close
The Wayback Machine - https://web.archive.org/web/20130820031244/http://it.slashdot.org/
 



Forgot your password?

typodupeerror

Find out the latest on data centers with SlashDataCenter.

Government

Why the NSA Can't Replace 90% of Its System Administrators 133

Posted by Unknown Lamer
from the plus-they'll-sink-your-oil-tankers dept.
An anonymous reader writes "Curious about the recently purposed NSA cuts, Courtney Nash explores a few myths about systems automation 'In the aftermath of Edward Snowden's revelations about NSA's domestic surveillance activities, the NSA has recently announced that they plan to get rid of 90% of their system administrators via software automation in order to "improve security." So far, I've mostly seen this piece of news reported and commented on straightforwardly. But it simply doesn't add up. Either the NSA has a monumental (yet not necessarily surprising) level of bureaucratic bloat that they could feasibly cut that amount of staff regardless of automation, or they are simply going to be less effective once they've reduced their staff.'"
Security

"Jekyll" Test Attack Sneaks Through Apple App Store, Wreaks Havoc 172

Posted by samzenpus
from the wolf-in-sheep's-clothing dept.
An anonymous reader writes "A malware test app sneaked through Apple's review process disguised as a harmless app, and then re-assembled itself into an aggressive attacker even while running inside the iOS 'sandbox' designed to isolate apps and data from each other. The app, dubbed Jekyll, was helped by Apple's review process. The malware designers, a research team from Georgia Institute of Technology's Information Security Center, were able to monitor their app during the review: they discovered Apple ran the app for only a few seconds, before ultimately approving it. That wasn't anywhere near long enough to discover Jekyll's deceitful nature."
The Almighty Buck

McAfee Regrets "Flawed" Trillion Dollar Cyber Crime Claims 37

Posted by samzenpus
from the price-of-things dept.
Techy77 writes "McAfee's chief technology officer Mike Fey has admitted that he regrets his own company's estimates, which once pinned global losses from cyber crime at more than $1 trillion. From the article: 'A more recent report commissioned by the security company, and released last month, reduced those estimates to as low as $US300 billion globally, but specifically noted the difficulty of determining exactly how much companies, governments and individuals could lose if subject to an attack. “It’s very difficult to put a dollar figure on it,” Mr Fey said. “When you meet an engineer that has spent a good chunk of his life working on some innovation and it’s stolen overnight, you get a good feeling for what [intellectual property] loss means. It is the shift in a moment’s instance from an innovative company set strategically, to loss. It becomes difficult for that company to invest in innovation."'"
Social Networks

Instagram "Likes" Worth More Than Stolen Credit Cards 100

Posted by samzenpus
from the with-a-little-help-from-my-bots dept.
Barence writes "In the world of online fraud, a fake fan on Instagram can be worth five times more than a stolen credit card number. In a sign of the growing value of social network 'likes', the Zeus virus has been modified to create bogus Instagram 'likes' that can be used to generate buzz for a company or individual, according to cyber experts at RSA, the security division of EMC. These fake 'likes' are sold in batches of 1,000 on hacker forums, where cybercriminals also flog credit card numbers and other information stolen from PCs. According to RSA, 1,000 Instagram 'followers' can be bought for $15 and 1,000 Instagram 'likes' go for $30, whereas 1,000 credit card numbers cost as little as $6."
Facebook

Security Researcher Makes His Point By Hacking Into Zuckerberg's Facebook Page 241

Posted by samzenpus
from the do-you-see-it-now? dept.
Eugriped3z writes "Whitehat Palestinian hacker, Kahlil Shreateh, submitted a bug report to Facebook's Whitehat bug reporting page, not once but twice. After it was ignored the first time and denied outright on the second occasion (which included links to an example as proof), he hacked Mark Zuckerberg's personal timeline, leaving both an explanation and an apology. From the article: 'In less than a minute, Shreateh's Facebook account was suspended and he was contacted by a Facebook security engineer requesting all the details of the exploit. "Unfortunately your report to our Whitehat system did not have enough technical information for us to take action on it," the engineer wrote in an email. "We cannot respond to reports which do not contain enough detail to allow us to reproduce an issue." Facebook has a policy that it will pay a minimum $500 bounty for any security flaws that a hacker finds. However, the company has refused to pay Shreateh for discovering the vulnerability because his actions violated Facebook's Terms of Service.'"
The Internet

Researchers Release Tool That Can Scan the Entire Internet In Under an Hour 94

Posted by samzenpus
from the scan-me dept.
dstates writes "A team of researchers at the University of Michigan has released Zmap, a tool that allows an ordinary server to scan every address on the Internet in just 45 minutes. This is a task that used to take months, but now is accessible to anyone with a fast internet connection. In their announcement Friday , at the Usenix security conference in Washington they provide interesting examples tracking HTTPS deployment over time, the effects of Hurricane Sandy on Internet infrastructure, but also rapid identification of vulnerable hosts for security exploits. A Washington Post Blog discussing the work shows examples of the rate with which of computers on the Internet have been patched to fix Universal Plug and Play, 'Debian weak key' and 'factorable RSA keys' vulnerabilities. Unfortunately, in each case it takes years to deploy patches and in the case of UPnP devices, they found 2.56 million (16.7 percent) devices on the Internet had not yet upgraded years after the vulnerability had been described."
Privacy

Partner of Guardian's Snowden Reporter Detained Under Terrorism Act 405

Posted by samzenpus
from the papers-please dept.
hydrofix writes "The partner of the Guardian journalist Glenn Greenwald, who has written a series of stories revealing mass surveillance programs by the National Security Agency (NSA), was held for almost nine hours on Sunday by UK authorities as he passed through the Heathrow airport on his way home to Rio de Janeiro. David Miranda was stopped by officers and informed that he would be questioned under the Terrorism Act 2000. The 28-year-old was held for nine hours, the maximum the law allows before officers must release or formally arrest the individual. According to official figures, most examinations last under an hour, and only one in 2,000 people detained are kept for more than six hours. Miranda was released without charge, but officials confiscated electronics including his mobile phone, laptop, camera, memory sticks, DVDs and games consoles. 'This is a profound attack on press freedoms [...] to detain my partner for a full nine hours while denying him a lawyer, and then seize large amounts of his possessions, is clearly intended to send a message of intimidation to those of us who have been reporting on the NSA and GCHQ,' Greenwald commented."
Businesses

Experiences and Realities of an Homesourced IT Worker 107

Posted by samzenpus
from the remember-to-wear-pants dept.
toygeek writes "Some companies have small corporate offices with a few desks and some basic staff, and the balance of their staff works from home. I have worked for two companies that have home-sourced their staffing. I wish to take you through my journey in working from home in the IT world and share some facts that I've accumulated along the way."
Encryption

Lavabit.com Owner: 'I Could Be Arrested' For Resisting Surveillance Order 248

Posted by timothy
from the how-can-you-dare-to-say-that dept.
Zak3056 writes "NBC News is reporting that 'The owner of an encrypted email service used by ex-NSA contractor Edward Snowden said he has been threatened with criminal charges for refusing to comply with a secret surveillance order to turn over information about his customers. "I could be arrested for this action," Ladar Levison told NBC News about his decision to shut down his company, Lavabit LLC, in protest over a secret court order he had received from a federal court that is overseeing the investigation into Snowden.''"
Encryption

Google To Encrypt Cloud Storage Data By Default 215

Posted by timothy
from the praise-be-to-google dept.
jfruh writes "Worries about snooping are now a permanent part of our computing landscape, but Google is attempting to ameliorate those fears by encrypting all data on its Google Cloud Storage service by default. Data is encrypted with 128-bit AES, and you can manage the keys yourself or have Google do it for you. A Google spokesperson said that the company "does not provide encryption keys to any government."" (Also at SlashCloud.)
Bitcoin

Google Admits Bitcoin Thieves Exploited Android Crypto PRNG Flaw 183

Posted by timothy
from the oopsie dept.
rjmarvin writes "The theft of 55 Bitcoins, or about $5,720, through Android wallet apps last week was made possible because of flaws in Android's Java and OpenSSL crypto PRNG, Google revealed in a blog post. In the wake of a Bitcoin security advisory and a Symantec vulnerability report, the Android Developers Blog admitted the reason the thieves were able to pilfer their wallet apps. The flaws are already, or in the process of being repaired."
The Media

Washington Post Hacked, a Day After New York Times 98

Posted by timothy
from the paper-of-record dept.
barlevg writes "A day after the New York Times was brought down by a cyber attack, the Washington Post reported being hacked, with various news stories being redirected to the website of the Syrian Electronic Army. It's been speculated that this is the work of the same hacking syndicate that compromised both news organizations last year."
Social Networks

Twitter Eyes Signatures To Kill Fake Followers 52

Posted by timothy
from the if-that-is-your-real-name dept.
mask.of.sanity writes "Researchers have developed a signature system being examined by Twitter that hold promise to cut down on the amount of fake accounts used to deliver spam and malware. The signatures were developed during a study into the semi-underground market of fake accounts and was subsequently used by Twitter to eliminate an impressive 95 percent of several million accounts identified in the research. It applied elements like account names, the timing of the account creation, and browser identifiers to identify fake accounts. The 10-month study found that the creation of fake accounts at its peak represented 60 percent of all new accounts. (Paper here.)"
Twitter

Researchers Buy Twitter Bots To Fight Twitter Spam 45

Posted by samzenpus
from the fight-fire-with-fire dept.
tsu doh nimh writes "The success of social networking community Twitter has given rise to an entire shadow economy that peddles dummy Twitter accounts by the thousands, primarily to spammers, scammers and malware purveyors. But new research on identifying bogus accounts has helped Twitter to drastically deplete the stockpile of existing accounts for sale, and holds the promise of driving up costs for both vendors of these shady services and their customers. Krebsonsecurity.com writes about a paper (PDF) being released today at the USENIX conference that details how researchers spent almost a year and $5,000 buying up accounts from 27 twitter account merchants, and then built templates to help Twitter detect accounts sold by these merchants — all with the aim of getting more of these bot accounts shut down before they can be used to spam legitimate Twitter users. The story goes into great detail on the lengths to which these account merchants will go to evade Twitter's anti-bot security measures."
Encryption

MIT Research: Encryption Less Secure Than We Thought 156

Posted by Soulskill
from the but-still-pretty-darn-secure dept.
A group of researchers from MIT and the University of Ireland has presented a paper (PDF) showing that one of the most important assumptions behind cryptographic security is wrong. As a result, certain encryption-breaking methods will work better than previously thought. "The problem, Médard explains, is that information-theoretic analyses of secure systems have generally used the wrong notion of entropy. They relied on so-called Shannon entropy, named after the founder of information theory, Claude Shannon, who taught at MIT from 1956 to 1978. Shannon entropy is based on the average probability that a given string of bits will occur in a particular type of digital file. In a general-purpose communications system, that’s the right type of entropy to use, because the characteristics of the data traffic will quickly converge to the statistical averages. ... But in cryptography, the real concern isn't with the average case but with the worst case. A codebreaker needs only one reliable correlation between the encrypted and unencrypted versions of a file in order to begin to deduce further correlations. ... In the years since Shannon’s paper, information theorists have developed other notions of entropy, some of which give greater weight to improbable outcomes. Those, it turns out, offer a more accurate picture of the problem of codebreaking. When Médard, Duffy and their students used these alternate measures of entropy, they found that slight deviations from perfect uniformity in source files, which seemed trivial in the light of Shannon entropy, suddenly loomed much larger. The upshot is that a computer turned loose to simply guess correlations between the encrypted and unencrypted versions of a file would make headway much faster than previously expected. 'It’s still exponentially hard, but it’s exponentially easier than we thought,' Duffy says."

Keep your boss's boss off your boss's back.

Working...