Tuesday, September 6, 2011
Department of Homeland Security warns Anonymous Hackers
The US Department of Homeland Security issued a warning to the security community regarding the planned activities of Anonymous.The DHS National Cybersecurity and Communications Integration Center (NCCIC), warns financial services companies about Anonymous’ attempts to “solicit ideologically dissatisfied, sympathetic employees.”
The bulletin warned:
Anonymous have tweeted about a tool, they call #RefRef which is believed to cause huge damage. However its damage potential remains unknown.
“Anonymous has stated publicly that the tool will be ready for wider use by the group in September 2011,” the DHS said. “But though there have been several publicly available tools that claim to be versions of #RefRef, so far it’s unclear “what the true capabilities of #RefRef are.”
They have also mentioned Apache Killer tool that can be used to launch denial of service attacks.
The DHS alert also warns of three cyber attacks:
More @ bit.ly/oOV08T
The bulletin warned:
“unwilling coercion through embarrassment or blackmail may be a risk to personnel,”They have alsowarned about the new tools that Anonymous has said it plans to use in launching future attacks.
Anonymous have tweeted about a tool, they call #RefRef which is believed to cause huge damage. However its damage potential remains unknown.
“Anonymous has stated publicly that the tool will be ready for wider use by the group in September 2011,” the DHS said. “But though there have been several publicly available tools that claim to be versions of #RefRef, so far it’s unclear “what the true capabilities of #RefRef are.”
They have also mentioned Apache Killer tool that can be used to launch denial of service attacks.
The DHS alert also warns of three cyber attacks:
- Occupy Wall Street
- Operation Facebook
- Project Mayhem
Operation Facebook is to take place on November 11, targeting the facebook for its alleged privacy violations.
Project Mayhem is scheduled for Dec 21, 2012. Not much details are available about this plan.More @ bit.ly/oOV08T
Nurses Protest in 60 Cities, Demanding Tax on Wall Street
Thousands of nurses and supporters descended on their local Congressional offices nationwide Thursday, demanding that Wall Street pay for the crisis it created.
The 60 protests in 21 states targeted both Democrats and Republicans, with austerity champions like Eric Cantor of Virginia and Michelle Bachmann of Minnesota singled out for special attention. A blockade outside Cantor’s office forced his staffers to meet with a delegation, a request they had repeatedly refused.
Soup kitchens outside Congressional offices highlighted the devastation wrought by the economy’s collapse and worsened when politicians rip into social programs. Hundreds lined up outside Democratic leader Nancy Pelosi’s San Francisco office to receive a meal.
Katie Oppenheim of the Michigan Nurses Association joined a group that served a meal in Jackson. When the nurses attempted to talk with Republican Tim Walberg, the receptionist would speak with them only from behind her bulletproof glass.
“This is one more fight among many in the country to convince corporate America we will not back down,” said Oppenheim, who chairs the professional nurse council at the University of Michigan health system.
More @ bit.ly/quJPou
The 60 protests in 21 states targeted both Democrats and Republicans, with austerity champions like Eric Cantor of Virginia and Michelle Bachmann of Minnesota singled out for special attention. A blockade outside Cantor’s office forced his staffers to meet with a delegation, a request they had repeatedly refused.
Soup kitchens outside Congressional offices highlighted the devastation wrought by the economy’s collapse and worsened when politicians rip into social programs. Hundreds lined up outside Democratic leader Nancy Pelosi’s San Francisco office to receive a meal.
Katie Oppenheim of the Michigan Nurses Association joined a group that served a meal in Jackson. When the nurses attempted to talk with Republican Tim Walberg, the receptionist would speak with them only from behind her bulletproof glass.
“This is one more fight among many in the country to convince corporate America we will not back down,” said Oppenheim, who chairs the professional nurse council at the University of Michigan health system.
More @ bit.ly/quJPou
Antisec Messes with Texas, Attacks Dozens of Police Systems and Chief Emails
| Greetings professional hypocrites in law enforcement! Having a slow day behind the desk, filing papers, staring at your colleague's fine posterior? What have you been up to since our last visit? Don't answer that. We already know. Lewd jokes? Check. Racist chain mails? Check. You lost your radio license? Lulz. Playing on the fears of voters? Check. But we already figured that. Our friends, allies, and vessels are threatened with 10+ years in prison. Yet terrorists like Luis Posada Carilles go free. This hypocritical and paranoid reaction puts us and the citizens you are supposed to protect in the same boat. You call us a national security risk. Yet BATFE guns go directly to drug dealers so they can take out rivals who don't launder money through backrooms of dominant banks. Any press can check court documents from operations like 'Fast and Furious'. Who came up with that one? What you didn't see 'From Dusk 'til Dawn'? Better title. Be more creative next time. In retaliation for the arrests of dozens of alleged Anonymous suspects, we opened fire on dozens of Texas police departments and stole boatloads of classified police documents and police chief emails across the state. During the San Jose courtdate we defaced and gave out live backdoor and admin access to the website TexasPoliceChiefs.org while allied ships launched ddos attacks upon Justice.gov and other law enforcement websites. For every defendant in the anonymous "conspiracy" we are attacking two top Texas police chiefs, leaking 3GB of their private emails and attachments. Mind you, we don't expect a sane response. Even a few insults would have been better than the way you cowards hide behind protocol, innuendo, and your badge. For more than a month we have been lurking their emails, law enforcement portals, and records and reporting systems. We leaked a few teasers including access to fbivirtualacademy.edu, several classified documents, voicemail recordings, live passwords, and even some dirty pictures. To continue the fighting spirit of WikiLeaks, we want to share the full Texas collection and expose these bumbling fools and all their secrets to the world. Thousands of documents are available on tor hidden services / bittorrent and include several dozen FBI, Border Patrol, and counter-terrorism documents classified as "law enforcement sensitive" and "for official use only". The emails also included police records, internal affairs investigations, meeting notes, training materials, officer rosters, security audits, and live password information to government systems. The private chief emails also included several racist and sexist chain email forwards and personal details sure to embarrass, discredit, and incriminate several of these so-called "community leaders". We are attacking Texas law enforcement as part of "Chinga La Migra" as they continue to harass immigrants and use border patrol operations as a cover for their backwards racist prejudice. The notoriously racist police state of Texas recently passed SB 9 and "Secure Comminities" anti-immigration laws. Texas is well known and hated for being full of Minutemen, Tea Party and KKK groups, murdering the most amount of innocent people on death row, and giving us the Bush and Cheney administration. Two months ago on the 1st we attacked the Arizona DPS and defaced several Fraternal Order of Police websites. One month ago we "Shot The Sheriff" and released 10GB of private law enforcement data while defacing dozens of police department websites in several states in the south. A week ago we released private emails belonging to Richard T. Garcia, VP of Texas-based Vanguard Defense Industries, and also a former FBI agent and current Infragard executive board member. More @ bit.ly/r6zHau |
Tuesday, August 30, 2011
An update on attempted man-in-the-middle attacks
Today we received reports of attempted SSL man-in-the-middle (MITM) attacks against Google users, whereby someone tried to get between them and encrypted Google services. The people affected were primarily located in Iran. The attacker used a fraudulent SSL certificate issued by DigiNotar, a root certificate authority that should not issue certificates for Google (and has since revoked it).
Google Chrome users were protected from this attack because Chrome was able to detect the fraudulent certificate.
More @ bit.ly/qzemez
Microsoft UI has officially entered the realm of self-parody
This is genuinely Microsoft’s idea of a “streamlined”, “optimized” UI for Windows Explorer. They were so proud of it they wrote a blog post about it.
The post is a sort of masterpiece of crazy rationalization, but I think my favourite part may be this screenshot:
Here, they proudly overlay the UI with data from their research into how often various commands are used. They use this to show that “the commands that make up 84% of what users do in Explorer are now in one tab”. But the more important thing is that the remaining 50% of the bar is taken up by buttons that nobody will ever use, ever, even according to Microsoft’s own research. And yet somehow they remain smack bang in the middle of the interface. The insanity is further enriched by this graph:
More @ bit.ly/qM4MRS
Monday, August 29, 2011
Sunday, August 28, 2011
So you want to be a video game programmer?
This post is a sequel of sorts to my How do I get a job designing video games. The good new is — if you’re a programmer — that nearly all video game companies are hiring programmers at all times. Demand is never satisfied. And the salaries are very very competitive.
The bad news is that it takes a hell of a lot of work to both be and become a great game programmer. Or maybe that isn’t such bad news, because you absolutely love programming, computers, and video games, right? If not, stop and do not goto 20.
I’m going to break this post down into a number of sub-posts, so this first one is going to be on what kinds of programming video game teams need. I’ll have followup posts on things like “how to get started” and “the interview.”
There are a couple of broad categories of programmers working on video game teams. If programmer is your player class, then the following types are your spec. Programmers are all warlocks and mages so instead of “demonology” or “frost” you can choose from below. (NOTE: if you don’t get this joke, you don’t play enough video games) This is the real world however, and many programmers dual (or even triple) spec — i.e. they handle multiple specialties.
More @ bit.ly/rbGzAM
The bad news is that it takes a hell of a lot of work to both be and become a great game programmer. Or maybe that isn’t such bad news, because you absolutely love programming, computers, and video games, right? If not, stop and do not goto 20.
I’m going to break this post down into a number of sub-posts, so this first one is going to be on what kinds of programming video game teams need. I’ll have followup posts on things like “how to get started” and “the interview.”
There are a couple of broad categories of programmers working on video game teams. If programmer is your player class, then the following types are your spec. Programmers are all warlocks and mages so instead of “demonology” or “frost” you can choose from below. (NOTE: if you don’t get this joke, you don’t play enough video games) This is the real world however, and many programmers dual (or even triple) spec — i.e. they handle multiple specialties.
More @ bit.ly/rbGzAM
Antivirus Software Pioneer Gets Dose of Reality
John McAfee knows about risk. A mathematician by training, in the late 1980s he developed the antivirus computer software program that has become a household name. In the 1990s he pioneered instant-messaging. In both cases, he grew bored and cashed out. At his peak, he was reportedly worth about $100 million.
"I don't know and that's the honest truth, eventually you have so many resources that a tiny fluctuation in the market can make you worth ten million dollars more in the morning and ten million dollars less in the evening," he explained of his ever-changing net worth.
Like many wealthy Americans, McAfee was hit hard with the simultaneous collapse of real estate, stocks and Wall Street investment banks. But he got whacked more than most, since much of his fortune was tied up in luxury properties.
"Oddly enough, when real estate markets crash, it's the higher end properties that crash the most ... simply because they're not necessities," he said. "My father always said, 'Real estate, you can't lose in real estate' ... you know, oddly enough you can."
Last Saturday, auctioneers worked up bids for his 80-acre retreat in the high desert of Rodeo, N.M. With a private airstrip and hangar, it's a slice of paradise, and it's all up for grabs.
"Everything that you see, from the real estate, the house, the automobiles, artwork, furniture, the entire ball of wax," McAfee told ABC News.
Raising the stakes for McAfee, it's an absolute auction: The highest bid wins, no matter how low it is. "It means if only one person shows up and they bid fifty cents, that's the amount of money I get," he said.
McAfee's net worth dropped from within the ballpark of $100 million to less than $10 million, he told ABC News. But instead of feeling a sense of loss, he says he feels free.
"I feel a sense of freedom," he said. "People think that it's a joy to own things. But it really isn't."
McAfee has sold his private twin-engine plane, beachfront property in Hawaii and a Colorado mansion in the shadow of Pike's Peak. His posh New Mexico getaway is the last property to hit the auction block.
"At one point, I had five houses in five different locations and it's impractical, it's almost insane to have that much real estate," he conceded. "You can only be in one place at a time."
"We are the ultimate consumer society," he said. "If you succeed within that culture, then you're simply more bonded to it. You feel like, 'Yes, I've got all this money, the ability to get things' ... and so you just do it. People buy yachts, they buy jets, they buy multiple homes."
McAfee himself indulged his whims and passions, spending millions to promote the sport of aero-trekking: tiny motorized kites that enthusiasts fly to explore the remotest corners of the country.
He built an aero-trekking playground in the Rodeo desert, which was auctioned off for $405,000 -- along with the vintage airstream trailers where his aero-trekking friends, known as "the sky gypsies," would stay, as well as his own customized camper, once owned by Howard Hughes.
More @ abcn.ws/qFgB7Q
"I don't know and that's the honest truth, eventually you have so many resources that a tiny fluctuation in the market can make you worth ten million dollars more in the morning and ten million dollars less in the evening," he explained of his ever-changing net worth.
Like many wealthy Americans, McAfee was hit hard with the simultaneous collapse of real estate, stocks and Wall Street investment banks. But he got whacked more than most, since much of his fortune was tied up in luxury properties.
"Oddly enough, when real estate markets crash, it's the higher end properties that crash the most ... simply because they're not necessities," he said. "My father always said, 'Real estate, you can't lose in real estate' ... you know, oddly enough you can."
Last Saturday, auctioneers worked up bids for his 80-acre retreat in the high desert of Rodeo, N.M. With a private airstrip and hangar, it's a slice of paradise, and it's all up for grabs.
"Everything that you see, from the real estate, the house, the automobiles, artwork, furniture, the entire ball of wax," McAfee told ABC News.
Raising the stakes for McAfee, it's an absolute auction: The highest bid wins, no matter how low it is. "It means if only one person shows up and they bid fifty cents, that's the amount of money I get," he said.
McAfee's net worth dropped from within the ballpark of $100 million to less than $10 million, he told ABC News. But instead of feeling a sense of loss, he says he feels free.
"I feel a sense of freedom," he said. "People think that it's a joy to own things. But it really isn't."
McAfee has sold his private twin-engine plane, beachfront property in Hawaii and a Colorado mansion in the shadow of Pike's Peak. His posh New Mexico getaway is the last property to hit the auction block.
"At one point, I had five houses in five different locations and it's impractical, it's almost insane to have that much real estate," he conceded. "You can only be in one place at a time."
McAfee: 'We Are the Ultimate Consumer Society'
McAfee admits that he got caught up in the culture of consumption."We are the ultimate consumer society," he said. "If you succeed within that culture, then you're simply more bonded to it. You feel like, 'Yes, I've got all this money, the ability to get things' ... and so you just do it. People buy yachts, they buy jets, they buy multiple homes."
McAfee himself indulged his whims and passions, spending millions to promote the sport of aero-trekking: tiny motorized kites that enthusiasts fly to explore the remotest corners of the country.
He built an aero-trekking playground in the Rodeo desert, which was auctioned off for $405,000 -- along with the vintage airstream trailers where his aero-trekking friends, known as "the sky gypsies," would stay, as well as his own customized camper, once owned by Howard Hughes.
More @ abcn.ws/qFgB7Q
Saturday, August 27, 2011
Simple Security for Wireless
In early August, at the Def Con conference -- a major annual gathering of computer hackers -- someone apparently hacked into many of the attendees' cell phones, in what may have been the first successful breach of a 4G cellular network. If early reports are correct, the incident was a man-in-the-middle (MITM) attack, so called because the attacker interposes himself between two other wireless devices.
Coincidentally, a week later, at the 20th Usenix Security Symposium, MIT researchers presented the first security scheme that can automatically create connections between wireless devices and still defend against MITM attacks. Previously, thwarting the attacks required password protection or some additional communication mechanism, such as an infrared transmitter.
Showcasing novel ways to breach security is something of a tradition at Def Con. In previous years, MITM attacks had been launched against attendees' Wi-Fi devices; indeed, the MIT researchers demonstrated the effectiveness of their new scheme on a Wi-Fi network. But in principle, MITM attacks can target any type of wireless connection, not only between devices (phones or laptops) and base stations (cell towers or Wi-Fi routers), but also between a phone and a wireless headset, a medical implant and a wrist-mounted monitor, or a computer and a wireless speaker system.
Key change
Ordinarily, when two wireless devices establish a secure connection, they swap cryptographic keys -- the unique codes they use to encrypt their transmissions. In an MITM attack, the attacker tries to broadcast his own key at the exact moment that the key swap takes place. If he's successful, one or both of the devices will mistake him for the other, and he will be able to intercept their transmissions.
Password protection can thwart MITM attacks, assuming the attacker doesn't know the password. But that's not always a safe assumption. At a hotel or airport that offers Wi-Fi, for instance, all authorized users are generally given the same password, which means that any one of them could launch an MITM attack against the others. Moreover, many casual computer users find it so complicated to set up home Wi-Fi networks that they don't bother to protect them; when they do, they often select passwords that are too simple to provide much security. That's led to the marketing of Wi-Fi transmitters with push-button configuration: To establish a secure link, you simply push a button on top of the transmitter and a corresponding button (or virtual button) on your wireless device. But such systems remain vulnerable to MITM attacks.
"None of these solutions are quite satisfactory," says Nickolai Zeldovich, the Douglas Ross (1954) Career Development Assistant Professor of Software Technology, who developed the new security scheme together with Dina Katabi, the Class of 1947 Career Development Associate Professor of Computer Science and Engineering, as well as postdoc Nabeel Ahmed and graduate student Shyam Gollakota, all of MIT's Department of Electrical Engineering and Computer Science. "The cool thing about this work is that it takes some insight from somewhat of a different field, from wireless communication -- actually, fairly low-level details about what can happen in terms of wireless signals -- and observes that, hey, if you assume some of these properties about wireless networks, you can actually get stronger guarantees."
More @ bit.ly/qfshwd
Coincidentally, a week later, at the 20th Usenix Security Symposium, MIT researchers presented the first security scheme that can automatically create connections between wireless devices and still defend against MITM attacks. Previously, thwarting the attacks required password protection or some additional communication mechanism, such as an infrared transmitter.
Showcasing novel ways to breach security is something of a tradition at Def Con. In previous years, MITM attacks had been launched against attendees' Wi-Fi devices; indeed, the MIT researchers demonstrated the effectiveness of their new scheme on a Wi-Fi network. But in principle, MITM attacks can target any type of wireless connection, not only between devices (phones or laptops) and base stations (cell towers or Wi-Fi routers), but also between a phone and a wireless headset, a medical implant and a wrist-mounted monitor, or a computer and a wireless speaker system.
Key change
Ordinarily, when two wireless devices establish a secure connection, they swap cryptographic keys -- the unique codes they use to encrypt their transmissions. In an MITM attack, the attacker tries to broadcast his own key at the exact moment that the key swap takes place. If he's successful, one or both of the devices will mistake him for the other, and he will be able to intercept their transmissions.
Password protection can thwart MITM attacks, assuming the attacker doesn't know the password. But that's not always a safe assumption. At a hotel or airport that offers Wi-Fi, for instance, all authorized users are generally given the same password, which means that any one of them could launch an MITM attack against the others. Moreover, many casual computer users find it so complicated to set up home Wi-Fi networks that they don't bother to protect them; when they do, they often select passwords that are too simple to provide much security. That's led to the marketing of Wi-Fi transmitters with push-button configuration: To establish a secure link, you simply push a button on top of the transmitter and a corresponding button (or virtual button) on your wireless device. But such systems remain vulnerable to MITM attacks.
"None of these solutions are quite satisfactory," says Nickolai Zeldovich, the Douglas Ross (1954) Career Development Assistant Professor of Software Technology, who developed the new security scheme together with Dina Katabi, the Class of 1947 Career Development Associate Professor of Computer Science and Engineering, as well as postdoc Nabeel Ahmed and graduate student Shyam Gollakota, all of MIT's Department of Electrical Engineering and Computer Science. "The cool thing about this work is that it takes some insight from somewhat of a different field, from wireless communication -- actually, fairly low-level details about what can happen in terms of wireless signals -- and observes that, hey, if you assume some of these properties about wireless networks, you can actually get stronger guarantees."
More @ bit.ly/qfshwd
Friday, August 26, 2011
Sunday, August 21, 2011
Linux Journal goes 100% digital
What is the last print issue I should expect to see?The last issue printed was the August 2011 issue.
I have a U.S. print subscription. What happens?As long as we have your email address, you don’t need to do anything. If you are concerned that we do not have your email address, or if you prefer to receive notifications at another email address, please visit linuxjournal.com/updateaccount. On the 1st of every month, you will receive a notification via email to download the latest issue of Linux Journal.
I have an international print subscription. What happens?As long as we have your email address, you don’t need to do anything. If you are concerned that we do not have your email address, or if you prefer to receive notifications at another email address, please visit linuxjournal.com/updateaccount. Your current subscription term will be extended based on the remaining value of your subscription. For example, if your current remaining subscription value is $52.13 USD (say you paid $69.50 and received 3 copies), the term will be extended by 21 issues based on the issue value of $2.46.
I have a print + digital (“combo”) subscription. What happens?You don’t need to do anything; we already have your email address. Your current subscription term will be extended based on the remaining value of your subscription. For example, if your current remaining subscription value is $29.63 USD (say you paid $39.50 and received 3 copies), the term will be extended by 12 issues based on the issue value of $2.46.
I already have a digital-only subscription. Does this announcement affect me?
You don’t need to do anything, and you will continue to receive your digital subscription. However, if you would like to upgrade to the new, enhanced online digital edition from Texterity, simply visit linuxjournal.com/updateaccount. There is no additional charge for upgrading.
When will I see my first digital issue?Current subscribers can expect to see the September 2011 issue of Linux Journal in their e-mail inboxes on Friday, August 19, 2011. If for any reason you do not receive your copy by the end of that day, please e-mail gm@linuxjournal.com with your full name and postal code.
More @ bit.ly/pGjO48
I have a U.S. print subscription. What happens?As long as we have your email address, you don’t need to do anything. If you are concerned that we do not have your email address, or if you prefer to receive notifications at another email address, please visit linuxjournal.com/updateaccount. On the 1st of every month, you will receive a notification via email to download the latest issue of Linux Journal.
I have an international print subscription. What happens?As long as we have your email address, you don’t need to do anything. If you are concerned that we do not have your email address, or if you prefer to receive notifications at another email address, please visit linuxjournal.com/updateaccount. Your current subscription term will be extended based on the remaining value of your subscription. For example, if your current remaining subscription value is $52.13 USD (say you paid $69.50 and received 3 copies), the term will be extended by 21 issues based on the issue value of $2.46.
I have a print + digital (“combo”) subscription. What happens?You don’t need to do anything; we already have your email address. Your current subscription term will be extended based on the remaining value of your subscription. For example, if your current remaining subscription value is $29.63 USD (say you paid $39.50 and received 3 copies), the term will be extended by 12 issues based on the issue value of $2.46.
I already have a digital-only subscription. Does this announcement affect me?
You don’t need to do anything, and you will continue to receive your digital subscription. However, if you would like to upgrade to the new, enhanced online digital edition from Texterity, simply visit linuxjournal.com/updateaccount. There is no additional charge for upgrading.
When will I see my first digital issue?Current subscribers can expect to see the September 2011 issue of Linux Journal in their e-mail inboxes on Friday, August 19, 2011. If for any reason you do not receive your copy by the end of that day, please e-mail gm@linuxjournal.com with your full name and postal code.
More @ bit.ly/pGjO48
How Google+ Is Like Twitter—but Not in a Good Way
Tech blogger Robert Scoble, the king of the early-adopter crowd, has posted some thoughts about what he likes and doesn’t like about using Google+, and some of his points hit home with me as well. And the more I thought about the new social network and the things it doesn’t do very well, the more similar it seemed to the issues that have also been dogging Twitter for some time. Like Twitter, the Web giant has to figure out how to solve some pretty challenging problems—including the "noisy stream" issue, the problems of search and discovery, and, of course, how to keep people from going away and never coming back.
As more than one person (including Scoble himself) has noted, he isn’t exactly the average user of social tools. As someone with hundreds of thousands of followers, who jumps on every new Web or social tool that comes along—in some cases dominating those new services to the point where they become almost unusable, as some found with FriendFeed—Scoble is definitely an "edge case." But at the same time, that makes him a little like the canary in a coal mine: He can highlight problems that may only become obvious for others much later.
More @ buswk.co/rnIEuC
As more than one person (including Scoble himself) has noted, he isn’t exactly the average user of social tools. As someone with hundreds of thousands of followers, who jumps on every new Web or social tool that comes along—in some cases dominating those new services to the point where they become almost unusable, as some found with FriendFeed—Scoble is definitely an "edge case." But at the same time, that makes him a little like the canary in a coal mine: He can highlight problems that may only become obvious for others much later.
More @ buswk.co/rnIEuC
Subscribe to:
Posts (Atom)













