The Internet - The first Worldwide Tool of Unification ("The End of History")

" ... Now I give you something that few think about: What do you think the Internet is all about, historically? Citizens of all the countries on Earth can talk to one another without electronic borders. The young people of those nations can all see each other, talk to each other, and express opinions. No matter what the country does to suppress it, they're doing it anyway. They are putting together a network of consciousness, of oneness, a multicultural consciousness. It's here to stay. It's part of the new energy. The young people know it and are leading the way.... "

" ... I gave you a prophecy more than 10 years ago. I told you there would come a day when everyone could talk to everyone and, therefore, there could be no conspiracy. For conspiracy depends on separation and secrecy - something hiding in the dark that only a few know about. Seen the news lately? What is happening? Could it be that there is a new paradigm happening that seems to go against history?... " Read More …. "The End of History"- Nov 20, 2010 (Kryon channelled by Lee Carroll)

"Recalibration of Free Choice"– Mar 3, 2012 (Kryon Channelling by Lee Carroll) - (Subjects: (Old) Souls, Midpoint on 21-12-2012, Shift of Human Consciousness, Black & White vs. Color, 1 - Spirituality (Religions) shifting, Loose a Pope “soon”, 2 - Humans will change react to drama, 3 - Civilizations/Population on Earth, 4 - Alternate energy sources (Geothermal, Tidal (Paddle wheels), Wind), 5 – Financials Institutes/concepts will change (Integrity – Ethical) , 6 - News/Media/TV to change, 7 – Big Pharmaceutical company will collapse “soon”, (Keep people sick), (Integrity – Ethical) 8 – Wars will be over on Earth, Global Unity, … etc.) - (Text version)

“…5 - Integrity That May Surprise…

Have you seen innovation and invention in the past decade that required thinking out of the box of an old reality? Indeed, you have. I can't tell you what's coming, because you haven't thought of it yet! But the potentials of it are looming large. Let me give you an example, Let us say that 20 years ago, you predicted that there would be something called the Internet on a device you don't really have yet using technology that you can't imagine. You will have full libraries, buildings filled with books, in your hand - a worldwide encyclopedia of everything knowable, with the ability to look it up instantly! Not only that, but that look-up service isn't going to cost a penny! You can call friends and see them on a video screen, and it won't cost a penny! No matter how long you use this service and to what depth you use it, the service itself will be free.

Now, anyone listening to you back then would perhaps have said, "Even if we can believe the technological part, which we think is impossible, everything costs something. There has to be a charge for it! Otherwise, how would they stay in business?" The answer is this: With new invention comes new paradigms of business. You don't know what you don't know, so don't decide in advance what you think is coming based on an old energy world. ..."
(Subjects: Who/What is Kryon ?, Egypt Uprising, Iran/Persia Uprising, Peace in Middle East without Israel actively involved, Muhammad, "Conceptual" Youth Revolution, "Conceptual" Managed Business, Internet, Social Media, News Media, Google, Bankers, Global Unity,..... etc.)


German anti-hate speech group counters Facebook trolls

German anti-hate speech group counters Facebook trolls
Logo No Hate Speech Movement

Bundestag passes law to fine social media companies for not deleting hate speech

Honouring computing’s 1843 visionary, Lady Ada Lovelace. (Design of doodle by Kevin Laughlin)
Showing posts with label Security. Show all posts
Showing posts with label Security. Show all posts

Thursday, May 16, 2019

Dutch researchers find major vulnerability in Intel chips

DutchNews, May 15, 2019

Photo: Depositphotos.com

Researchers at Amsterdam’s VU university have discovered a major leak in Intel microchips which make it possible to get hold of passwords and other sensitive information. 

The vulnerability, named Rogue In-Flight Data Load, was discovered a year ago but only just made public to give Intel time to develop an acceptable fix. 

The leak covered all Intel processors made since 2008 and would have been extremely easy to abuse, the researchers say. 

‘Even if home users used their browsers to visit a website with an advert or other content with a malware Java programme, the hacker could still steal information,’ the researchers say. There were also problems with cloud services. 

However, Herbert Bos, who was in charge of the research, told broadcaster RTL Z that most consumers should not immediately be very concerned and that specific targets, such as senior employees of a company or senior government officials, were more likely to have been victims. 

Intel has now taken steps to close the leaks and protect users, who are now being recommended to update their processors and software.

Friday, September 14, 2018

Norwegian police find canoe belonging to missing Dutch cyber security expert

DutchNews, September 13, 2018


Police in Norway say they have found a collapsible canoe which belongs to missing Dutch cyber security expert Arjen Kamphuis. 

The canoe was found a day after several other items owned by Kamphuis turned up on the coast, east of Bodo where he was staying when he disappeared. He is known to have bought a canoe to use in the Norwegian fjords. 

Norwegian television station TV2 also claims that a fisherman found Kamphuis’ identity papers close to where the canoe was found. Police have declined to comment on the other findings. 

Kamphuis was last seen in Bodo on August 20 and should have returned to the Netherlands on August 22. On September 6 a witness told police he had spotted the missing man in Denmark. 

Police also say that Kamphuis’ mobile telephone had been turned on on August 30 in the vicinity of Vikeså, about 50k from Stavanger in Norway. The device remained active for 20 minutes after which a German sim card was put in it. 

The hunt for Kamphuis, 47, has been conducted by a police team known as Kripos, who specialise in organised crime and disappearances, Norwegian police said in a press release. According to Dutch media he is an expert in cyber security who advises governments, journalists and human rights experts. He is also an associate of Wikileaks founder Julian Assange.

Saturday, August 18, 2018

'Hacky hack hack': Australia teen breaches Apple's secure network

Yahoo - AFP, August 17, 2018

Police reportedly raided the boy's home last year and found hacking files and
 instructions saved in a folder called 'hacky hack hack' (AFP Photo/Josh Edelson)

Sydney (AFP) - A schoolboy who "dreamed" of working for Apple hacked the firm's computer systems, Australian media has reported, although the tech giant said Friday no customer data was compromised.

The Children's Court of Victoria was told the teenager broke into Apple's mainframe -- a large, powerful data processing system -- from his home in the suburbs of Melbourne and downloaded 90GB of secure files, The Age reported late Thursday.

The boy, then aged 16, accessed the system multiple times over a year as he was a fan of Apple and had "dreamed of" working for the US firm, the newspaper said, citing his lawyer.

Apple said in a statement Friday that its teams "discovered the unauthorised access, contained it, and reported the incident to law enforcement".

The firm, which earlier this month became the first private-sector company to surpass US$1 trillion in market value, said it wanted "to assure our customers that at no point during this incident was their personal data compromised".

An international investigation was launched after the discovery involving the FBI and the Australian Federal Police, The Age reported.

The federal police said it could not comment on the case as it is still before the court.

The Age said police raided the boy's home last year and found hacking files and instructions saved in a folder called "hacky hack hack".

"Two Apple laptops were seized and the serial numbers matched the serial numbers of the devices which accessed the internal systems," a prosecutor was reported as saying.

A mobile phone and hard drive were also seized whose IP address matched those detected in the breaches, he added.

The teen has pleaded guilty and the case is due to return to court for his sentencing next month.

Saturday, January 13, 2018

New security flaw detected in Intel hardware

Finnish cybersecurity specialist F-Secure has reported another serious flaw in Intel hardware. It has nothing to do with the Spectre and Meltdown vulnerabilities, but has a huge "destructive potential" too.

Deutsche Welle, 12 January 2018


F-Secure said Friday it had found a serious flaw in Intel hardware which could enable hackers to access corporate laptops remotely.

It said it detected an issue within Intel's Active Management Technology (AMT) "which is commonly found in most corporate laptops and allows attackers to take complete control over a user's device in a matter of seconds."

"The issue potentially affects millions of laptops globally," said F-Secure consultant Harry Sintonen, who discovered the flaw. "It's of an almost shocking simplicity, but its destructive potential is unbelievable."

Loss of confidentiality

F-Secure said once an attacker had the chance to reconfigure AMT (for which he would initially need physical access to the device in question), the device could be fully controlled remotely by connecting to the same wireless or wired network as the user.


A successful attack would lead to complete loss of confidentiality, integrity and availability, with the attacker able to read and modify all of the data and applications users have access to on their computers, even at the firmware level.

Related Article:


Tuesday, October 4, 2016

Driving licences on your mobile phone ‘in next few years’

DutchNews, October 3, 2016

Photo: rijbewijs.nl
Driving licences could be available as a phone app in the next few years under plans proposed by the vehicle licensing service. 

Bas van den Berg, head of the driving licences unit at the RVW agency, said the technology for mobile licences was in development. ‘You’ll download an app from the store and the details of your driving licence will be stored in a secure manner,’ he said. 

The proposal came on the day when paper driving licences officially expired. The Telegraaf reported that around 300,000 old-style licenses had not been handed in, even though drivers risk a €90 fine if they rely on an invalid document. 

Van den Berg explained that the app would exist in two forms: one for the licence holder and one to allow the police to read the details securely. 

He added that security was a paramount issue: ‘There are no 100 per cent guarantees against hacking, but the technology has evolved to the point where people’s details can be stored securely.’

Wednesday, January 14, 2015

Obama makes fresh push for cybersecurity legislation

US President Barack Obama has made a fresh push for cybersecurity legislation. It comes in the wake of highly publicized cyber attacks including on the US Central Command's Twitter page, which was targeted this week.

Deutsche Welle, 13 Jan 2015


US President Barack Obama renewed calls on Tuesday for cybersecurity legislation and asked the new Congress to revive an initiative which had been stalled in recent years.

The new proposal would allow increased sharing of information on cyber threats from the private sector with protection from liability.

It would also be a criminal offence to sell stolen financial data and companies would have to notify consumers about data breaches under the measures.

Speaking at a White House meeting with congressional leaders, Obama said that recent events had increased the need for tougher cybersecurity legislation.

"With the Sony attack that took place, with the Twitter account that was hacked by Islamist jihadist sympathizers yesterday, it just goes to show we need to do much more work in the public and private sector to strengthen our cyber security," the president said.

A White House statement said the updated proposal "promotes better cybersecurity information sharing between the private sector and government, and it enhances collaboration and information sharing amongst the private sector."

Sense of urgency over cybersecurity

Obama had pressed for the legislation to be revised in order to allow the private sector to share data on threats without fear of any adverse consequences from the disclosures.

Earlier efforts were stalled due to opposition from civil libertarians who feared the measures could allow too much government interference. In turn, conservatives argued they would create a new bureaucracy.

However, concerns were further heightened by the hacking of Sony Pictures in December, which the administration blamed on North Korea, and major data breaches affecting retailers including Target and Home Depot.

On Monday, the US Central Command suspended its Twitter and Youtube pages after a group declaring its support for "Islamic State" (IS) jihadists hacked its social media accounts and posted internal documents.

However, it seems to have been a temporary hitch as the department's Twitter account was up and running once again on Tuesday:

Obama is scheduled to comment on the legislative proposals later on Tuesday in a speech at the National Cybersecurity and Communications Integration Center in Virginia.
The proposals are also expected to be part of his State of the Union address on January 20.

Monday, November 10, 2014

Putin gives Xi world's first dual-screen smartphone

Want China Times, Staff Reporter 2014-11-10

Vladimir Putin gives Xi Jinping a new Yotaphone 2. (Internet photo)

Chinese president Xi Jinping has become the owner of the world's first dual-screen smartphone courtesy of his Russian counterpart Vladimir Putin.

Xi was personally presented with a YotaPhone 2, developed by Russia's state-owned tech company Rostec, by Putin, who had arrived in Beijing on Sunday ahead of the Asia-Pacific Economic Cooperation (APEC) leadership summit on Nov. 10-11.

Apart from a traditional LCD screen on one side, the back of the YotaPhone 2 features a 4.7-inch electronic paper display (EPD) for reading e-books and playing simple games like Sudoku or chess. If the main screen runs out of battery, the EPD side can act as a backup.

The special edition of the smartphone Xi received has reportedly been installed with special Russian, Chinese and APEC paraphernalia. It also includes a special data protection system developed by Russian engineers, which is said to make the phone "unique" in regard of safety levels.

Xi was reportedly all smiles when he received the gift, and later even asked Putin, "Do we have partnership in this project as well?" to which Putin responded, "Will do!"

The official launch of the YotaPhone 2, which runs on Google's Android operating system, is scheduled for December. The phone will then hit European markets before arriving in China and South-East Asia in the first quarter of 2015.

Apart from playing with his new phone, Xi also managed to squeeze in the execution of 17 bilateral cooperation agreements with Putin that traverse areas such as natural gas, oil, nuclear power, transportation, aerospace and finance.

Sunday, November 9, 2014

e-ID card offers more protection to China's internet users

Want China Times, Staff Reporter 2014-11-09

A woman uses her laptop to chat online. (File photo/CNS)

The Third Research Institute of China's Ministry of Public Security has developed an electronic identity card that claims to provide better and more efficient protection to internet users' personal information and security, reports the Chinese-language Beijing Morning Post.

The new technology, named e-ID, was on show at the 16th China International Industry Fair between Nov. 4-8. It stores personal information on a chip of a bank card. At the fair, the institute's staff used a card reader or a smartphone to read the e-ID, which allows the owners to shop online and check their purchases without submitting their name, address, phone number or personal information.

Yan Zeming, deputy director of the institute's information and internet security laboratory, said the technology uses an algorithm called Guomi SM2 and has a strong security mechanism that ensures the card's information cannot be read, copied, changed or used illegally.

The institute has launched a trial program for the e-ID since 2012 when it provided nearly 30,000 e-IDs to Beijing University of Posts and Telecommunications. Industrial and Commercial Bank of China, the country's largest commercial bank, has also issued 6 million bank IC cards installed with the technology across the country.

Sunday, September 14, 2014

China's internet regulator warns foreign firms

Want China Times, Xinhua 2014-09-14

Chairman and CEO of Qualcomm, Paul Jacobs, speaks at a conference in
Las Vegas. (File photo/Xinhua)

A senior official with China's internet regulator Wednesday warned that foreign firms should not harm the country's interests and security while making big money from this market.

The bottom line of the Chinese government concerning the management of internet is national interest and the interests of Chinese consumers, said Lu Wei, director of the State Internet Information Office, at 2014 Summer Davos in the north Chinese city of Tianjin.

"We welcome all foreign companies to do business in China if they stick to this bottom line," Lu said at a sub-forum about the future of internet business.

"What we can not allow is that you undermine the country's interests while doing business in this market and profiting from it."

When responding to a question about China's ongoing anti-trust probes, Lu said the probes do not target any specific company and China is always open to foreign firms.

"But we also would like all foreign companies to understand that they should abide by Chinese laws," he said.

Lu stressed that the fast development of internet businesses in China proved that the country's industrial policy is open, and domestic IT firms are also open to cooperation with foreign counterparts.

The creativity of Chinese IT firms and high-quality regulation of the Internet also contributed to the development, he added.

China is conducting anti-monopoly investigations against Microsoft, Jaguar Land Rover, and Qualcomm. Paul E. Jacobs, executive chairman of Qualcomm, attended the forum with Lu.

The National Development and Reform Commission confirmed in February that it is conducting an antitrust investigation into the US mobile chip maker.

Jacobs refused to comment about the anti-trust probe but stressed that the company's cooperation with Chinese firms is important, mutually beneficial and has great potential.

Sunday, December 8, 2013

BRICS announce joint cybersecurity group

The Brics Post, December 7, 2013

BRICS said they would step up cooperation
 and vigilance for maintaining global and
regional peace [Xinhua]
BRICS on Friday agreed on the establishment of an expert working group on cyber-security that will meet in early 2014, in South Africa, to finalize concrete set of proposals for adoption by the leaders’ summit. The move was announced after a meet of the national security advisors of the five countries.

Chinese State Councilor Yang Jiechi said on Friday that BRICS would step up cooperation and vigilance for maintaining global and regional peace.

Yang was addressing the BRICS meet on national security in South Africa’s Cape Town.

The group of five also discussed measures to boost cyber-security in the wake of the recent US snooping revelations. Brazil has successfully mustered enough support to get a “right to privacy” resolution co-drafted with Germany passed by the UN earlier in November.

China said BRICS must take cognizance of the new security challenges facing the world.

In a separate meeting with Shivshankar Menon, India’s national security advisor, Yang said China hoped the two sides would enhance coordination in regional and international affairs.

To combat terror challenges, BRICS agreed to share best practices, capacity building and information and intelligence, said a statement released after the meet.

China is stepping up its campaign against terrorism after a recent suicide attack at the Forbidden City overlooking Tiananmen square.

Authorities termed that incident a “terrorist attack” and have said that it was carried out by several people with links to a separatist group known as the East Turkestan Islamic Movement from China’s far-western Xinjiang region, home to the mostly Muslim Uighur minority.

Unlike China where incidents of targeted terror-related violence has been sparse, India has been among the most affected by terrorist attacks.

The Global Terrorism Index – published in December 2012 by the US and Australia-based Institute for Economics and Peace think tank ranked India among the top four nations which has been a target of terror.

Meanwhile, on Friday, the five nations also agreed to step up coordination towards conflict resolution in troubled regions including the African continent.

Wednesday, November 6, 2013

Apple details government data requests

Yahoo –AFP, 5 November 2013

An Apple store on July 23, 2013 in New York City (AFP Photo/Spencer Platt)

Washington (AFP) - Apple on Tuesday released details of government requests for its data while protesting a "gag order" that limits what can be disclosed about US national security orders.

The iPhone and iPad maker followed the lead of other US tech giants and released its first report on requests from governments around the world.

Most of the requests involve criminal investigations into "robberies and other crimes or requests from law enforcement officers searching for missing persons or children, finding a kidnapping victim, or hoping to prevent a suicide," Apple said in a seven-page document.

In the United States, Apple said, "the US government has given us permission to share only a limited amount of information about these orders, with the requirement that we combine national security orders with account-based law enforcement requests and report only a consolidated range in increments of 1000."

The document said Apple received between 1,000 and 2,000 US government requests between January 1 and June 30 of this year, affecting between 2,000 and 3,000 accounts.

It was unable to provide details on how much, if any, data was disclosed, saying this happened in a range of zero to 1,000 cases.

"We strongly oppose this gag order," the document said, adding that Apple has been pressing for greater ability to disclose the figures.

"Despite our extensive efforts in this area, we do not yet have an agreement that we feel adequately addresses our customers' right to know how often and under what circumstances we provide data to law enforcement agencies."

Apple added that "dialogue and advocacy are the most productive way to bring about a change in these policies, rather than filing a lawsuit against the US government."

But the company said it filed an amicus brief with the secret Foreign Intelligence Surveillance Court in support of others seeking greater transparency.

Apple said that it has never received a request under the controversial Section 215 of the Patriot Act, which gives the government broad electronic surveillance authority, and added that "we would expect to challenge such an order if served on us."

Outside the United States, Apple said it received several hundred requests, including 127 in Britain, 102 in Spain, 93 in Germany, 74 in Australia and 71 in France.

"We have reported all the information we are legally allowed to share, and Apple will continue to advocate for greater transparency about the requests we receive," the statement said.

The report comes with US tech companies under pressure following revelations of a secret government program that scoops up vast amounts of data from Internet firms.

Tech firms including Microsoft, Google and Facebook have been seeking to release more information on government data requests, in the belief this would reassure customers.

Related Article:


Monday, October 14, 2013

Brazil announces secure email to counter US spying

Google – AFP, 14 October 2013

Brazilian President Dilma Rousseff in Brasilia on October 8, 2013 (AFP/File,
 Evaristo Sa)

Brasilia — Brazilian President Dilma Rousseff announced Sunday that her government was creating a secure email system to try and shield official communications from spying by the United States and other countries.

"We need more security on our messages to prevent possible espionage," Rousseff said on Twitter, ordering the Federal Data Processing Service, or SERPRO, to implement a safe email system throughout the federal government.

The agency, which falls under Brazil's Finance Ministry, develops secure systems for online tax returns and also creates new passports.

The move came after Rousseff publicly condemned spying against Brazilian government agencies attributed to the United States and Canada.

"This is the first step toward extending the privacy and inviolability of official posts," Rousseff said.

After bringing her complaints against US intelligence agencies to the United Nations General Assembly last month and canceling a state visit to Washington, Rousseff announced that the country will host an international conference on Internet governance in April.

In recent months, Brazilian media outlets have published documents showing that the US National Security Agency's spied on Rousseff's official communications, her close associates and state-controlled oil giant Petrobras.

The information was revealed by Edward Snowden, a 30-year-old former NSA contractor who has sought refuge in Russia and is wanted by the United States after revealing details of the agency's massive snooping activities.

Related Articles:



Friday, September 13, 2013

iPhone transforms security with fingerprint reader

Google – AFP, Glenn Chapman (AFP), 12 Sep 2013

Apple chief executive Tim Cook introduces the new iPhone 5S on
September 10, 2013 in Cupertino, California. (AFP, Glenn Chapman)

SAN FRANCISCO — With the swipe of a finger, Apple could jumpstart a new era of smartphone security and strip away fear of tending to banking or other business on mobile devices.

Fingerprint recognition technology built into a sophisticated iPhone 5S set to hit the market on September 20 was hailed by computer security specialists as a welcome move that rivals will likely rally to match.

"It could be amazing," Lookout principal security researcher Marc Rogers told AFP on Wednesday.

"What is going to happen really depends on Apple's implementation," he continued. "We've seen Apple take obscure technologies and make them mainstream overnight."

Apple on Tuesday unveiled two new iPhone models, one of them a top-of-the-line 5S with innovative features including a fingerprint sensor to use as a security measure in place of passcodes.

A new iPhone 5S handset, which lets the
 user unlock the phone with a fingerprint, 
pictured September 10, 2013 (AFP,
Glenn Chapman)
"You can just press the home button to unlock your phone," Apple vice president Phil Schiller during an event at the company's Silicon Valley headquarters. "You can use it to authenticate iTunes purchases."

Schiller added: "We have so much of our personal data on these devices, and they are with us almost everyplace we go, so we have to protect them."

Reticle Research principle analyst Ross Rubin described Touch ID as a "show stealer" that addresses "a necessary annoyance that many consumers have to deal with many times a day."

Studies by Apple and Lookout, which specializes in protecting smartphones and tablets from hackers, show that only about half of smartphone owners protect handsets with access codes
A camera sensor built into the 5S home button at the bottom of the smartphone face peers deep into layers of skin to analyze loops and swirls of fingerprints.

Data from fingers is stored exclusively inside the sophisticated Apple-made chip that powers the smartphone and is refined every time Touch ID is used, according to Schiller.

"The company says that fingerprint data is encrypted and not sent to its (or anyone else's - sorry, NSA) servers," security researcher Graham Cluley said in a blog post, making a reference to reports of US spying on the Internet.

Touch ID lets 5S owners store as many as five fingerprints, meaning people will be able to let spouses, children, or others they trust share access to smartphones.

Combining fingerprint recognition with "second-factor authentication" such as verification codes ramps up smartphone security tremendously, according to Rogers.

"Imagine a banking application that lets you press a fingerprint to gain access, but to transfer money you also enter a four-digit code," Rogers said.

"It could make mobile devices more secure than their desktop counterparts."

Whether Touch ID transforms mobile commerce is likely to depend on how Apple shares the technology with the creators of applications tailored to run on iPhones.

"It is not unreasonable to imagine where Apple might go in the payment space for things outside the Apple ecosystem with a PayPal or Square type function," said Forrester analyst Charles Golvin.

"Some aspect of doing commerce in the real world is on the horizon for Apple."

Computer security specialists note that fingerprint security is not flawless, and resourceful hackers will still craft attacks.

Apple Senior Vice President of Worldwide
 Marketing Phil Schiller speaks about the
 new iPhone on September 10, 2013
(Getty Images/AFP, Justin Sullivan)
"Your fingerprint isn't a secret, you leave it everywhere you touch," said security researcher Bruce Schneier.

Fooling some of the better fingerprint sensors with rubber fingers is difficult, but possible, according to Schneier, who noted that a researcher in Japan managed the trick more than a decade ago with candy gelatin used to make Gummi bears.

"The best system I've ever seen was at the entry gates of a secure government facility," Schneier said.

"Maybe you could have fooled it with a fake finger, but a Marine guard with a big gun was making sure you didn't get the opportunity to try."

Touch ID also prompted speculation about movie-style scenarios in which someone's digit is lopped off to unlock a stolen smartphone.

Security specialists thought the gruesome tactic unlikely, especially since PIN code access will likely remain in place as a way to get access to a smartphone if something goes wrong with the fingerprint scanner.

"It's inconceivable that malicious hackers and data thieves won't try to subvert Apple's Touch ID fingerprint scanning technology," Cluley said.

"How capable they will be at doing that, remains to be seen."

Related Article:


Friday, August 30, 2013

Cisco fixes critical remote command exec vulnerability in Secure ACS

Vulnerability could allow remote, unauthenticated attackers to take control of the underlying operating system, the company said

TechCentral.ie, 30 August 2013
               
Tech4Biz | 30 Aug 2013 :  Cisco Systems released security patches for Secure Access Control Server (Secure ACS) for Windows to address a critical vulnerability that could allow unauthenticated attackers to remotely execute arbitrary commands and take control of the underlying operating system.

Cisco Secure ACS is an application that allows companies to centrally manage access to network resources for various types of devices and users. According to Cisco's documentation, it enforces access control policies for VPN, wireless and other network users and it authenticates administrators, authorises commands, and provides an audit trail.

Cisco Secure ACS supports two network access control protocols: Remote Access Dial In User Service (RADIUS) and Terminal Access Controller Access-Control System Plus (TACACS+).

The newly patched vulnerability is identified as CVE-2013-3466 and affects Cisco Secure ACS for Windows versions 4.0 through 4.2.1.15 when configured as a RADIUS server with Extensible Authentication Protocol-Flexible Authentication via Secure Tunnelling (EAP-FAST) authentication.

"The vulnerability is due to improper parsing of user identities used for EAP-FAST authentication," Cisco said in a security advisory. "An attacker could exploit this vulnerability by sending crafted EAP-FAST packets to an affected device."
 
"Successful exploitation of the vulnerability may allow an unauthenticated, remote attacker to execute arbitrary commands and take full control of the underlying operating system that hosts the Cisco Secure ACS application in the context of the System user for Cisco Secure ACS running on Microsoft Windows," the company said.

The vulnerability received the maximum severity score, 10.0, in the Common Vulnerability Scoring System (CVSS), which indicates that it is highly critical. Cisco Secure ACS for Windows version 4.2.1.15.11 was released to address the flaw.

There are no known workarounds, so upgrading to the patched version of the application is recommended.

Wednesday, July 10, 2013

Pirate Bay founder creates encrypted messaging app

BBC News, 10 July 2013

A mock-up of the planned Hemlis app
One of the Pirate Bay file-sharing site's founders has announced plans for a "totally secure" rival to WhatsApp and Apple's iMessage services.

Hemlis, which means secret in Swedish, will use end-to-end encryption so messages are seen only by the sender and recipient.

Peter Sunde said it was a response to governments spying on users' data.

The iOS and Android project is quickly approaching its $100,000 (£149,133) funding target.

However, Apple and WhatsApp say communications using their services are already "fully encrypted".

Blackberry is also planning to extend its BBM chat service - which can be made fully secure - to other mobile operating systems.

The team behind Hemlis said their service would be more beautiful and user-friendly.

'Secure, fun and sexy.'

Hemlis is being crowdfunded by users who can opt to pay either in the virtual online currency Bitcoin or PayPal.

In return for a $5 donation, they are being offered free access to all the premium features regular users would normally have to pay for, such as picture-sharing.

Peter Sunde was one of three co-founders
of the Pirate Bay file-sharing site.
In contrast, other apps are often funded by selling adverts or user data - a model the app's developers want to steer away from.

"We're interested in helping, not selling users", said the developers.

"No-one can spy on you. Not even us."

The move by the Pirate Bay co-founder comes after recent revelations that the US government's National Security Agency has been using a system called Prism to tap into data stored by US-based technology giants including Google, Facebook and Apple.

Tuesday, January 15, 2013

Oracle patches dangerous Java holes

Google – AFP,  14 January 2013 

Oracle is distributing a patch for flaws so dangerous the Department of
Homeland  Security said people should stop using it (Getty Images/AFP/
File, Justin Sullivan)

SAN FRANCISCO — Oracle on Monday was distributing a patch for Java software flaws deemed so dangerous that the US Department of Homeland Security said that people should stop using it.

"Oracle recommends that this Security Alert be applied as soon as possible because these issues may be exploited 'in the wild' and some exploits are available in various hacking tools," Oracle's Eric Maurice said in a blog post.

The patch was crafted to fix two holes that hackers could slip through in Java 7 software used by web browsers to interact with websites.

"To be successfully exploited, an attacker needs to trick an unsuspecting user into browsing a malicious website," Maurice said.

"The execution of the malicious applet within the browser of the unsuspecting users then allows the attacker to execute arbitrary code in the vulnerable system."

Essentially, hackers could take advantage of the vulnerability to infect and take control of computers by getting them to visit a booby-trapped website.

Oracle raised Java security settings so that mini-programs referred to as "applets" will need to get permission from website visitors before being able to run on people's computers, according to Maurice.

Despite the patch, which was released by Oracle on Sunday, computer specialists at the Department of Homeland Security advised people to avoid using the software "unless it is absolutely necessary," even after updating.

"This will help mitigate other Java vulnerabilities that may be discovered in the future," the DHS Computer Emergency Readiness Team said Monday in an updated advisory on its website.

Java is distributed by business software powerhouse Oracle and is popular because it lets developers create websites in code that can be accessed regardless of a computer's operating system.

Java was created by Sun Microsystems, which was purchased by Northern California-based Oracle.

Friday, July 27, 2012

Black Hat: Iris scanners 'can be tricked' by hackers

BBC News, 26 July 2012

Related Stories 

Iris scanners are widely recognised
 as one of the most secure biometric
security measures
 
Security researchers have discovered a way to replicate a person's eye to bypass iris-scanning security systems.

A team at the Universidad Autonoma de Madrid was able to recreate the image of an iris from digital codes of real irises stored in security databases.

The findings were shared at the annual Black Hat security conference in Las Vegas.

It raises doubts over what is considered to be one of the most secure methods of biometric security.

Researcher Javier Galbally and his team, which included researchers from West Virginia University, were able to print out synthetic images of irises.

In one experiment, the researchers tested their fake irises against a leading commercial-recognition system. In 80% of attempts, they said, the scanner believed it was a real eye.

While researchers have been able to create realistic iris images for some time, it is thought that this is the first instance where the fake image can be generated from the iris code of a real person - a method which could be used to steal someone's identity.

An iris code is the data stored by recognition systems when it scans a person's eye. It contains around 5,000 different pieces of information.

Digital WMD

The research was explained to an audience at the annual Black Hat conference, a meeting of the leading figures in IT security from across the world.

Shawn Henry, the former head of the FBI's cybercrime unit, gave a key speech at the event.

He urged security experts to counter-attack in their attempts to stamp out criminal activity.

"We need warriors to fight our enemies, particularly in the cyber world right now," he told his audience.

"I believe the threat from computer network attack is the most significant threat we face as a civilised world, other than a weapon of mass destruction."

He called on the computer security industry to begin looking at ways of gathering intelligence on possible attacks and attackers, rather than seeking simply to block them when they happen.

"It is not enough to watch the perimeter," Mr Henry said.

"We have to be constantly hunting, looking for tripwires.

"Intelligence is the key to all of this. If we understand who the adversary is, we can take specific actions."

Apple appearance

For the first time, Apple representatives will be speaking at the Black Hat event.

The company is expected to outline security features in the coming release of its latest mobile operating system, iOS.

The appearance comes at a crucial time for Apple. Earlier in the year, the company's Mac range suffered a malware attack, with more than 500,000 machines infected.

The fallout put a dent in Apple's reputation for producing computers that were safe from the kind of attacks which are common on PCs.

According to Black Hat's general manager Trey Ford, Apple was scheduled to appear at the event in 2008, but pulled out after the company's marketing team intervened.

"Bottom line - no-one at Apple speaks without marketing approval," Mr Ford wrote in an email quoted by Bloomberg.

"Apple will be at Black Hat 2012, and marketing is on board."