Category Archives: Security

Comcast Migrating Customers To DNSSEC Resolvers

ctg1701 passes along this quote from a Comcast announcement: “Starting today we will begin migrating customers who have opted out of our Domain Helper service over to our production DNSSEC-validating servers. This will happen first in a selected part of our Virginia network, and will later expand to all markets in the following sixty days, at which point all of our customers who have opted out of Domain Helper will be migrated. After this has been completed, we will migrate the rest of our customers, which we anticipate will stretch into the early part of 2011.”

Read more of this story at Slashdot.

Link to the original site

Ubuntu Gets Multitouch Support

In June 2009 we had some very good news about the integration of multitouch events support inside the Linux kernel. Since then, many multitouch device drivers were developed, mostly in collaboration with LII-ENAC, to take advantage from this. All the work was kernel-based, and multitouch supports needs more components to be added in a stack to get multitouch working out of the box. Canonical got interested in providing the needed user experience for multitouch by developing a new gesture engine that recognizes the grammar of natural hand gestures and provide them upstream in the stack as new events.

Link to the original site

New Firefox iFrame Bug Bypasses URL Protections

Trailrunner7 writes “There is a newly discovered vulnerability in Mozilla’s flagship Firefox browser that could enable an attacker to trick a user into providing his login credentials for a given site by using an obfuscated URL. In most cases, Firefox will display an alert when a URL has been obfuscated, but by using an iFrame, an attacker can evade this layer of protection, possibly leading to a compromise of the user’s sensitive information.”

Read more of this story at Slashdot.

Link to the original site

Root Privileges Through Linux Kernel Bug

Lars T. writes “The H has a story about a Linux kernel bug that allows root level access. ‘According to a report written by Rafal Wojtczuk (PDF), a conceptual problem in the memory management area of Linux allows local attackers to execute code at root level. The Linux issue is caused by potential overlaps between the memory areas of the stack and shared memory segments.’ SUSE maintainer Andrea Arcangeli provided a fix for the problem in September 2004, but for unknown reasons this fix was not included in the Linux kernel. The bug is not related to the X Server bug found by Brad Spengler.” As the linked article notes: “SUSE itself has the fix and SUSE Linux Enterprise 9, 10 and 11 as well as openSUSE 11.1 through 11.3 do not exhibit this vulnerability.”

Read more of this story at Slashdot.

Link to the original site

1978 Cryptosystem Resists Quantum Attack

KentuckyFC writes “In 1978, the CalTech mathematician Robert McEliece developed a cryptosystem based on the (then) new idea of using asymmetric mathematical functions to create different keys for encrypting and decrypting information. The security of these systems relies on mathematical steps that are easy to make in one direction but hard to do in the other. Today, popular encryption systems such as the RSA algorithm use exactly this idea. But in 1994, the mathematician Peter Shor dreamt up a quantum algorithm that could factorise much faster than any classical counterpart and so can break these codes. As soon as the first decent-sized quantum computer is switched on, these codes will become breakable. Since then, cryptographers have been hunting for encryption systems that will be safe in the post quantum world. Now a group of mathematicians have shown that the McEliece encryption system is safe against attack by Shor’s algorithm and all other known quantum algorithms. That’s because it does not depend on factorisation but gets its security from another asymmetric conundrum known as the hidden subgroup problem which they show is immune to all known quantum attacks.”

Read more of this story at Slashdot.

Link to the original site

The Hidden Security Risk of Geotags

pickens writes “The NY Times reports that security experts and privacy advocates have begun warning consumers about the potential dangers of geotags, which are embedded in photos and videos taken with GPS-equipped smartphones and digital cameras. By looking at geotags of uploaded photos, ‘you can easily find out where people live, what kind of things they have in their house and also when they are going to be away,’ says one security expert. Because the location data is not visible to the casual viewer, the concern is that many people may not realize it is there; and they could be compromising their privacy, if not their safety, when they post geotagged media online.”

Read more of this story at Slashdot.

Link to the original site

Trojan-Infected Computer Linked To 2008 Spanair Crash

An anonymous reader writes “Two years ago, Spanair flight JK-5022 crashed shortly after takeoff in Madrid, killing 154 of its 172 passengers and crew. El Pais online newspaper reports that the ground computer responsible for triggering an alarm after three failures are reported in a plane failed to do so. The computer was infected with trojans (Google translation of Spanish original).”

Read more of this story at Slashdot.

Link to the original site

A Conference For Malware Writers

tsu doh nimh writes “There is a security conference being held in Mumbai later this year called MalCon, and the organizers say it’s the first ever conference dedicated to the ‘malcoder community.’ Brian Krebs interviewed one of them and got this gem: ‘Just like the concept of “ethical hacking” has helped organizations to see that hackers are not all that bad, it is time to accept that “ethical malcoding” is required to research, identify and mitigate newer malwares in a “proactive” way.’ Bruce Schneier is speaking at a sister MalCon event in Pune, India two days later, and he said he doesn’t agree with the organizer’s premise that more malware is needed to build better security tools.”

Read more of this story at Slashdot.

Link to the original site

Home WiFi Network Security Failings Exposed

An anonymous reader writes “The shocking state of home wireless (Wi-Fi) network security in the UK has been revealed by a life assistance company study. CPP used an ‘ethical hacker,’ Jason Hart, to test thousands of Wi-Fi networks across six UK cities, including London. He found that many didn’t even have a password and roughly half of home UK Wi-Fi networks could be hacked in less than 5 seconds.”

Read more of this story at Slashdot.

Link to the original site

US Reigns As Most Bot-Infected Country

Trailrunner7 writes “The US has by far the highest number of bot-infected computers of any country in the world, with nearly four times as many infected PCs as the country in second place, Brazil, according to a new report by Microsoft. The quarterly report on malicious software and Internet attacks shows that while some of the major botnets have been curtailed in recent months, the networks of infected PCs still represent a huge threat.”

Read more of this story at Slashdot.

Link to the original site