Open letter to the Linux World

So, what is systemd? Well, meet your new God. You may have been praying at the alter of simplicity, but your religion is being deprecated. It likely already happened without your knowledge during an upgrade of your Linux box. systemd is the all knowing, all controlling meta-deity that sees all and supervises all. It’s the new One Master Process that aspires to control everything it can - and it’s already doing a lot. It’s what init would look like if it were a transformer on steroids. It’s complicated, multi-faceted, opaque, and supremely powerful. ...

August 31, 2014 · 1 min · 98 palabras · Nacho Cano

Offline attack shows Wi-Fi routers still vulnerable

The attack exploits weak randomization, or the lack of randomization, in a key used to authenticate hardware PINs on some implementations of Wi-Fi Protected Setup, allowing anyone to quickly collect enough information to guess the PIN using offline calculations. By calculating the correct PIN, rather than attempting to brute-force guess the numerical password, the new attack circumvents defenses instituted by companies. » Offline bruteforce attack on WiFi Protected Setup » Hands-on: hacking WiFi Protected Setup with Reaver< /a> ...

August 30, 2014 · 1 min · 83 palabras · Nacho Cano

The Feynman Lectures on Physics, completely online

Last fall, we let you know that Caltech and The Feynman Lectures Website joined forces to create an online edition of The Feynman Lectures on Physics. They started with Volume 1. And now they’ve followed up with Volume 2 and Volume 3, making the collection complete. » The Feynman Lectures on Physics, Volume I » | The Feynman Lectures on Physics, Volume II » The Feynman Lectures on Physics, Volume III » Free textbooks » | Free ebooks ...

August 30, 2014 · 1 min · 80 palabras · Nacho Cano

Hackers transform a smartphone gyroscope into an always-on microphone

Apps that use your smartphone’s microphone need to ask permission, but the motion sensors? No say-so needed. That might not sound like a big deal, but security researchers from Stanford University and defense firm Rafael have discovered a way to turn Android phone gyroscopes into crude microphones. They call their app ”Gyrophone” and here’s how it works: the tiny gyros in your phone that measure orientation do so using vibrating pressure plates. As it turns out, they can also pick up air vibrations from sounds, and many Android devices can do it in the 80 to 250 hertz range – exactly the frequency of a human voice. ...

August 16, 2014 · 1 min · 112 palabras · Nacho Cano

Reflections on Trusting Trust

You can’t trust code that you did not totally create yourself. (Especially code from companies that employ people like me.) No amount of source-level verification or scrutiny will protect you from using untrusted code. In demonstrating the possibility of this kind of attack, I picked on the C compiler. I could have picked on any program-handling program such as an assembler, a loader, or even hardware microcode. As the level of program gets lower, these bugs will be harder and harder to detect. A well installed microcode bug will be almost impossible to detect. ...

August 15, 2014 · 1 min · 99 palabras · Nacho Cano

The VP of Devil’s Advocacy

The tenth man. If nine of us look at the same information and arrive at the exact same conclusion, it’s the duty of the tenth man to disagree. No matter how improbable it may seem, the tenth man has to start thinking with the assumption that the other nine are wrong. » MG Siegler | techcrunch.com

August 7, 2014 · 1 min · 56 palabras · Nacho Cano

Why the Security of USB Is Fundamentally Broken

That’s the takeaway from findings security researchers Karsten Nohl and Jakob Lell plan to present next week, demonstrating a collection of proof-of-concept malicious software that highlights how the security of USB devices has long been fundamentally broken. The malware they created, called BadUSB, can be installed on a USB device to completely take over a PC, invisibly alter files installed from the memory stick, or even redirect the user’s internet traffic. Because BadUSB resides not in the flash memory storage of USB devices, but in the firmware that controls their basic functions, the attack code can remain hidden long after the contents of the device’s memory would appear to the average user to be deleted. And the two researchers say there’s no easy fix: The kind of compromise they’re demonstrating is nearly impossible to counter without banning the sharing of USB devices or filling your port with superglue. ...

August 2, 2014 · 1 min · 153 palabras · Nacho Cano

Conseguir la lista actualizada de medios AEDE para bloquearlos

La lista de medios asociados a AEDE se puede consultar en su página: www.aede.es/publica/Periodicos_Asociados.asp. Si no queremos visitar ni por error las páginas de dichos medios, tenemos diferentes alternativas, desde scripts de GreaseMonkey para Firefox y complementos para Chrome, hasta añadir los dominios en el fichero /etc/hosts, tal como haríamos si fuesen dominios maliciosos, o incluso complementos para WordPress. Los siguientes comandos nos facilitan descargar la lista de dominios: $ lynx -dump http://www.aede.es/publica/Periodicos_Asociados.asp | \grep -Eo "http://[^/\"]+" | \grep -v aede.es | sort | uniq | awk "{gsub(/http:\/\//, \"\"); print; gsub(/www\./, \"\"); print; }" | sed 's/^/127.0.0.1 /' Una alternativa a lynx sería utilizar el comando curl: ...

July 27, 2014 · 1 min · 177 palabras · Nacho Cano

Hacker a los 70: abuelos de la informática moderna que aún pican código a diario

Estamos tan inmersos en un mundo de electrónica, unos y ceros, que olvidamos lo recientes que son esos inventos que usamos a diario. Los primeros ordenadores personales verdaderamente relevantes nacieron a finales del siglo pasado: el Apple II (1977), el IBM PC (1981), el Commodore 64 (1982), el primer Macintosh (1984)¦ Windows nació aún más tarde, en 1985, como una extensión gráfica del sistema operativo MS-DOS. » David G. Ortiz | yorokobu.es

July 22, 2014 · 1 min · 72 palabras · Nacho Cano

StackOverflow Update: 560M Pageviews A Month, 25 Servers, And It’s All About Performance

The network of sites that make up StackExchange, which includes StackOverflow, is now ranked 54th for traffic in the world; they have 110 sites and are growing at a rate of 3 or 4 a month; 4 million users; 40 million answers; and 560 million pageviews a month. This is with just 25 servers. For everything. That’s high availability, load balancing, caching, databases, searching, and utility functions. All with a relative handful of employees. Now that’s quality engineering. ...

July 21, 2014 · 1 min · 83 palabras · Nacho Cano