Categories
Aside Links

Meet USBee, the malware that uses USB drives to covertly jump airgaps

Meet USBee, the malware that uses USB drives to covertly jump airgaps:

The software works on just about any storage device that’s compliant with the USB 2.0 specification. Some USB devices such as certain types of cameras that don’t receive a stream of bits from the infected computer, aren’t suitable. USBee transmits data at about 80 bytes per second, fast enough to pilfer a 4096-bit decryption key in less than 10 seconds. USBee offers ranges of about nine feet when data is beamed over a small thumb drive to as much as 26 feet when the USB device has a short cable, which acts as an antenna that extends the signal. USBee transmits data through electromagnetic signals, which are read by a GNU-radio-powered receiver and demodulator. As a result, an already-compromised computer can leak sensitive data even when it has no Internet or network connectivity, no speakers, and when both Wi-Fi and Bluetooth have been disabled. The following video demonstrates USBee in the lab:

While this is still of limited value because you need to infect the airgapped computer in the first place, it’ll only take a while until this exfiltration method is weaponized. Airgaps have long been seen as a key way of keeping highly sensitive data secure but researchers working inside and outside of government keep revealing all the ways in which data can be quietly extracted from such systems. Their successes should give pause to anyone who is concerned about computer security, generally, to say nothing of those interested in the security of government and corporate systems.

Categories
Links

WhatsApp to start sharing user data with Facebook

WhatsApp to start sharing user data with Facebook:

WhatsApp says that sharing this information means Facebook can offer better friend suggestions by mapping users’ social connections across the two services, and deliver more relevant ads on the social network. Additional analytics data from WhatsApp will also be shared to track usage metrics and fight spam.

WhatsApp now provides about the best security of any chat application that is available. Sadly, the privacy aspects of the company are now being weakened as Facebook more fully integrates WhatsApp into the broader range of Facebook companies.

Categories
Links

McDonald’s recalls Happy Meal fitness trackers after they injure kids

McDonald’s recalls Happy Meal fitness trackers after they injure kids:

The wristband toys given away in the fast food chain’s signature Happy Meals were intended to help get kids moving. Instead, the toys have gotten company officials racing to issue a recall after the devices were found to burn and irritate kids’ skin. So far, there have been 70 reports of injuries from the colorful gadgets, including seven reports of blistering burns.

Even dedicated fitness tracker companies have problems with their trackers. Fitbit, as an example, had to recall their fitness trackers a few years back because of manufacturing problems.

So while we should wonder what happened in this instance, I’d bet that it’s a combination of the low cost of the fitness trackers linked with relatively little testing to ensure there wasn’t nickle or other allergetic materials.

Categories
Links

The Million Dollar Dissident: NSO Group’s iPhone Zero-Days used against a UAE Human Rights Defender – The Citizen Lab

The place I work at did some stuff.

But the major takeaway for most people should probably be this:

IF YOU ARE ON AN iOS DEVICE, UPDATE YOUR PHONE OR iPAD RIGHT NOW

  1. Open Settings >> General >> Software Update
  2. Tap Download and Install. If a message asks to temporarily remove apps because iOS needs more space for the update, tap Continue or Cancel.

The vulnerabilities we identified in iOS are incredibly severe. Please update your device immediately.

Categories
Links

Turns Out You Can’t Trust Russian Hackers Anymore

Turns Out You Can’t Trust Russian Hackers Anymore :

Navalny denies receiving funding from Soros and says he has had no support from Yandex. Laura Silber, a spokesperson for Open Society, said the foundation has never supported Navalny and that the edited documents posted by Cyber Berkut amounted to a libelous claim.

The Kremlin, Navalny wrote in an email to Foreign Policy, “really likes that type of tactics: posting fake documents among real hacked documents.” The goal, he wrote, is to create a mess for the opposition.

“At the end of the day everyone will understand — documents are fake, but it will be a two-week-long discussion: ‘Is [the] opposition and Navalny in particular using Soros’ money?’,” Navalny wrote.

The Kremlin hates George Soros because Open Society, his marquee philanthropy, focuses on boosting democracy in the former Soviet bloc and elsewhere. Silber says Open Society “supports human rights, democratic practice, and the rule of law in more than 100 countries around the world.”

We can’t fully believe all the documents that are stolen, and then subsequently posted online by Russian-affiliated groups with an agenda of discrediting certain parties?

Shocking.

Categories
Links

BlackBerry’s new round of lawsuits targets BLU—and Android

BlackBerry’s new round of lawsuits targets BLU—and Android:

The new lawsuits also suggest that BlackBerry has patents it believes describe Android features, so don’t be surprised if more Android phones are in the crosshairs soon. One of the two cases filed last week accuses user-interface features that are more about Android than they are about BLU. A small manufacturer like BLU could make for a good “test case” against a maker of Android phones.

Great. We’re back to the patent-suit wars that more or less wrapped up between mobile phone companies a few years back.

It’s going to be pretty amazing to watch Blackberry sue firms which have adopted the Android OS…just like Blackberry itself. I wonder if some other trolls will come out from their bridge and fire reciprocal suits against Blackberry.

Categories
Links

Bait and Switch: The Failure of Facebook Advertising — An OSINT Investigation

Facebook is preventing their users from blocking ads while, at the same time, promoting links that are (at best) linked to fraudulent websites and (at worst) ultimately serving up some kind of malware. But those of use who insist on blocking ads are somehow being ‘irresponsible’ in our activities?

Categories
Links

VR Needs to Be Pleasurable for Women Before VR Porn Can Be

VR Needs to Be Pleasurable for Women Before VR Porn Can Be:

The study measured body movement, with participants playing a Rift game for 15 minutes and researchers recording the time it took for someone to feel nauseous. Of the 35 percent of subjects who felt unwell within ten minutes, 70 percent were women. It’s a major design flaw, says Stoffregen.

“Engineers, the people who design VR systems, tend to think about motion sickness in terms of the technology—resolution, frame rate, things like that—and in terms of the sensory systems that the technology was designed to stimulate, usually the eyes,” he told me. “That’s the origin of the impetus to focus on things like visual field size. But there’s no science behind it.”

Instead, Stoffregen believes that “susceptibility is related to the degree to which people can stabilise their own bodies.” In other words, on the whole, men are able to stabilise their bodies better than women because they have higher centres of gravity, larger feet, and are heavier. This, Stoffregen says, is why men are also less susceptible to more traditional forms of motion sickness like seasickness.

“It’s not surprising that men and women respond differently in a postural sense to unfamiliar motion situations,” he said. “A person using VR must control and stabilize their own body. The more compelling the VR, the more likely it is that the person will try to stabilize the body relative to the virtual world. But that is a mistake; the body is not in the virtual world, and we need to stabilize it relative to the physical world, gravity etc.”

Other researchers have also found gender differences in the VR experience. A study from Microsoft’s danah boyd (who chooses not to capitalize her name) also found that there’s a difference in how men and women experience the various methods VR producers use to suggest distance. Motion parallax, which uses perspective to suggest distance, is processed far better by men than women; shape-from-shading, which uses light to alter the way you perceive objects, is processed better by women. Most systems use motion parallax—mostly because it’s easier to program—despite the fact it can make the VR experience far less pleasurable or immersive for women.

Setting aside Vice’s focus on pornography, I found the suggested rationales for why VR’s unpleasant effects are unequally experienced along gender lines fascinating. Developers should be striving to increase equality in their development studios, not just because it’s the right thing to do, but because not doing so could inhibit the adoption of VR applications as a result of insufficiently diverse testing groups.

Categories
Links

Good cooks are quitting the kitchen, and that’s bad news for your favourite restaurant

Good cooks are quitting the kitchen, and that’s bad news for your favourite restaurant:

For those making $14 an hour, we’re not even talking about fresh-out-of-school, no-experience, paying-their-dues cooks, who often swing $125 for a 12-hour shift that works out to less than Ontario’s legal minimum wage of $11.25 per hour. No, we’re talking about people who’ve spent years honing their skills, demonstrating their loyalty and work ethic in an industry where “passion” is used as a marker of dedication, and the perceived lack of it as a tool for dismissing any cook who complains about conditions or compensation. One chef I spoke with referred to this as a “crime of passion.”

I have a family member in the food industry, and it staggers me whenever I learn how much he takes home in a year after working 60 hour weeks, 51 weeks a year.

Categories
Humour Links

Toronto company is hiring a Pokemon Go expert

We truly live in the end of days: Toronto company is hiring a Pokemon Go expert.