Categories
Links

Packets of Death

cleverhacks:

very nice detective work, in which we discover that a single ill-favored packet can completely kill certain Intel gigabit NICs (to the point that a power cycle is required to resurrect them). Excellent writeup (and I discovered a new tool: open source packet generation suite Ostinato, which aims to be “wireshark in reverse”).

The significance, via Slashdot: “With a modified HTTP server configured to generate the data at byte value (based on headers, host, etc) you could easily configure an HTTP 200 response to contain the packet of death and kill client machines behind firewalls!”

Categories
Links

South Korea to Ban Profanity and Porn from Teens’ Smartphones?

The supposed ban is meant to, in part, crack-down on cyberbullying. To be clear, such bullying is serious, but introducing security deficits into smartphones – for the children! – really isn’t the way to solve this social problem. You don’t solve social ills by turning to technological filters and blocks. Especially not when trying to get between a teenager and porn.

Categories
Links Writing

Casey Johnston!: I have this seminar I’m running for free for college students and I’m…

caseyj:

I have this seminar I’m running for free for college students and I’m going to show them this picture before we start. It’s a picture of someone graduating from college. You can’t tell, but you can guess that they’re probably $150,000 in debt. Written on the top of their mortarboard with masking tape it says, “Hire me.” The thing about the picture that’s pathetic, beyond the notion that you need to spam the audience at graduation with a note saying you’re looking for a job, is that you went $150,000 in debt and spent four years of your life so someone else could pick you. That’s ridiculous. It really makes me sad to see that.

While I understand what Seth Godin is suggesting, I also think that it’s largely reflective of his incredibly privileged position. When people are leaving schools with that amount of debt, with knowledge that they want to start a family and not suffer (total) financial ruin by starting something and failing, then those individuals may quite reasonably want full-time regular employment.

Godin’s most common response is that ‘such employment doesn’t really exist anymore – so adapt!’ While it’s a great response for some people who are willing to take on heightened risks in their lives it isn’t one that ought to be imposed on all individuals. Moreover, the thought that it’s “ridiculous” to want to be picked and work at a meaningful job and launch a career with a business that is compatible with your training and expertise shouldn’t make anyone sad. Instead, what should be “sad” is that such aspirations are less and less likely to be realized as companies abandon long-term commitment to employees and instead harden their ‘flexible’ hiring strategies that facilitate profits at the expense of human life.

Categories
Links

Yale Suing Former Students Shows Crisis in Loans to Poor

infoneer-pulse:

infoneer-pulse:

Needy U.S. borrowers are defaulting on almost $1 billion in federal student loans earmarked for the poor, leaving schools such as Yale University and the University of Pennsylvania with little choice except to sue their graduates.

The record defaults on federal Perkins loans may jeopardize the prospects of current students since they are part of a revolving fund that colleges give to students who show extraordinary financial hardship.

Yale, Penn and George Washington University have all sued former students over nonpayment, court records show. While no one tracks the number of lawsuits, students defaulted on $964 million in Perkins loans in the year ended June 2011, 20 percent more than five years earlier, government data show. Unlike most student loans — distributed and collected by the federal government — Perkins loans are administered by colleges, which use repayment money to lend to other poor students.

» via Bloomberg

The default situation is only going to get worse and worse, especially for those that tried to hide from the US recession by staying in school and taking on educational debt.

Yale Suing Former Students Shows Crisis in Loans to Poor

Categories
Links Writing

Banking Trojan Ships With Its Own Certificate

This is all kinds of badness, and speaks to malware vendors becoming increasingly sophisticated in how they are targeting low hanging fruit (i.e. random users). In essence, the attack involved getting a certificate issued and then using it to create valid digital signatures for .pdf invoice documents. Once individuals opened the invoices the malware associated with the .pdf would burrow into the OS and act as a key logger that targeted banking information.

Unfortunately, I’ve not yet seen a media article discuss the mediocre effectiveness of revoking the certificate used to sign the .pdf. The OCSP protocol is incredibly susceptible to being defeated, especially if malware already resides on the target’s computer or a point in between the target and the revocation server is controlled by the attacker (possible by setting a compromised computer to proxy traffic to a host controlled by the attacker). So, while while the cert has been revoked, this actions does not necessarily stop the malware from functioning, but just reduces the prospective attack surface. Moreover, if browser/operating system CA stores are not updated – again, possible if the attacker already controls the host – then the same attacker can convince the browser or OS to continue trusting an expired certificate.

Categories
Links Writing

EU citizen warned not to use US cloud services over spying fears

shonelikethesun:

What the title says, basically. I had missed this.

The warning should be heard by non-EU citizen too, with the Cloud, privacy is fucking dead. And what’s sadder is that 90% of people simply don’t care.
Unless it makes more probable for your significant other to see your transsexual porn browser history…

The EU Report is well worth a full read (available here in .pdf). Things to keep in mind that aren’t all that being well discussed:

  • you know about this report – media is covering it – because of the tireless efforts of Caspar Bowden, one of the authors and a noted global privacy advocate. It was out for months before it hit the media.
  • everyone is focused on US intelligence (good) but missing the significance of the FISAAA amendments: it’s not just that you can be spied on. It’s that the spying does not have to happen for national security reasons. No, it’s sufficient to conduct surveillance for political (read: espionage) reasons.
  • a huge aspect of the report – which isn’t touched on, even in the European media that much – is its call for the European Parliament to given EUROPOL and ENISA a direct mandate.

The second point is particularly important for non-Europeans. While it’s a lesser spoken about part of the intelligence world, spooks are routinely engaged in industrial espionage on the grounds that such acts assist the nation-state’s finances. This can include the theft of foreign corporations’ information, or (in extreme cases) the deletion of the same information. It seems that FISAAA’s amendments would only permit the former, and not the latter. However, as a result of these amendments corporations should be more wary of outsourcing their document storage to US-based cloud services, content creation to US hosts and online services, or communications systems to (you guessed it!) American firms. Placing such data in the hands of the Americans is rife with potential economic harms and, no matter how much you like Dropbox, Google, or other cloud provider, they’re all likely to turn on you if the NSA comes knocking.

Source: EU citizen warned not to use US cloud services over spying fears

Categories
Humour Links

Cat Found With Malware Strapped to Collar

No, really, no joke: a Japanese hacker is playing with the authorities. The latest gambit involved attaching an SD card with malware code to a cat’s collar. Authorities still have no clue who designed the software or who the individual(s) is/are.

Categories
Links Writing

Should Microsoft Be Targeted for a Truth in Adverting Campaign?

So, the Microsoft 64GB Surface Pro will only have 23GB of usable storage at launch. This is, to be blunt, absurd. Consumers are entirely used to variations between the storage that manufacturers say will be available versus what actually is available for use, but in this case we’re talking about less than 50% of the advertised storage actually being available. Microsoft is saying that removing the recovery partition will alleviate some of this storage use, but that’s immaterial: few consumers will do this, or feel comfortable doing so. As a result, they’re going to generally have devices that have less than half of the market storage.

While Apple – and, to an extent, Google – comes under fire for announcing hardware specs and then not meeting them because of OS storage consumption, neither company has ever had such deceptive claims as Microsoft’s regarding the Surface Pro. I can entirely appreciate that the newest Microsoft OS plus applications consumes a huge amount of space. I’m OK with that. But, given this consumption, the 64GB surface shouldn’t ever be marketed (or even suggested as being) as a 64GB device; the device should be presented as being closer to the actual storage available. Don’t get me wrong, all OSes take room. But, as far as I know, no OS plus application suite has ever consumed this amount of space in competing product offerings.

Categories
Links Writing

A Poignant Comment on Deleting Email

For the past two months I’ve been trying to figure out what to say about something Peter Fleischer, Google’s Global Privacy Counsel, wrote about his personal email retention and deletion policies. After talking about whether people should worry about “covering their tracks” from government snooping, he writes (emphasis added):

In the meantime, as users, we all have to decide if we want to keep thousands of old emails in our inboxes in the cloud.  It’s free and convenient to keep them.  Statistics published by some companies seem to confirm that the risks of governments seeking access to our data are extremely remote for “normal people”.  But the laws, like ECPA, that are meant to protect the privacy of our old emails are obsolete and full of holes.  The choice is yours:  keep or delete.  I’m a pragmatist, and I’m not paranoid, but personally, I’ve gotten in the habit of deleting almost all my daily emails, except for those that I’d want to keep for the future.  Like the rule at my tennis club:  sweep the clay after you play.

His comments struck me as being incredibly poignant when I first read them, and remain so today. I’ve stopped archiving email. I delete email (as best I can, given cloud data retention policies and all…) on a regular basis. Over the Christmas break I removed an aggregate of about 6 GB of mail that had just…accrued…in my various accounts over the past decade. In short, his post motivated me enough to spend the better part of 3 or 4 days sifting and sorting through my digital life. Ultimately I removed an awful lot of what was there.

At some point I hope to spend more time writing about, and thinking through, some of Peter’s points. At the moment, however, I’d just recommend you think about what it means when Google’s Global Privacy Counsel – the guy who is best able to go to the mat to protect the privacy of his own inbox – chooses to routinely delete his email from the cloud. If he takes that precaution, and he has the influence that he does, shouldn’t you at least consider following his lead?

Categories
Links

Globe and Mail runs loony screed against “hackers”, Aaron Swartz, logic – Boing Boing:

*Actually, there is a connection between Ahmed Al-Kabaz and Aaron Swartz. Ahmed investigated a powerful institution to see if it was competent and safe, and when he discovered that it wasn’t, he exposed it. Aaron believed passionately in the public’s right to information. Both were doing journalism. In decrying their actions, the Globe has in effect taken a position against the basic mission of journalism .

Hadn’t thought of this through a journalism angle; just through the angle of “cruddy editorializing based on ignorance of how technical systems function.”