0 views

  •  
    " Andy on January 24, 2016 C: 74 Opinion Basic rules of economics dictate that websites need a way to monetize their operations but with pressure in the advertising world increasing, options for pirate sites are more narrow than they were. However, while many still do their best to deliver a decent experience to users, others are letting everyone down."
« First ‹ Previous 221 - 240 of 289 Next › Last »
Showing 20 items per page