Showing posts with label computers. Show all posts
Showing posts with label computers. Show all posts

Thursday, August 10, 2017

Biohackers Encoded Malware in a Strand of DNA

Wired reports Biohackers Encoded Malware in a Strand of DNA “In new research they plan to present at the USENIX Security conference on Thursday, a group of researchers from the University of Washington has shown for the first time that it’s possible to encode malicious software into physical strands of DNA, so that when a gene sequencer analyzes it the resulting data becomes a program that corrupts gene-sequencing software and takes control of the underlying computer. While that attack is far from practical for any real spy or criminal, it’s one the researchers argue could become more likely over time, as DNA sequencing becomes more commonplace, powerful, and performed by third-party services on sensitive computer systems. And, perhaps more to the point for the cybersecurity community, it also represents an impressive, sci-fi feat of sheer hacker ingenuity.”

Tuesday, April 25, 2017

A Plea for Responsible and Contextualized Reporting on User Security

Zeynep Tufekci In Response to Guardian’s Irresponsible Reporting on WhatsApp: A Plea for Responsible and Contextualized Reporting on User Security. She basically rips them a new one. It's a nice article, with the details of the issue which act as a great example of the difficulties of making something secure against a variety of adversaries vs making it usable by a wide range of users.

Signal is well-designed. Many in the security community use and consistently recommend it. However, the very thing that makes Signal a recommendation for people at high risk—that it drops messages at any sign of hiccup—prevents a large number of ordinary people from adopting it. Our community has used Signal for a long time, and have been trying to convert people to it, but its inevitable delivery failures (some by design, to keep users safer, and some due to bandwidth or other issues) mean that we often cannot convince people to use it despite spending a lot of effort trying to convince them—even people who have a lot at stake. The reason people, including journalists and activists, use WhatsApp over Signal isn’t because people are flaky, but because in the real world, reliability, usability and a large user base are key to security.

WhatsApp effectively protects people against mass surveillance. Individually targeted attacks by powerful adversaries willing to put effort into compromising a single person are a different kind of threat. If that is the threat model in mind, then merely recommending Signal is irresponsible. Your reckless, uncontextualized piece posits a mythical Snowden-type character, with a powerful, massively resourced adversary, for whom WhatsApp would not be a good choice. From that it concludes that WhatsApp is unsafe for a billion people for whom it is, at the moment, among the best options for secure communication.

To further complicate things, switching to Signal may not be advisable in some settings, because it marks you as an activist. There are many threat models under which WhatsApp is the safest option, and there are reports of people around the world being jailed merely for having installed an encryption app. It’s fine to recommend Signal and to broaden its user base. It’s not fine to fearmonger and scare people away from WhatsApp (which runs the same protocol as Signal) because of a minor and defensible difference in the kind of warnings it gives and the blocking behavior of a few undelivered messages when someone changes phones or SIM cards.

Thursday, February 23, 2017

RIP, SHA-1

Ed Felton reports RIP, SHA-1 "Today’s cryptography news is that researchers have discovered a collision in the SHA-1 cryptographic hash function. Though long-expected, this is a notable milestone in the evolution of crypto standards."

Wednesday, November 23, 2016

Continuous Unix commit history from 1970 until today in Git

The Unix History Repository on GitHub is a Continuous Unix commit history from 1970 until today:

The history and evolution of the Unix operating system is made available as a revision management repository, covering the period from its inception in 1970 as a 2.5 thousand line kernel and 26 commands, to 2016 as a widely-used 27 million line system. The 1.1GB repository contains about half a million commits and more than two thousand merges. The repository employs Git system for its storage and is hosted on GitHub. It has been created by synthesizing with custom software 24 snapshots of systems developed at Bell Labs, the University of California at Berkeley, and the 386BSD team, two legacy repositories, and the modern repository of the open source FreeBSD system. In total, about one thousand individual contributors are identified, the early ones through primary research. The data set can be used for empirical research in software engineering, information systems, and software archaeology. The project aims to put in the repository as much metadata as possible, allowing the automated analysis of Unix history.

The files appear to be added in the repository in chronological order according to their modification time, and large parts of the source code have been attributed to their actual authors. Commands like git blame and (sometimes) git log produce the expected results.

Thursday, November 17, 2016

Britain has passed the most extreme surveillance law ever passed in a democracy

This is bad, ZDNet reports Britain has passed the ‘most extreme surveillance law ever passed in a democracy’. “The law forces UK internet providers to store browsing histories – including domains visited – for one year, in case of police investigations.”

The new law, dubbed the “snoopers’ charter”, was introduced by then-home secretary Theresa May in 2012, and took two attempts to get passed into law following breakdowns in the previous coalition government. Four years and a general election later – May is now prime minister – the bill was finalized and passed on Wednesday by both parliamentary houses.

The law will force internet providers to record every internet customer’s top-level web history in real-time for up to a year, which can be accessed by numerous government departments; force companies to decrypt data on demand – though the government has never been that clear on exactly how it forces foreign firms to do that that; and even disclose any new security features in products before they launch. Not only that, the law also gives the intelligence agencies the power to hack into computers and devices of citizens (known as equipment interference), although some protected professions – such as journalists and medical staff – are layered with marginally better protections.

Thursday, September 08, 2016

Forget Software—Now Hackers Are Exploiting Physics

Wired had a good article explain a new class of hacks, Forget Software—Now Hackers Are Exploiting Physics "Both of those new attacks use a technique Google researchers first demonstrated last March called ‘Rowhammer.’ The trick works by running a program on the target computer, which repeatedly overwrites a certain row of transistors in its DRAM flash memory, ‘hammering’ it until a rare glitch occurs: Electric charge leaks from the hammered row of transistors into an adjacent row. The leaked charge then causes a certain bit in that adjacent row of the computer’s memory to flip from one to zero or vice versa. That bit flip gives you access to a privileged level of the computer’s operating system. It’s messy. And mind-bending. And it works."

Rowhammer is far from the only new hacking technique that exploits computers’ physical properties. Proof-of-concept malware shown off by Israeli researchers over the summer, for instance, uses the sound of computers’ cooling fans or hard drive motors to transmit stolen data as audio. Another group of Israelis showed last year they could use just $300 of handheld equipment to extract encryption keys from a computer by monitoring the radio emissions leaked by its processor’s power use.

Wednesday, August 17, 2016

A Reconstruction of the Delta Airlines Datacenter Outage

UP2V presents A reconstruction of the Delta Airlines datacenter outage .

A Few Links

Here are some tech related articles I've liked recently

Monday, June 20, 2016

Hello, TensorFlow!

Aaron Schumacher walks through using Google's open sourced machine learning library in Hello, TensorFlow!. Python knowledge assumed.

Wednesday, June 01, 2016

How the Top 5 PC Makers Open Your Laptop to Hackers

Wired reports How the Top 5 PC Makers Open Your Laptop to Hackers

SOFTWARE MAKERS LIKE Microsoft put a lot of effort into ensuring that the operating system and application updates they deliver to your system are secure, so that hackers can’t hijack updates to get into your computer.

But it turns out that PC hardware makers are not so careful. An investigation conducted by Duo Security into the software updaters of five of the most popular PC manufacturers—HP, Dell, Acer, Lenovo, and Asus—found that all had serious security problems that would allow attackers to hijack the update process and install malicious code on victim machines.

Researchers at Duo Security’s Duo Labs found that all five vendors, known as OEMs or Original Equipment Manufacturers, shipped computers with pre-installed updaters that had at least one high-risk vulnerability that would give an attacker remote-code execution abilities—the ability to remotely run whatever malicious code they want on a system—and gain complete control of the system. The skill required to exploit the vulnerabilities was minimal, the researchers said in a report they’re releasing (.pdf) about their findings."

It's amazing to me that vendors are still getting this so wrong when security has been a big issue on PCs for so long and Microsoft is so public about securing Windows. To be sending updates over unencrypted channels shows complete incompetence.

Friday, April 08, 2016

The Senate’s Draft Encryption Bill Is ‘Ludicrous, Dangerous, Technically Illiterate’

Wired reports The Senate’s Draft Encryption Bill Is ‘Ludicrous, Dangerous, Technically Illiterate’ "On Thursday evening, the draft text of a bill called the ‘Compliance with Court Orders Act of 2016,’ authored by offices of Senators Diane Feinstein and Richard Burr,  was published online by the Hill.1 It’s a nine-page piece of legislation that would require people to comply with any authorized court order for data—and if that data is ‘unintelligible,’ the legislation would demand that it be rendered ‘intelligible.’ In other words, the bill would make illegal the sort of user-controlled encryption that’s in every modern iPhone, in all billion devices that run Whatsapp’s messaging service, and in dozens of other tech products. ‘This basically outlaws end-to-end encryption,’ says Joseph Lorenzo Hall, chief technologist at the Center for Democracy and Technology. ‘It’s effectively the most anti-crypto bill of all anti-crypto bills.’"

There are issue I really hate Diane Feinstein on.

Tuesday, March 15, 2016

Once again: Why you shouldn't blindly install things on your Mac

iMore explains Once again: Why you shouldn't blindly install things on your Mac.

It seems that people who accidentally misspell a URL and end it with .om versus .com are being redirected to sites that only exist to serve malware. Sites many of us visit every day have been spoofed, such as Citibank, Dell, Macy's and Gmail. Our testing hasn't seen the issue on the listed sites, but it's always better to be safe than sorry."

The only popups I run into that tell me to install something are for flash and they've always been legit. But still, whenever I see one I never click yes in the popup, instead I dismiss it, open the flash system preferences on my mac and install from there. That way I know I'm going to the real site.

I'm also mostly immune to the described attack because all such sites I regularly visit I have Safari bookmarks for and to visit them I use the bookmark via Quicksilver (Spotlight will serve the same function). The bookmarks also include HTTPS so I visit them securely.

Monday, March 14, 2016

The Two Misconceptions Dominating The Encryption Debate

TechCrunch describes The two misconceptions dominating the encryption debate.

In the first he points out that the government already has access to more data than it's ever had before or knows what to do with:

The majority of global networks – including Facebook, Google, Twitter and Skype – operate with full visibility into user accounts and often their activities, rendering this data available to law enforcement with a warrant request. That includes metadata, a rich unencrypted layer in our expanding profiles – who we talk to, where and how often, where we spend time and with whom, and what our interests are.

Widespread visual surveillance — from cameras on public utility polls and transport to commercial data collectors time-stamping and geo-tagging billions of photos of license plates – supplies an exhaustive picture of ourphysical activity. Law enforcement has access to a historically unprecedented amount of information, capable of mapping out countless connections between people, businesses, locations, and things – sometimes with and sometimes without a warrant.

Current trends in technology are only adding to the pool of data that law enforcement can draw from. When vulnerability is injected into technology used worldwide, it becomes everyone’s liability."

And this will only get worse with the Internet of Things (as more and more things are connected to the Internet). The second is the obvious one, we only want a backdoor for warranted government access; but of course there's no way to enforce that any such backdoor is not also used by bad guys. That's the part that non-technical people have problems understanding or believing (this is not going to be fixed any time soon by smart people trying harder).

John Oliver covered part of this brilliantly and hilariously last night:

Monday, March 07, 2016

Kevin Mitnick's advice on protecting laptops, smartphones, and more

MacWorld has Kevin Mitnick's advice on protecting laptops, smartphones, and more. Nice simple tips for everyone.

First OS X Ransomware Found in Transmission BitTorrent Client Installer

The Transmission.app installer was infected on March 4th, 2016 and it was found yesterday, so the window is small. If you installed Transmission this weekend, you should read this in detail. The malware waits 3 days before activating, so you have time to remove it. You can otherwise read it in detail because it's interesting. :) New OS X Ransomware KeRanger Infected Transmission BitTorrent Client Installer.

Tuesday, March 01, 2016

Diffie and Hellman Receive Turing Award

The Turing Award is basically the Nobel Prize of computer science. Today, Cryptography Pioneers Receive ACM A.M. Turing Award "ACM, the Association for Computing Machinery, today named Whitfield Diffie, former Chief Security Officer of Sun Microsystems and Martin E. Hellman, Professor Emeritus of Electrical Engineering at Stanford University, recipients of the 2015 ACM A.M. Turing Award for critical contributions to modern cryptography. The ability for two parties to communicate privately over a secure channel is fundamental for billions of people around the world. On a daily basis, individuals establish secure online connections with banks, e-commerce sites, email servers and the cloud. Diffie and Hellman's groundbreaking 1976 paper, 'New Directions in Cryptography,' introduced the ideas of public-key cryptography and digital signatures, which are the foundation for most regularly-used security protocols on the Internet today. The Diffie-Hellman Protocol protects daily Internet communications and trillions of dollars in financial transactions."

Here's a nice video explanation of their invention:

Tuesday, February 16, 2016

Extremely severe bug leaves dizzying number of software and devices vulnerable

Ars reports Extremely severe bug leaves dizzying number of software and devices vulnerable

The vulnerability was introduced in 2008 in GNU C Library, a collection of open source code that powers thousands of standalone applications and most distributions of Linux, including those distributed with routers and other types of hardware. A function known as getaddrinfo() that performs domain-name lookups contains a buffer overflow bug that allows attackers to remotely execute malicious code. It can be exploited when vulnerable devices or apps make queries to attacker-controlled domain names or domain name servers or when they're exposed to man-in-the-middle attacks where the adversary has the ability to monitor and manipulate data passing between a vulnerable device and the open Internet. All versions of glibc after 2.9 are vulnerable.

Maintainers of glibc, as the open source library is called, released an update that patches the vulnerability. Anyone responsible for Linux-based software or hardware that performs domain name lookups should install it as soon as possible. For many people running servers, patching will be a simple matter of downloading the update and installing it. But for other types of users, a fix may not be so easy. Some apps that were compiled with a vulnerable version of glibc will have to be recompiled with an updated version of the library, a process that will take time as users wait for fixes to become available from hardware manufacturers and app developers."

Saturday, February 06, 2016

National Security Agency Plans Major Reorganization

The Washington Post reports National Security Agency plans major reorganization "The National Security Agency, the largest electronic spy agency in the world, is undertaking a major reorganization, merging its offensive and defensive organizations in the hope of making them more adept at facing the digital threats of the 21st century, according to current and former officials."

"In place of the Signals Intelligence and Information Assurance directorates — the organizations that historically have spied on foreign targets and defended classified networks against spying, respectively — the NSA is creating a Directorate of Operations that combines the operational elements of each."

"“When it comes to cyber in particular, the line between collection capabilities and our own vulnerabilities — between the acquisition of signals intelligence and the assurance of our own information — is virtually nonexistent,” said Rep. Adam B. Schiff (Calif.), the ranking Democrat on the House Intelligence Committee. “What is a vulnerability to be patched at home is often a potential collection opportunity abroad and vice versa.”"

Bruce Schneier doesn't think it's a good idea: "I think this will make it even harder to trust the NSA. In my book Data and Goliath, I recommended separating the attack and defense missions of the NSA even further, breaking up the agency. (I also wrote about that idea here.) And missing in their reorg is how US CyberCommmand's offensive and defensive capabilities relate to the NSA's. That seems pretty important, too."

It seems to me that the real problem is that NSA targets use the same systems as we do, and by we I mean our government, industry and civilians. By definition a hole in these systems means we're vulnerable too and fixing that hole removes a spying opportunity. If the offensive unit isn't going to share vulnerabilities then perhaps they should be separate.

Wednesday, January 27, 2016

Google Go Program Beats Go Master

Google reports AlphaGo: using machine learning to master the ancient game of Go

We trained the neural networks on 30 million moves from games played by human experts, until it could predict the human move 57 percent of the time (the previous record before AlphaGo was 44 percent). But our goal is to beat the best human players, not just mimic them. To do this, AlphaGo learned to discover new strategies for itself, by playing thousands of games between its neural networks, and adjusting the connections using a trial-and-error process known as reinforcement learning. Of course, all of this requires a huge amount of computing power, so we made extensive use of Google Cloud Platform.

After all that training it was time to put AlphaGo to the test. First, we held a tournament between AlphaGo and the other top programs at the forefront of computer Go. AlphaGo won all but one of its 500 games against these programs. So the next step was to invite the reigning three-time European Go champion Fan Hui—an elite professional player who has devoted his life to Go since the age of 12—to our London office for a challenge match. In a closed-doors match last October, AlphaGo won by 5 games to 0. It was the first time a computer program has ever beaten a professional Go player. You can find out more in our paper, which was published in Nature today.

Monday, January 25, 2016

RIP Marvin Minsky

he New York Times reports Marvin Minsky, Pioneer in Artificial Intelligence, Dies at 88. Virtually every colleague mentioned in this obituary is a genius who had a huge impact on the world (Alan Kay, John McCarthy, Seymour Papert, Ray Kurzweil, Danny Hillis, Stanley Kubrick, etc.)

Update: Here are more: Personal page for Marvin Minsky