Skip to main content

Home/ Future of the Web/ Group items matching "drives" in title, tags, annotations or url

Group items matching
in title, tags, annotations or url

Sort By: Relevance | Date Filter: All | Bookmarks | Topics Simple Middle
Paul Merrell

Visit the Wrong Website, and the FBI Could End Up in Your Computer | Threat Level | WIRED - 0 views

  • Security experts call it a “drive-by download”: a hacker infiltrates a high-traffic website and then subverts it to deliver malware to every single visitor. It’s one of the most powerful tools in the black hat arsenal, capable of delivering thousands of fresh victims into a hackers’ clutches within minutes. Now the technique is being adopted by a different kind of a hacker—the kind with a badge. For the last two years, the FBI has been quietly experimenting with drive-by hacks as a solution to one of law enforcement’s knottiest Internet problems: how to identify and prosecute users of criminal websites hiding behind the powerful Tor anonymity system. The approach has borne fruit—over a dozen alleged users of Tor-based child porn sites are now headed for trial as a result. But it’s also engendering controversy, with charges that the Justice Department has glossed over the bulk-hacking technique when describing it to judges, while concealing its use from defendants. Critics also worry about mission creep, the weakening of a technology relied on by human rights workers and activists, and the potential for innocent parties to wind up infected with government malware because they visited the wrong website. “This is such a big leap, there should have been congressional hearings about this,” says ACLU technologist Chris Soghoian, an expert on law enforcement’s use of hacking tools. “If Congress decides this is a technique that’s perfectly appropriate, maybe that’s OK. But let’s have an informed debate about it.”
  • The FBI’s use of malware is not new. The bureau calls the method an NIT, for “network investigative technique,” and the FBI has been using it since at least 2002 in cases ranging from computer hacking to bomb threats, child porn to extortion. Depending on the deployment, an NIT can be a bulky full-featured backdoor program that gives the government access to your files, location, web history and webcam for a month at a time, or a slim, fleeting wisp of code that sends the FBI your computer’s name and address, and then evaporates. What’s changed is the way the FBI uses its malware capability, deploying it as a driftnet instead of a fishing line. And the shift is a direct response to Tor, the powerful anonymity system endorsed by Edward Snowden and the State Department alike.
Gonzalo San Gil, PhD.

Hard drive encryption in Linux | Linux User & Developer - the Linux and FOSS mag for a GNU generation - 0 views

  •  
    "by Nitish Tiwari TrueCrypt is no more, but dm-crypt and LUKS are great open source options for setting up and using data encryption Follow @LinuxUserMag"
  •  
    "by Nitish Tiwari TrueCrypt is no more, but dm-crypt and LUKS are great open source options for setting up and using data encryption Follow @LinuxUserMag"
Gonzalo San Gil, PhD.

Google Continues To Try To Appease Hollywood, Though It Is Unlikely To Ever Be Enough | Techdirt - 0 views

  •  
    "Google has come out with the latest version of its "How Google Fights Piracy" report (pdf link), going to great lengths to show how the company goes above and beyond what is required by law to try to drive people to authorized copies of content while also increasing opportunities for content creators to monetize their own content."
  •  
    "Google has come out with the latest version of its "How Google Fights Piracy" report (pdf link), going to great lengths to show how the company goes above and beyond what is required by law to try to drive people to authorized copies of content while also increasing opportunities for content creators to monetize their own content."
Gonzalo San Gil, PhD.

Bribes and Extortion Help Turn Android (Linux-powered) Into 'Microsoft Android' | Techrights - 0 views

  •  
    "Summary: A strategy involving harassment and bribes drives large Android players into Microsoft's arms (PRISM and lock-in), much to Google's (and users') detriment and beyond regulators' range of visibility"
  •  
    "Summary: A strategy involving harassment and bribes drives large Android players into Microsoft's arms (PRISM and lock-in), much to Google's (and users') detriment and beyond regulators' range of visibility"
Gonzalo San Gil, PhD.

Top 10 Open Source Developments of 2015 | Business | LinuxInsider - 0 views

  •  
    "Open source is driving an ever-expanding market. The notion of community-driven development is a growing disruption to proprietary software controlled by commercial vendors, and the free open source software concept has become a major disruption in industry and technology."
  •  
    "Open source is driving an ever-expanding market. The notion of community-driven development is a growing disruption to proprietary software controlled by commercial vendors, and the free open source software concept has become a major disruption in industry and technology."
Gonzalo San Gil, PhD.

The U.N. wants to connect the world to the Internet. That's not enough. - 0 views

  •  
    "But connectivity alone cannot be global policy. Respect for privacy and the freedom of expression must go hand in glove with the drive to connection."
Gonzalo San Gil, PhD.

Court Freezes Megaupload's MPAA and RIAA Lawsuits - TorrentFreak - 0 views

  •  
    " By Ernesto on November 25, 2016 C: 18 Breaking A federal court in Virginia has granted Megaupload's request to place the cases filed by the music and movie companies on hold until April next year, while the criminal case remains pending. Meanwhile, Megaupload is working hard to ensure that critical evidence on decaying hard drives is "
Gonzalo San Gil, PhD.

Thank you for donating! | Electronic Frontier Foundation - 0 views

  •  
    "Thank you for donating to the Electronic Frontier Foundation during the Summer Security Reboot membership drive! Stand with EFF and protect yourself, your personal information, and your rights. We've been fighting back for 25 years because of members like you, and your support will help us advocate for users for many years to come. "
Gonzalo San Gil, PhD.

Save EU Net Neutrality - 0 views

  •  
    "This summer, the EU decides on net neutrality. If we lose, European ISPs win the power to give some sites & apps special treatment-while slowing others to a crawl. On June 28, the EU Slowdown begins. Sites will protest with a slow loading icon based on Europe's flag, to drive millions of comments to EU regulators. Can you join?"
Gonzalo San Gil, PhD.

Fedora 24 shows off new visions of the Linux desktop, cloud, and containers | ZDNet - 0 views

  •  
    "Fedora adds multiple Linux desktops, OpenShift cloud Origin and Fedora Atomic Host to drive containerized application development and deployment. Steven J. Vaughan-Nichols By Steven J. Vaughan-Nichols for Linux and Open Source | June 21, 2016 -- 17:29 GMT (18:29 BST) | Topic: Enterprise Software "
Gonzalo San Gil, PhD.

Sneakernet Redux: Walk Your Data - 1 views

  •  
    [Out: the Internet. In again: sneakernet. While Internet speeds stagnate and firewalls proliferate, portable storage media have been screaming ahead in capacity, transfer speed and, most importantly, ease of use. As a result, computer users are bypassing cyberspace and burning discs or toting plug-and-play drives instead. ]
Gonzalo San Gil, PhD.

DailyDirt: Publishing Digitally (For Free!) | Techdirt - 0 views

  •  
    "from the urls-we-dig-up dept Publishing content digitally is a topic that comes up around here fairly regularly. If you're a longtime Techdirt reader, you'll know that we generally think digital publishing drives down the price of content to free (but that doesn't mean your work is worthless!) and giving away content is often a very effective promotional tactic for selling other things that can't be freely copied. Here are just a few interesting examples of free content you can peruse at your leisure. "
Paul Merrell

Testosterone Pit - Home - The Other Reason Why IBM Throws A Billion At Linux (With NSA- Designed Backdoor) - 0 views

  • IBM announced today that it would throw another billion at Linux, the open-source operating system, to run its Power System servers. The first time it had thrown a billion at Linux was in 2001, when Linux was a crazy, untested, even ludicrous proposition for the corporate world. So the moolah back then didn’t go to Linux itself, which was free, but to related technologies across hardware, software, and service, including things like sales and advertising – and into IBM’s partnership with Red Hat which was developing its enterprise operating system, Red Hat Enterprise Linux. “It helped start a flurry of innovation that has never slowed,” said Jim Zemlin, executive director of the Linux Foundation. IBM claims that the investment would “help clients capitalize on big data and cloud computing with modern systems built to handle the new wave of applications coming to the data center in the post-PC era.” Some of the moolah will be plowed into the Power Systems Linux Center in Montpellier, France, which opened today. IBM’s first Power Systems Linux Center opened in Beijing in May. IBM may be trying to make hay of the ongoing revelations that have shown that the NSA and other intelligence organizations in the US and elsewhere have roped in American tech companies of all stripes with huge contracts to perfect a seamless spy network. They even include physical aspects of surveillance, such as license plate scanners and cameras, which are everywhere [read.... Surveillance Society: If You Drive, You Get Tracked].
  • Then another boon for IBM. Experts at the German Federal Office for Security in Information Technology (BIS) determined that Windows 8 is dangerous for data security. It allows Microsoft to control the computer remotely through a “special surveillance chip,” the wonderfully named Trusted Platform Module (TPM), and a backdoor in the software – with keys likely accessible to the NSA and possibly other third parties, such as the Chinese. Risks: “Loss of control over the operating system and the hardware” [read.... LEAKED: German Government Warns Key Entities Not To Use Windows 8 – Links The NSA.
  • It would be an enormous competitive advantage for an IBM salesperson to walk into a government or corporate IT department and sell Big Data servers that don’t run on Windows, but on Linux. With the Windows 8 debacle now in public view, IBM salespeople don’t even have to mention it. In the hope of stemming the pernicious revenue decline their employer has been suffering from, they can politely and professionally hype the security benefits of IBM’s systems and mention in passing the comforting fact that some of it would be developed in the Power Systems Linux Centers in Montpellier and Beijing. Alas, Linux too is tarnished. The backdoors are there, though the code can be inspected, unlike Windows code. And then there is Security-Enhanced Linux (SELinux), which was integrated into the Linux kernel in 2003. It provides a mechanism for supporting “access control” (a backdoor) and “security policies.” Who developed SELinux? Um, the NSA – which helpfully discloses some details on its own website (emphasis mine): The results of several previous research projects in this area have yielded a strong, flexible mandatory access control architecture called Flask. A reference implementation of this architecture was first integrated into a security-enhanced Linux® prototype system in order to demonstrate the value of flexible mandatory access controls and how such controls could be added to an operating system. The architecture has been subsequently mainstreamed into Linux and ported to several other systems, including the Solaris™ operating system, the FreeBSD® operating system, and the Darwin kernel, spawning a wide range of related work.
  • ...1 more annotation...
  • Among a slew of American companies who contributed to the NSA’s “mainstreaming” efforts: Red Hat. And IBM? Like just about all of our American tech heroes, it looks at the NSA and other agencies in the Intelligence Community as “the Customer” with deep pockets, ever increasing budgets, and a thirst for technology and data. Which brings us back to Windows 8 and TPM. A decade ago, a group was established to develop and promote Trusted Computing that governs how operating systems and the “special surveillance chip” TPM work together. And it too has been cooperating with the NSA. The founding members of this Trusted Computing Group, as it’s called facetiously: AMD, Cisco, Hewlett-Packard, Intel, Microsoft, and Wave Systems. Oh, I almost forgot ... and IBM. And so IBM might not escape, despite its protestations and slick sales presentations, the suspicion by foreign companies and governments alike that its Linux servers too have been compromised – like the cloud products of other American tech companies. And now, they’re going to pay a steep price for their cooperation with the NSA. Read...  NSA Pricked The “Cloud” Bubble For US Tech Companies
Gonzalo San Gil, PhD.

Connected Continent: a single telecom market for growth & jobs - Digital Agenda for Europe - European Commission - 0 views

  •  
    "In the face of the deep crisis affecting its economy and society, Europe needs to tap into new sources of growth in areas that will reinforce its competitiveness, drive innovation and create new job opportunities. " [Key information: Communication Regulation Recommendation Impact assessment Press release - Watch the press conference Memo Speech: We must act now - time for a Connected Continent Press conference opening remarks by Neelie Kroes, Vice-President of the EC in charge of Digital Agenda Statement by Ryan Heath, Spokesperson for Digital Agenda on the Telecom Package Tags: Telecoms telecoms single market growth and jobs]
Gary Edwards

Apple and Facebook Flash Forward to Computer Memory of the Future | Enterprise | WIRED - 1 views

  •  
    Great story that is at the center of a new cloud computing platform. I met David Flynn back when he was first demonstrating the Realmsys flash card. Extraordinary stuff. He was using the technology to open a secure Linux computing window on an operating Windows XP system. The card opened up a secure data socket, connecting to any Internet Server or Data Server, and running applications on that data - while running Windows and Windows apps in the background. Incredible mesh of Linux, streaming data, and legacy Windows apps. Everytime I find these tech pieces explaining Fusion-io though, I can't help but think that David Flynn is one of the most decent, kind and truly deserving of success people that I have ever met. excerpt: "Apple is spending mountains of money on a new breed of hardware device from a company called Fusion-io. As a public company, Fusion-io is required to disclose information about customers that account for an usually large portion of its revenue, and with its latest annual report, the Salt Lake City outfit reveals that in 2012, at least 25 percent of its revenue - $89.8 million - came from Apple. That's just one figure, from just one company. But it serves as a sign post, showing you where the modern data center is headed. 'There's now a blurring between the storage world and the memory world. People have been enlightened by Fusion-io.' - Gary Gentry Inside a data center like the one Apple operates in Maiden, North Carolina, you'll find thousands of computer servers. Fusion-io makes a slim card that slots inside these machines, and it's packed with hundreds of gigabytes of flash memory, the same stuff that holds all the software and the data on your smartphone. You can think of this card as a much-needed replacement for the good old-fashioned hard disk that typically sits inside a server. Much like a hard disk, it stores information. But it doesn't have any moving parts, which means it's generally more reliable. It c
Gonzalo San Gil, PhD.

Net Neutrality Rules Are Already Forcing Companies To Play Fair, And The Giant ISPs Absolutely Hate It | Techdirt - 0 views

  •  
    "from the please-stop-doing-your-job dept The FCC's net neutrality rules don't even go into effect until June 12, but they're already benefiting consumers. You'll recall that the last year or so has been filled with ugly squabbling over interconnection issues, with Level 3 accusing ISPs like Verizon of letting peering points congest to kill settlement-free peering and drive Netflix toward paying for direct interconnection."
Gonzalo San Gil, PhD.

Cloud Native Computing Foundation - 0 views

  •  
    "The Cloud Native Computing Foundation's mission is to create and drive the adoption of a new computing paradigm that is optimized for modern distributed systems environments. The participants believe that systems architected will be:"
Gonzalo San Gil, PhD.

Microsoft joins the Linux Foundation | It runs on Linux - 0 views

  •  
    "The founding members of the R Consortium include other major corporations like Google, HP and Oracle. R is a rapidly evolving language for statistical data analysis that's driving innovation in the field of data sciences."
Gonzalo San Gil, PhD.

Censoring Pirate Sites is Counterproductive, Research Finds - TorrentFreak - 0 views

  •  
    " Ernesto on July 8, 2015 C: 60 Breaking A new study has found that blocking access to torrent and linking sites results in the opposite effect. Instead of driving people towards legal websites and services, many of the blocked sites simply move to other domain names where they enjoy a significant and sustained boost in traffic."
Paul Merrell

Popular Security Software Came Under Relentless NSA and GCHQ Attacks - The Intercept - 0 views

  • The National Security Agency and its British counterpart, Government Communications Headquarters, have worked to subvert anti-virus and other security software in order to track users and infiltrate networks, according to documents from NSA whistleblower Edward Snowden. The spy agencies have reverse engineered software products, sometimes under questionable legal authority, and monitored web and email traffic in order to discreetly thwart anti-virus software and obtain intelligence from companies about security software and users of such software. One security software maker repeatedly singled out in the documents is Moscow-based Kaspersky Lab, which has a holding registered in the U.K., claims more than 270,000 corporate clients, and says it protects more than 400 million people with its products. British spies aimed to thwart Kaspersky software in part through a technique known as software reverse engineering, or SRE, according to a top-secret warrant renewal request. The NSA has also studied Kaspersky Lab’s software for weaknesses, obtaining sensitive customer information by monitoring communications between the software and Kaspersky servers, according to a draft top-secret report. The U.S. spy agency also appears to have examined emails inbound to security software companies flagging new viruses and vulnerabilities.
  • The efforts to compromise security software were of particular importance because such software is relied upon to defend against an array of digital threats and is typically more trusted by the operating system than other applications, running with elevated privileges that allow more vectors for surveillance and attack. Spy agencies seem to be engaged in a digital game of cat and mouse with anti-virus software companies; the U.S. and U.K. have aggressively probed for weaknesses in software deployed by the companies, which have themselves exposed sophisticated state-sponsored malware.
  • The requested warrant, provided under Section 5 of the U.K.’s 1994 Intelligence Services Act, must be renewed by a government minister every six months. The document published today is a renewal request for a warrant valid from July 7, 2008 until January 7, 2009. The request seeks authorization for GCHQ activities that “involve modifying commercially available software to enable interception, decryption and other related tasks, or ‘reverse engineering’ software.”
  • ...9 more annotations...
  • The NSA, like GCHQ, has studied Kaspersky Lab’s software for weaknesses. In 2008, an NSA research team discovered that Kaspersky software was transmitting sensitive user information back to the company’s servers, which could easily be intercepted and employed to track users, according to a draft of a top-secret report. The information was embedded in “User-Agent” strings included in the headers of Hypertext Transfer Protocol, or HTTP, requests. Such headers are typically sent at the beginning of a web request to identify the type of software and computer issuing the request.
  • According to the draft report, NSA researchers found that the strings could be used to uniquely identify the computing devices belonging to Kaspersky customers. They determined that “Kaspersky User-Agent strings contain encoded versions of the Kaspersky serial numbers and that part of the User-Agent string can be used as a machine identifier.” They also noted that the “User-Agent” strings may contain “information about services contracted for or configurations.” Such data could be used to passively track a computer to determine if a target is running Kaspersky software and thus potentially susceptible to a particular attack without risking detection.
  • Another way the NSA targets foreign anti-virus companies appears to be to monitor their email traffic for reports of new vulnerabilities and malware. A 2010 presentation on “Project CAMBERDADA” shows the content of an email flagging a malware file, which was sent to various anti-virus companies by François Picard of the Montréal-based consulting and web hosting company NewRoma. The presentation of the email suggests that the NSA is reading such messages to discover new flaws in anti-virus software. Picard, contacted by The Intercept, was unaware his email had fallen into the hands of the NSA. He said that he regularly sends out notification of new viruses and malware to anti-virus companies, and that he likely sent the email in question to at least two dozen such outfits. He also said he never sends such notifications to government agencies. “It is strange the NSA would show an email like mine in a presentation,” he added.
  • The NSA presentation goes on to state that its signals intelligence yields about 10 new “potentially malicious files per day for malware triage.” This is a tiny fraction of the hostile software that is processed. Kaspersky says it detects 325,000 new malicious files every day, and an internal GCHQ document indicates that its own system “collect[s] around 100,000,000 malware events per day.” After obtaining the files, the NSA analysts “[c]heck Kaspersky AV to see if they continue to let any of these virus files through their Anti-Virus product.” The NSA’s Tailored Access Operations unit “can repurpose the malware,” presumably before the anti-virus software has been updated to defend against the threat.
  • The Project CAMBERDADA presentation lists 23 additional AV companies from all over the world under “More Targets!” Those companies include Check Point software, a pioneering maker of corporate firewalls based Israel, whose government is a U.S. ally. Notably omitted are the American anti-virus brands McAfee and Symantec and the British company Sophos.
  • As government spies have sought to evade anti-virus software, the anti-virus firms themselves have exposed malware created by government spies. Among them, Kaspersky appears to be the sharpest thorn in the side of government hackers. In the past few years, the company has proven to be a prolific hunter of state-sponsored malware, playing a role in the discovery and/or analysis of various pieces of malware reportedly linked to government hackers, including the superviruses Flame, which Kaspersky flagged in 2012; Gauss, also detected in 2012; Stuxnet, discovered by another company in 2010; and Regin, revealed by Symantec. In February, the Russian firm announced its biggest find yet: the “Equation Group,” an organization that has deployed espionage tools widely believed to have been created by the NSA and hidden on hard drives from leading brands, according to Kaspersky. In a report, the company called it “the most advanced threat actor we have seen” and “probably one of the most sophisticated cyber attack groups in the world.”
  • Hacks deployed by the Equation Group operated undetected for as long as 14 to 19 years, burrowing into the hard drive firmware of sensitive computer systems around the world, according to Kaspersky. Governments, militaries, technology companies, nuclear research centers, media outlets and financial institutions in 30 countries were among those reportedly infected. Kaspersky estimates that the Equation Group could have implants in tens of thousands of computers, but documents published last year by The Intercept suggest the NSA was scaling up their implant capabilities to potentially infect millions of computers with malware. Kaspersky’s adversarial relationship with Western intelligence services is sometimes framed in more sinister terms; the firm has been accused of working too closely with the Russian intelligence service FSB. That accusation is partly due to the company’s apparent success in uncovering NSA malware, and partly due to the fact that its founder, Eugene Kaspersky, was educated by a KGB-backed school in the 1980s before working for the Russian military.
  • Kaspersky has repeatedly denied the insinuations and accusations. In a recent blog post, responding to a Bloomberg article, he complained that his company was being subjected to “sensationalist … conspiracy theories,” sarcastically noting that “for some reason they forgot our reports” on an array of malware that trace back to Russian developers. He continued, “It’s very hard for a company with Russian roots to become successful in the U.S., European and other markets. Nobody trusts us — by default.”
  • Documents published with this article: Kaspersky User-Agent Strings — NSA Project CAMBERDADA — NSA NDIST — GCHQ’s Developing Cyber Defence Mission GCHQ Application for Renewal of Warrant GPW/1160 Software Reverse Engineering — GCHQ Reverse Engineering — GCHQ Wiki Malware Analysis & Reverse Engineering — ACNO Skill Levels — GCHQ
‹ Previous 21 - 40 of 84 Next › Last »
Showing 20 items per page