Saturday, September 27, 2014

43% of companies had a data breach in the past year

 Even in companies that have breach plans in place, employees aren't convinced they will work. Only 30% of those responding to the survey said their organization was "effective or very effective" at creating such plans.

One reason might be that few companies seem to take the need seriously. Of the companies surveyed, just 3% looked at their plan of action each quarter. Thirty-seven percent hadn't reviewed or updated their plan since it was first put in place.

More:
http://www.11alive.com/story/news/2014/09/24/43-of-companies-had-a-data-breach-in-the-past-year/16144167/

Friday, September 19, 2014

World Wide Web inventor slams Internet fast lanes: ‘It’s bribery.’

 "We need rules," said Berners-Lee. "If businesses are to move here and start here rather than start in Europe or Brazil or Australia — they're going to look around and make sure, 'Oh, does the power stay up?' And they'll look for other things. "Is the Internet open?' Will they have to effectively bribe their ISPs to start a new service? That's what it looks like from the outside. It's bribery."

More:
http://www.washingtonpost.com/blogs/the-switch/wp/2014/09/19/world-wide-web-inventor-lashes-out-at-internet-fast-lanes-its-bribery/

CDC: 90% of kids who died last flu season didn't get vaccine


SALT LAKE CITY — The flu took the lives of more than 100 children in the U.S. last flu season, and most of those kids didn't get a flu shot.

That's according to a new report by the Centers of Disease Control and Prevention, aimed to encourage Americans to get vaccinated now. The flu kills up to approximately 36,000 people each year, but less than half of the population gets an annual flu shot. That's something the CDC wants to change.


Saturday, September 6, 2014

The Police Tool That Pervs Use to Steal Nude Pics From Apple’s iCloud



On Tuesday afternoon, Apple issued a statement calling the security debacle a "very targeted attack on user names, passwords and security questions." It added that "none of the cases we have investigated has resulted from any breach in any of Apple's systems including iCloud® or Find my iPhone."

But the conversations on Anon-IB make clear the photo-stealing attacks aren't limited to a few celebrities. And Zdziarski argues that Apple may be defining a "breach" as not including a password-guessing attack like iBrute. Based on his analysis of the metadata from leaked photos of Kate Upton, he says he's determined that the photos came from a downloaded backup that would be consistent with the use of iBrute and EPPB. If a full device backup was accessed, he believes the rest of the backup's data may still be possessed by the hacker and could be used for blackmail or finding other targets. "You don't get the same level of access by logging into someone's [web] account as you can by emulating a phone that's doing a restore from an iCloud backup," says Zdziarski. "If we didn't have this law enforcement tool, we might not have the leaks we had."

Friday, September 5, 2014

US Air Force admits to quietly changing a regulation that now requires all personnel to swear an oath to God -- Airmen denied reenlistment for practicing constitutional rights

 ...
The Air Force said it cannot change its AFI to make "so help me God" optional unless Congress changes the statute mandating it.

Miller pointed out that Article VI of the Constitution prohibits requiring religious tests to hold an office or public trust.

"Forcing [the airman] to swear to a supreme being as a condition of his reenlistment is tantamount to a 'religious test' and is therefore violative of this constitutional provision as well," Miller said
...

More:
http://www.airforcetimes.com/article/20140904/NEWS05/309040066/Group-Airman-denied-reenlistment-refusing-say-help-me-God-

Thursday, September 4, 2014

Well, isn't that special... Army can't track spending on $4.3b system to track spending, IG finds



The problem, according to the IG, is that the Army has failed to comply with a variety of federal laws that require agencies to standardize reporting and prepare auditable financial statements.

"This occurred because DOD and Army management did not have adequate controls, including procedures and annual reviews, in place to ensure GCSS-Army compliance with Treasury and DOD guidance," the IG report concludes.

"Although Army personnel have been responsive to correcting deficiencies identified during the audit, the Army has spent $725.7 million on a system that still has significant obstacles to overcome" to comply with federal financial reporting laws.


Tuesday, September 2, 2014

Apple says iCloud is safe and secure, stolen celebrity pics were targeted accounts

 Apple said it has completed more than 40 hours of investigation to date, and found that the iCloud accounts in question were compromised based on practices that are "all too common on the Internet."

The company's statement dispels rumors that a wider exploit of its iCloud services, including the Find My iPhone function, played a part in the leaks. Apple recommends that its users employ a strong password, and also enable two-step verification to maximize security.

More:
http://appleinsider.com/articles/14/09/02/apple-says-icloud-is-safe-and-secure-stolen-celebrity-pics-were-targeted

Monday, September 1, 2014

Android security mystery - 'fake’ cellphone towers found in U.S.



"What we find suspicious is that a lot of these interceptors are right on top of U.S. military bases." says Goldsmith.  "Whose interceptor is it?  Who are they, that's listening to calls around military bases?  The point is: we don't really know whose they are."

Baseband attacks are considered extremely difficult – the details of the chips are closely guarded. "Interceptors" are costly devices – and hacking baseband chips is thought to be technically advanced beyond the reach of "ordinary" hackers, ESD says. The devices vary in form, and are sold to government agencies and others, but are computers with specialized software designed to defeat the encryption of cellphone networks. The towers target the "Baseband" operating system of cellphones – a secondary OS which sits "between" iOS or Android, for instance, and the cellular network.


Thursday, August 28, 2014

Good to know Tor isn't absolute protection... This scumbag needed to be caught.



Cybersecurity official uses Tor but still gets caught with child porn

...One site frequented by DeFoggi was PedoBook, hosted by Aaron McGrath—a Nebraska man who was convicted earlier for his role in the operations. The websites were only accessible to users who installed Tor on their browsers. DeFoggi used names such as "fuckchrist" and "PTasseater" to register on the sites, where he could view more than 100 videos and more than 17,000 child porn images.

The FBI seized McGrath's site in late 2012 after monitoring him for a year. Then they kept it up and running for several more weeks, gathering private communications from DeFoggi and other users. The FBI used "various investigative techniques… to defeat the anonymous browsing technology afforded by the Tor network."...

More:

http://arstechnica.com/tech-policy/2014/08/federal-cybersecurity-official-going-to-jail-on-child-porn-charges/


Sunday, August 24, 2014

I wonder how many lives 15 more minutes of fame might cost



George Zimmerman Arrested While Visiting Ferguson - National Report


Zimmerman is heard yelling something again, and finally the teens stop. One of the teens rather articulately asks Zimmerman to leave him, his friend, and his town, alone. "Sir, sir, we don't… we don't have an issue with you, sir. Please leave us alone," the younger teenager says in the video, while Zimmerman continues to rant about something in the background. "Mr. Zimmerman, I don't know why you're here in Ferguson, but It's pretty damn insensitive, you showing up here. This town's been through enough already, we don't need you here intensifying things, okay? And my friend and I didn't say anything to you."

"I have a right to be here. It's a free country, we're on a public street," Zimmerman angrily says to the teens. "Why were you following me? Why were you harassing me?"

"We did no such thing, Mr. Zimmerman. You were leaving the store and we saw you and crossed the street," the younger teen replies. "You followed us for a whole block. We said nothing to you and we were not following you."


Friday, August 22, 2014

Researchers find it’s terrifyingly easy to hack traffic lights


--This can't end well...

Taking over a city's intersections and making all the lights green to cause chaos is a pretty bog-standard Evil Techno Bad Guy tactic on TV and in movies, but according to a research team at the University of Michigan, doing it in real life is within the realm of anyone with a laptop and the right kind of radio. In a paper published this month, the researchers describe how they very simply and very quickly seized control of an entire system of almost 100 intersections in an unnamed Michigan city from a single ingress point.

Thursday, August 21, 2014

Seriously? The Day Ferguson Cops Were Caught in a Bloody Lie



Police in Ferguson, Missouri, once charged a man with destruction of property for bleeding on their uniforms while four of them allegedly beat him.

"On and/or about the 20th day of Sept. 20, 2009 at or near 222 S. Florissant within the corporate limits of Ferguson, Missouri, the above named defendant did then and there unlawfully commit the offense of 'property damage' to wit did transfer blood to the uniform," reads the charge sheet.


Wednesday, August 20, 2014

Decoding the Antikythera Mechanism


I had not seen this before. Fascinating. Well worth less than an hour of your time. 

"Decoding the Antikythera Mechanism" 
 

Monday, August 4, 2014

Why, Unless You're Running With Amazon, Google and Microsoft, You Should Never Build Another Data Center - Forbes



The Make-vs-Buy Question

The question every IT executive must answer is whether it's worth a $20+ million investment to build, own and operate a facility, which is probably still not state-of-the-art, but merely much sufficient for future needs and much better than existing facilities? Or would it be better to lease space in a veritable data center superstore that provides higher efficiency, better physical and perimeter network security, ample room for growth and far better network connections to major ISPs, wireless carriers and cloud services? I contend that for IT organizations both large and small, owning, operating, maintaining and upgrading data centers yields no significant business advantage and is a waste of IT capital and effort.



Thursday, July 31, 2014

What is EMV?



U.S. banks are switching up the insides of your customers' credit cards. They're adding something called EMV technology, which stands for "Europay, MasterCard, and Visa." Translation: Credit cards will be equipped with a super-small computer chip that's extremely hard to counterfeit. If you've gotten a card recently, chances are it's souped up with this technology.

Chip Card Blog Copy

Why the changeover? Here's a crazy statistic: Almost half of the world's credit card fraud now happens in the United States—even though only a quarter of all credit card transactions happen here. The banks want to rein this in ASAP by moving away from magnetic-stripe cards, which are much easier to counterfeit. The recent Target and Neiman Marcus security breaches also added motivation.


CIA Admits to Hacking Senate Computers



In a sharp and sudden reversal, the CIA is acknowledging it improperly tapped into the computers of Senate staffers who were reviewing the intelligence agency's Bush-era torture practices.







More:

Monday, July 21, 2014

Government-Grade Stealth Malware In Hands Of Criminals



Malware originally developed for government espionage is now in use by criminals, who are bolting it onto their rootkits and ransomware.

The malware, dubbed Gyges, was first discovered in March by Sentinel Labs, which just released an intelligence report outlining their findings. From the report: "Gyges is an early example of how advanced techniques and code developed by governments for espionage are effectively being repurposed, modularized and coupled with other malware to commit cybercrime."


Wednesday, July 9, 2014

Apache Spark™ - Lightning-Fast Cluster Computing


Apache Spark™ is a fast and general engine for large-scale data processing.

Speed

Run programs up to 100x faster than Hadoop MapReduce in memory, or 10x faster on disk.

Spark has an advanced DAG execution engine that supports cyclic data flow and in-memory computing.


Sunday, June 29, 2014

Gliese 832c: Potentially Habitable Super-Earth Discovered 16 Light-Years Away



The newly discovered exoplanet, labeled Gliese 832c, has an orbital period of 35.68 days, a mass 5.4 times that of Earth's and receives about the same average energy as Earth does from the Sun.

Gliese 832c might have Earth-like temperatures, albeit with large seasonal shifts, given a similar terrestrial atmosphere.

"If the planet has a similar atmosphere to Earth it may be possible for life to survive, although seasonal shifts would be extreme," Prof Tinney said.