Offline attack shows Wi-Fi routers still vulnerable

The attack exploits weak randomization, or the lack of randomization, in a key used to authenticate hardware PINs on some implementations of Wi-Fi Protected Setup, allowing anyone to quickly collect enough information to guess the PIN using offline calculations. By calculating the correct PIN, rather than attempting to brute-force guess the numerical password, the new attack circumvents defenses instituted by companies. » Offline bruteforce attack on WiFi Protected Setup » Hands-on: hacking WiFi Protected Setup with Reaver< /a> ...

August 30, 2014 · 1 min · 83 palabras · Nacho Cano

The Feynman Lectures on Physics, completely online

Last fall, we let you know that Caltech and The Feynman Lectures Website joined forces to create an online edition of The Feynman Lectures on Physics. They started with Volume 1. And now they’ve followed up with Volume 2 and Volume 3, making the collection complete. » The Feynman Lectures on Physics, Volume I » | The Feynman Lectures on Physics, Volume II » The Feynman Lectures on Physics, Volume III » Free textbooks » | Free ebooks ...

August 30, 2014 · 1 min · 80 palabras · Nacho Cano

Hackers transform a smartphone gyroscope into an always-on microphone

Apps that use your smartphone’s microphone need to ask permission, but the motion sensors? No say-so needed. That might not sound like a big deal, but security researchers from Stanford University and defense firm Rafael have discovered a way to turn Android phone gyroscopes into crude microphones. They call their app ”Gyrophone” and here’s how it works: the tiny gyros in your phone that measure orientation do so using vibrating pressure plates. As it turns out, they can also pick up air vibrations from sounds, and many Android devices can do it in the 80 to 250 hertz range – exactly the frequency of a human voice. ...

August 16, 2014 · 1 min · 112 palabras · Nacho Cano

Reflections on Trusting Trust

You can’t trust code that you did not totally create yourself. (Especially code from companies that employ people like me.) No amount of source-level verification or scrutiny will protect you from using untrusted code. In demonstrating the possibility of this kind of attack, I picked on the C compiler. I could have picked on any program-handling program such as an assembler, a loader, or even hardware microcode. As the level of program gets lower, these bugs will be harder and harder to detect. A well installed microcode bug will be almost impossible to detect. ...

August 15, 2014 · 1 min · 99 palabras · Nacho Cano

The VP of Devil’s Advocacy

The tenth man. If nine of us look at the same information and arrive at the exact same conclusion, it’s the duty of the tenth man to disagree. No matter how improbable it may seem, the tenth man has to start thinking with the assumption that the other nine are wrong. » MG Siegler | techcrunch.com

August 7, 2014 · 1 min · 56 palabras · Nacho Cano

Why the Security of USB Is Fundamentally Broken

That’s the takeaway from findings security researchers Karsten Nohl and Jakob Lell plan to present next week, demonstrating a collection of proof-of-concept malicious software that highlights how the security of USB devices has long been fundamentally broken. The malware they created, called BadUSB, can be installed on a USB device to completely take over a PC, invisibly alter files installed from the memory stick, or even redirect the user’s internet traffic. Because BadUSB resides not in the flash memory storage of USB devices, but in the firmware that controls their basic functions, the attack code can remain hidden long after the contents of the device’s memory would appear to the average user to be deleted. And the two researchers say there’s no easy fix: The kind of compromise they’re demonstrating is nearly impossible to counter without banning the sharing of USB devices or filling your port with superglue. ...

August 2, 2014 · 1 min · 153 palabras · Nacho Cano

Hacker a los 70: abuelos de la informática moderna que aún pican código a diario

Estamos tan inmersos en un mundo de electrónica, unos y ceros, que olvidamos lo recientes que son esos inventos que usamos a diario. Los primeros ordenadores personales verdaderamente relevantes nacieron a finales del siglo pasado: el Apple II (1977), el IBM PC (1981), el Commodore 64 (1982), el primer Macintosh (1984)¦ Windows nació aún más tarde, en 1985, como una extensión gráfica del sistema operativo MS-DOS. » David G. Ortiz | yorokobu.es

July 22, 2014 · 1 min · 72 palabras · Nacho Cano

StackOverflow Update: 560M Pageviews A Month, 25 Servers, And It’s All About Performance

The network of sites that make up StackExchange, which includes StackOverflow, is now ranked 54th for traffic in the world; they have 110 sites and are growing at a rate of 3 or 4 a month; 4 million users; 40 million answers; and 560 million pageviews a month. This is with just 25 servers. For everything. That’s high availability, load balancing, caching, databases, searching, and utility functions. All with a relative handful of employees. Now that’s quality engineering. ...

July 21, 2014 · 1 min · 83 palabras · Nacho Cano

Sarah Harrison: ”No poder negar la verdad es lo que más les aterra”

Lo mismo sucede con el término de ”seguridad nacional” ampliamente utilizado desde la aparición de los documentos de la NSA. ”El término en sí significa proteger la estabilidad de tu país dentro de tus fronteras, por tanto no hay razón para vigilar a todo un país o invadir todo un país. Lo que hacen es utilizarlo como término universal para asustar a la gente evitando que publiquen la verdad y permitiéndoles tapar sus propios actos ilegales”, y recuerda como en pro de esta seguridad nacional, la agencia de seguridad nacional britanica irrumpió el pasado agosto en la redacción del diario estadounidense The Guardian y destruyó discos duros y documentación, en un ”extraordinario acto contra la libertad de prensa”. ”Y eso pasó en un país occidental, pero era por la seguridad nacional”. ...

July 21, 2014 · 1 min · 149 palabras · Nacho Cano

El Gobierno de España está librando una guerra en contra del internet y tú eres la víctima

El canon AEDE se aprobaría el martes 22 de julio y sus implicaciones son mucho más grandes de lo que parece. Tasar el derecho a cita y legalizar medidas que atentan contra la libertad de expresión en internet. En este caso, la víctima eres tú. » Eduardo Arcos | alt1040.com

July 21, 2014 · 1 min · 50 palabras · Nacho Cano