Saturday, January 11, 2014

Meet the Other Mayor Accusing Chris Christie of Retaliation | Mother Jones


Interesting. I think this might be a pattern, no? 

FTA:
After being told that Sokolich was asking questions about the George Washington Bridge lane closures, recently resigned Port Authority official David Wildstein replied, "Radio silence. His name comes right after mayor Fulop." Fulop told the Jersey Journal that after seeing that exchange he believes he's "Enemy Number 1."

More:

Friday, January 10, 2014

Schneier on Security: JETPLOW: NSA Exploit of the Day


From Bruce Schneier.  Fascinating stuff. 

I was worried about Supply Chain Security based on where this equipment is made.  Seems like that is minor compared to this...

JETPLOW: NSA Exploit of the Day

Today's implant from the NSA's Tailored Access Operations (TAO) group implant catalog:

JETPLOW

(TS//SI//REL) JETPLOW is a firmware persistence implant for Cisco PIX Series and ASA (Adaptive Security Appliance) firewalls. It persists DNT's BANANAGLEE software implant. JETPLOW also has a persistent back-door capability.

(TS//SI//REL) JETPLOW is a firmware persistence impant for Cisco PIX Series and ASA (Adaptive Security Appliance) firewalls. It persists DNT's BANANAGLEE software implant and modifies the Cisco firewall's operating system (OS) at boot time. If BANANAGLEE support is not available for the booting operating system, it can install a Persistent Backdoor (PDB) designed to work with BANANAGLEE'S communications structure, so that full access can be reacquired at a later time. JETPLOW works on Cisco's 500-series PIX firewalls, as well as most ASA firewalls (5505, 5510, 5520, 5540, 5550).

(TS//SI//REL) A typical JETPLOW deployment on a target firewall with an exfiltration path to the Remote Operations Center (ROC) is shown above. JETPLOW is remotely upgradable and is also remotely installable provided BANANAGLEE is already on the firewall of interest.

Status: (C//REL) Released. Has been widely deployed. Current availability restricted based on OS version (inquire for details).

Unit Cost: $0


More:

Wednesday, January 8, 2014

How Does RSA-NSA Deal Affect You?



As part of the deal, RSA Security will provide backdoors that the NSA can make use of in order to gain access to crucial information stored in what used to be a relatively safe database. This backdoor involves setting a particular random number generator (DUAL_EC_DRBG) as a default in its BSAFE cryptographic library. This doesn't sound like much of a big deal, but there is clear evidence pointing to the fact that this particular random number generator'soutcomes can be predicted effectively under some conditions. This wasdiscovered at some point in 2005.

RSA Security has come out with the news to its customers, telling them not to use the default generator, but as the old adage goes, "too little, too late." Customers who have long had faith in RSA and are unaware of the $10 million deal will not have the time to make a complete switchover on their algorithms.


More:

Monday, January 6, 2014

BlackBerry CEO: 'I Believe We Can Succeed' | Mobile Device Management content from MSPmentor


Not so sure about the claim that only BB has a DOD ATO... 

FTA:

BlackBerry (BBRY) interim CEO John Chen last week released another open letter to assure enterprise customers that the company is "strong financially, technologically savvy and is well-positioned for the future." He failed, again, to mention how BlackBerry will work with channel partners in 2014.

In his letter, Chen continued to stress the importance of surrounding himself with "a talented team of industry leaders," noting that he will add to his "leadership team with those who have the skills and passion to get BlackBerry back on the path to profitability."

Chen said his team needed to move to a new operating unit structure to place more emphasis on  what he called core business drivers. He then went on the offensive, calling out BlackBerry's competitors in the mobile device management (MDM) space.

"With a global enterprise customer base exceeding 80,000, we have three times the number of customers compared to Good,AirWatch and MobileIron combined," he said. "This makes BlackBerry the leader in mobile device management."

Chen said BlackBerry's customers include those who have the most stringent security needs.

"For governments, BlackBerry cannot just be replaced. We are the only MDM provider to obtain Authority to Operate on U.S. Department of Defense (DoD) networks," he said. "This means the DoD is allowed to use only BlackBerry. Across the globe, seven out of seven of the G7 governments are also BlackBerry customers."



More:

Friday, December 27, 2013

The Console Living Room : Free Software : Download & Streaming : Internet Archive



983 itemsWelcome to The Console Living Room

The Internet Archive Console Living Roomharkens back to the revolution of the change in the hearth of the home, when the fireplace and later television were transformed by gaming consoles into a center of videogame entertainment. Connected via strange adapters and relying on the television's speaker to put out beeps and boops, these games were resplendent with simple graphics and simpler rules.



More:

Thursday, December 26, 2013

BlackBerry Founder Walks Away From Possible Takeover Deal



BlackBerry Ltd. (BBRY) co-founder and former Chief Executive Officer Mike Lazaridis walked away from a possible takeover plan and reduced his stake in the struggling smartphone maker after it ended an attempt to sell itself.

Lazaridis now owns 26.3 million shares, or 4.99 percent of its outstanding shares, according to a regulatory filing yesterday. The former BlackBerry executive, who earlier this year had considered making a bid for the Waterloo, Ontario-based company, sold more than $26 million of stock this week, according to the filing. Together with co-founder Doug Fregin, he had controlled about 8 percent of the stock.

Following the collapse of a $4.7 billion buyout by Fairfax Financial Holdings Ltd. last month, BlackBerry ended its strategic review, opting instead to raise $1 billion in convertible debt and seek a new CEO. Former Sybase Inc. chief John Chen was named executive chairman and interim CEO. The $1 billion infusion helped stabilize the unprofitable company, giving Chen time to craft a turnaround plan.

More:
http://www.bloomberg.com/news/2013-12-24/blackberry-former-ceo-lazaridis-cuts-stake-in-smartphone-maker.html

Sunday, December 22, 2013

Atheists are good if they do good, Pope Francis says



He told the story of a Catholic who asked a priest if even atheists had been redeemed by Jesus.

"Even them, everyone," the pope answered, according to Vatican Radio. "We all have the duty to do good," he said.

"Just do good, and we'll find a meeting point," the pope said in a hypothetical conversation in which someone told a priest: "But I don't believe. I'm an atheist."


More:

Saturday, December 21, 2013

Microsoft Security Essentials misses 39% of malware in Dennis test



While the other eight packages all achieved protection scores of 87% or higher - with five scoring 98% or 99% - Microsoft's free antivirus software protected against only 61% of the malware samples used in the test.

Microsoft conceded last year that its security software was intended to offer only "baseline" performance, saying it wanted to "give customers a good reason to pay for their [security] products" because that would create greater diversity in the market and make life harder for malware writers.

Nevertheless, the company insisted that Security Essentials provided "strong, comprehensive defence against malicious code and attacks".



Read more: Microsoft Security Essentials misses 39% of malware in Dennis test | Security | News | PC Pro http://www.pcpro.co.uk/news/security/386185/microsoft-security-essentials-misses-39-of-malware-in-dennis-test#ixzz2o80ADd6R

More:

Wednesday, December 18, 2013

Why the Web Won't Be Nirvana - Newsweek circa 1995


Best part:

Then there's cyberbusiness. We're promised instant catalog shopping—just point and click for great deals. We'll order airline tickets over the network, make restaurant reservations and negotiate sales contracts. Stores will become obselete. So how come my local mall does more business in an afternoon than the entire Internet handles in a month? Even if there were a trustworthy way to send money over the Internet—which there isn't—the network is missing a most essential ingredient of capitalism: salespeople.


More:

Monday, December 2, 2013

BlackBerry CEO's open letter to enterprise customers: 'We are very much alive'

 FTA:
"In short, reports of our death are greatly exaggerated." BlackBerry CEO.

Ouch! I'm pretty sure it is a bad sign when you have to tell your customers that you are still alive...

http://www.fiercewireless.com/story/blackberry-ceos-open-letter-enterprise-customers-we-are-very-much-alive/2013-12-02

Wednesday, November 27, 2013

I wonder why Tesla gets pounded for a single fire when this is happening...


Ford said it is recalling nearly 140,000 2013 Escape SUVs with 1.6-liter engines in the United States — and 161,333 worldwide — because of fires caused by overheating of the engine cylinder head, which can crack and leak oil. Ford said it had received reports of 13 fires, including one in Canada, stemming from the engine issue.

Monday, November 18, 2013

The government needs to see Hadoop’s ROI



The healthcare use case: Improving the quality of life and the effectiveness of government spending

For the uninitiated, Hadoop is a solution for distributed parallel processing of huge amounts of data. You can see some examples of its uses in our Hadoop infographic.

IT can improve symptom analysis, time to market for drug development and safety, decreased hospitalization and sickness and a lower frequency of spreading diseases. How? Through Hadoop's uses in information exchange, service quality improvements, drug safety testing, symptom co-occurrence identification, drug development processes, illness detection and large-scale patient studies. There's one thing all these health-related topics (and just about everything else government agencies do) have in common —data, and lots of it.


More:

Explaining Hadoop to Your CEO

 A seasoned CEO will look for a plausible path to significant value, along with the outlines of a plan for broad adoption if all goes well. The path to value should describe the initial questions that will be answered by the technology, the processes that will be improved, the decisions that will be made better with more information. The suspected business impact should be defined, but it should be clear to everyone that it is very likely that the unexpected impact may be even bigger. The amount of money to be spent should be presented with plan for the first few experiments that will be performed. With cloud computing infrastructure, none of this should mean a huge upfront cost.

More:
http://www.forbes.com/sites/danwoods/2011/11/03/explaining-hadoop-to-your-ceo/

Tuesday, October 29, 2013

Security hole found in Obamacare website


Uggggg...
The Obamacare website has more than annoying bugs. A cybersecurity expert found a way to hack into users' accounts.

Until the Department of Health fixed the security hole last week, anyone could easily reset your Healthcare.gov password without your knowledge and potentially hijack your account.


More:

Saturday, October 26, 2013

LMI Claims NASA Could Adopt Pentagon's Supply Chain Techniques | SYS-CON MEDIA



A new LMI study has found that NASA could implement techniques already in use by the Defense Department when designing rockets and spaceships.

The nonprofit research recommended the space agency use readiness-based sparing in supply chain management to support ground systems for launch missions, LMI said Thursday.

Research authors Julie Castilho, David Peterson, Tovey Bachman and Rob Kline presented an RBS structure using LMI's ASM Sparing Model, which is designed to provide NASA logisticians with a platform to quantify the trade space using advanced analytics.


More:

Friday, October 18, 2013

LMI Researchers to NASA: Apply DoD's Cost-Effective Sparing Strategies to Next Generation of Critical Ground Systems

 As NASA develops the technologies and innovations to launch the next generation of rockets and spacecraft, the agency should leverage readiness-based sparing (RBS) techniques that are currently deployed successfully by the Department of Defense (DoD), according to LMI researchers investigating space exploration logistics. The findings are part of NASA-funded research presented at the American Institute of Aeronautics and Astronautics' SPACE 2013 conference in San Diego.

The research, authored by LMI logistics experts Julie Castilho,David Peterson, Ph.D., Tovey Bachman, Ph.D., and Rob Kline, explores the benefits of RBS as a way to extend systems-based sparing capabilities to NASA's critical launch-support ground systems in order to achieve the right balance of effectiveness and affordability.

More:
http://www.hispanicbusiness.com/2013/10/18/lmi_researchers_to_nasa_apply_dod.htm

Thursday, October 10, 2013

The Healthcare.gov Fiasco: Blame Bureaucracy - IT Clan Editor's Blog - Internet Evolution



The Healthcare.gov Fiasco: Blame Bureaucracy

The broken government procurement process shoulders the blame for the fiasco over the launch of Healthcare.gov, according to a blog for a company that designs government software.

The problem is that the federal procurement process gives work to a limited number of firms whose expertise is in navigating the procurement process, rather than doing the work, according to a blog post at The Department of Better Technology.

Healthcare.gov is the linchpin of the Affordable Care Act, which mandates, among other things, that Americans have health insurance. States set up exchanges to sell affordable insurance to individuals who don't get it through other channels, such as employers. Some 36 states have elected not to set up their own exchanges, instead letting federal systems handle the work for them. Healthcare.gov is the front door to that federal system.

On launch day Oct. 1, Healthcare.gov was plagued by slowdowns and outages. Site visitors saw a lot of this -- it's Healthcare.gov's fail whale:

Although the problems have been mitigated, they're not completely solved.

Bureaucracy is to blame, says the Department of Better Technology:

Healthcare.gov got this way not because of incompetence or sloppiness of an individual vendor, but because of a deeply engrained and malignant cancer that's eating away at the federal government's ability to provide effective online services. It's a cancer that's shut out the best and brightest minds from working on these problems, diminished competition for federal work, and landed us here — where you have half-billion dollar websites that don't work.

That cancer is called "procurement" and it's primarily a culture-driven cancer one that tries to mitigate so much risk that it all but ensures it. It's one that allowed for only a handful of companies like CGI Federal to not only build disasters like this, but to keep building more and more failures without any accountability to the ultimate client: us. Take a look at CGI's website, and the industries they serve: financial services, oil and gas, public utilities, insurance. Have you had a positive user experience in any of those industries?

The Department of Better Technology, which publishes the blog, makes government software, so of course it has a dog in this race. But, still, the blog makes good points. And the blog post is authored by Clay Johnson, who's had a substantial career in government, politics, and the Internet, including heading the digital presidential campaigns of Howard Dean (2004) and Barack Obama (2008). Johnson is CEO and founder of DBT, as well as a supporter of RFP-EZ, a federal project designed to make it easier for smaller companies to bid on federal IT projects.

Bureaucracy wasn't all there was to it. Healthcare.gov is also an incredibly complex problem. "Private companies sell things online all the time. Why is the government having such a hard time setting up an online health insurance marketplace?" writes The Washington Post.

Healthcare.gov's job was much harder than simple online commerce. "Much of the complexity comes from the fact that the exchanges are used to administer the complex system of subsidies the Affordable Care Act provides to low-income consumers. Figuring out whether a customer is eligible for a subsidy, and if so how much, requires data from a lot of federal and state agencies," the Post says. The site must also confirm that the applicant is an American citizen or documented immigrant, checking with the Social Security Administration and Department of Homeland Security. And so on. The Post reproduces a chart from Xerox that describes the problem:

Healthcare.gov was just plain badly built, according to The Wall Street Journal. It was overwhelmed by traffic, failing to cache frequently used portions of the website. Identity authentication broke down. And the site is susceptible to security vulnerabilities.

The White House knew since February that the launch was shaky, according to Forbes.com. But the White House was eager to get the site up and running fast. As Republicans combat the Affordable Care Act, proponents felt they needed to get the law implemented and get the American people using the system to make ObamaCare impossible to repeal. "The Obama administration was more afraid of delaying the launch of Obamacare, than they were of botching it," Forbes said.

This may prove to be a sound strategy. But the key is that the American people have to enjoy the benefits of the ACA. If the White House can't fix the law's Internet problem, there will be no benefits, only frustrations. And the ACA will go down.

Monday, October 7, 2013

Uh oh... NIST web sites are down. No FISMA guidance for you.


NIST Closed, NIST and Affiliated Web Sites Not Available

Due to a lapse in government funding, the National Institute of Standards and Technology (NIST) is closed and most NIST and affiliated web sites are unavailable until further notice. We sincerely regret the inconvenience.

The National Vulnerability Database and the NIST Internet Time Service web sites will continue to be available. A limited number of other web sites may also be available.

Notice will be posted here (www.nist.gov) once operations resume. You may also get updates on NIST's operating status by calling (301) 975-8000.

Conferences and other events scheduled during the shutdown are postponed or cancelled. Even after NIST reopens, some NIST events may need to be rescheduled. Once access to NIST Web sites resumes, please see the Conferences and Events (http://www.nist.gov/allevents.cfm) list for updated information on specific events.



Sunday, October 6, 2013

New Fitbit® Pink Flex™


Make fitness a lifestyle with Flex™.
FLEX™ WIRELESS ACTIVITY & SLEEP WRISTBAND
This slim, stylish device is with you all the time. During the day, it tracks steps, distance, and calories burned. At night, it tracks your sleep quality and wakes you silently in the morning. Just check out the lights to see how you stack up against your personal goal. It's the motivation you need to get out and be more active.