CCC hackers break the security of DECT phones
CCC researchers demonstrated that calls on many DECT cordless phones could be eavesdropped on in practice.
Read the full post18 posts
Projects, Linux, networks, systems, finds and internet standards from 2008.
CCC researchers demonstrated that calls on many DECT cordless phones could be eavesdropped on in practice.
Read the full postAn international team of researchers demonstrates how MD5 collisions made a validly signed intermediate certificate for a rogue certificate authority possible. The attack produced a fraudulent CA certificate that browsers would accept. System-wide security follows the weakest algorithm that is still accepted.
Read the full postbushing and marcan take apart the security architecture of the Nintendo Wii and show how several implementation errors rendered an impressive chain of trust useless. Several layers of protection do not help if they share the same unchecked assumption. Mass-market hardware turns rare implementation errors into permanently available research objects.
Read the full postAcceptEx moves accepting data into the Windows kernel but creates difficult socket semantics and error cases.
Read the full postHackaday shows OpeniBoot, which boots Linux 2.6 and BusyBox on early iPhones and the first iPod Touch. Touchscreen support was still missing. First and second generation iPhones were supported.
Read the full postDavide R mounts PC components on a VARIERA kitchen insert and gets an airy, visible barebone case. An IKEA VARIERA insert serves as the base. The system remains completely open.
Read the full postRFC 5321 describes SMTP for relaying, delivery, queueing and error handling between mail servers. Email is a federated queueing system rather than a direct end-to-end connection. Deliverability combines protocol compliance with reputation and abuse protection.
Read the full postHackaday describes a spectrum analyser and function generator on a PlayStation 3 with Yellow Dog Linux and an external USB sound card. The project uses Yellow Dog Linux. The measurement bandwidth remains limited to audio frequencies.
Read the full postThe Kernel-Log of August 2008 presented Jon Corbet’s guide “How to Participate in the Linux Community”, which explains the kernel development process to newcomers and companies. In addition, the Synaptics touchpad driver 0.15.0 appeared for the first time under the MIT licence in the X.org project. With Linux 2.6.27-rc3 the auerswald ISDN driver was dropped, and support for Intel’s upcoming Ibex Peak chipsets was added.
Read the full postOnly three weeks after its presentation in 2008, the kernel developers accepted the ath9k driver for Atheros draft-N Wi-Fi chips into the main branch for Linux 2.6.27. Initially it only supported client mode; mesh, AP and monitor modes were planned. The Kernel-Log also pointed to reading material such as the OLS 2008 talks and an ACM special issue on the CFS scheduler, readahead and virtio.
Read the full postIn Dublin in 2008 the IETF discussed how IPv4 devices could continue to communicate during the transition to IPv6, since all 4.3 billion IPv4 addresses were expected to be allocated in around three years. Comcast engineer Alain Durand presented “Dual-Stack Lite”: IPv4 is tunnelled through the provider’s IPv6 network and translated there using carrier-grade NAT. Experts such as Fred Baker and Gert Döring warned that such NAT could delay IPv6 and called for native deployment.
Read the full postRFC 5246 standardises TLS 1.2 and shaped encrypted communication on the web for many years. RFC 5246 was superseded by RFC 8446. Protocol security also depends on algorithm selection and implementation.
Read the full postA Qwerk controller combines Linux, Wi-Fi, servos and a modified webcam into a remote-controlled infrared robot. The robot uses model aircraft wheels. Webcam and Wi-Fi adapter work over USB.
Read the full postManuel Schmitt warns customers about predictable keys from faulty Debian and Ubuntu versions and names check tools and replacement steps. Keys for OpenSSH and web server certificates, among others, were affected. The article points to the Debian tool vulnkey and other ways of checking.
Read the full postTen SSH techniques improve secure login, tunnels, key management and recurring remote maintenance tasks.
Read the full postIn January 2008 Linux 2.6.24 brought additional Wi-Fi drivers for the new Wi-Fi subsystem and the power-saving tickless feature for further architectures besides x86. The Completely Fair Scheduler introduced with 2.6.23 was optimised and learned fair group scheduling. This allowed priorities to be assigned to users or process groups, for example to favour multimedia or compilers.
Read the full postIn January 2008 the PostgreSQL developers closed five critical holes in all maintained versions from 7.3 to 8.2. Via expression indexes and DBLink functions, attackers could gain administrator rights, and via regular expressions they could bring the server down with a denial of service. The holes were found in the project’s own analyses, and no exploits were known.
Read the full postIn 2008 Abdel Benamrouche adapted the very first Linux kernel 0.01 so that it could be compiled with GCC 4.x and booted in emulators such as QEMU and Bochs. Bash 3.2, Coreutils 6.9, Vim 7.1 and other tools were also to run on it. Benamrouche provided a floppy and hard disk image for QEMU for download.
Read the full post