Twitter releases Android security technology as open source
Twitter made one of its own Android security components available as freely usable source code.
Read the full post19 posts
Projects, Linux, networks, systems, finds and internet standards from 2011.
Twitter made one of its own Android security components available as freely usable source code.
Read the full postRFC 6455 defines persistent, bidirectional message channels after an HTTP-based upgrade handshake. WebSocket adds persistent real-time channels to the request-oriented web. Long-lived connections change scaling, timeouts and security monitoring.
Read the full postJohannes documents how contradictory C++ USE flags and missing symlinks block the AVR cross-compiler on Gentoo. The problem concerned the transition to GCC stage two. Gentoo bug 147155 documents part of the error.
Read the full postThe BR-alpha series traces Werner Heisenberg’s path to quantum mechanics and connects the limits of physical knowledge with philosophy, atomic research and scientific responsibility. The six-part BR-alpha series began on 13 November 2011. Werner Heisenberg received the Nobel Prize in Physics for 1932.
Read the full postThe stlink project replaces vendor-specific Windows tools with free compile, flash and debug workflows for STM32 Discovery boards. The board uses an ARM Cortex-M3. The manufacturer did not support Linux natively at the time.
Read the full postHackaday follows a detailed guide that brings together uClinux, a soft-core processor and custom LED hardware on the DE0-Nano. The DE0-Nano cost about 80 to 100 US dollars at the time. The guide used Fedora 14 as the build system.
Read the full postShortly before Windows 8, Matthew Garrett explains the key model of UEFI Secure Boot and warns that computers with only OEM and Microsoft keys will no longer boot a generic Linux. According to Garrett’s analysis, signed Linux versions fail because of GPL bootloaders, self-built kernels and the lack of a central signing authority. The assessment: it is too early to panic, but not too early to be concerned.
Read the full postLxardoscope uses an Arduino as a two-channel data logger and Linux for display and control. Each channel reaches about 3,000 samples per second. The example uses an Arduino Uno.
Read the full postThe break-in at kernel.org affected central infrastructure without removing the cryptographic verifiability of the kernel code.
Read the full postIn 2011 many routers from Telekom and Vodafone came with a preconfigured WPA key that was in some cases derived from the MAC address of the Wi-Fi interface. Attackers could capture the MAC address and use it to guess the key. Looking at almost 14,000 access points, the students Stefan Viehböck and Manuel Müller found that 17 to 25 percent still used a default Speedport or EasyBox SSID, presumably mostly with the default key.
Read the full postIn August 2011 Linus Torvalds published the first release candidate of Linux 3.1, whose release was planned for early October. The focus was on improvements to virtualisation, including basic nested virtualisation with KVM on Intel processors. Also new were drivers for Realtek’s RTL8192DE and RTL8188DE PCIe Wi-Fi chips.
Read the full postFor Patch Tuesday on 9 August 2011, Microsoft announced 13 bulletins intended to close 22 holes. Among them were critical holes in all versions of Internet Explorer and in most editions of Windows Server, both exploitable remotely for code execution. Further updates concerned Windows, Office 2003 to 2010, .NET 3.5 and Visual Studio 2005.
Read the full postPhilipp Pobaschnig shows why default installations are not a finished security strategy and how small, systematic changes close typical attack paths. Server hardening is a recurring operational process rather than a one-off checklist. The most secure feature is often the service nobody had to install.
Read the full postManuel Schmitt describes joint IPv4 and IPv6 reverse DNS management with search, CSV export and delegation of entire IPv6 networks. The editor supported PTR, CNAME and NS records for IPv6. CSV exports also contained addresses in binary notation.
Read the full postRFC 6265 unifies cookie syntax and browser behaviour for session-related state over HTTP. Automatically attached state makes applications easier and increases CSRF and tracking risks. Secure defaults matter more than policies added later.
Read the full postLinux systems collect distributed sensor values wirelessly and bring them together for evaluation.
Read the full postIn January 2011 ICQ 7.4 appeared with an improved chat history, better Facebook integration and notifications of new mail from Gmail, Yahoo and Mail.ru. Users could switch faster between chat, SMS, voice and video calls. However, the developers had not fixed a known security hole in the auto-update function.
Read the full postFacebook, Google, Yahoo, Akamai, Limelight and the Internet Society declared 8 June 2011 World IPv6 Day. For 24 hours they wanted to offer their main services over IPv6 as well, in order to test the infrastructure under real load. According to Google, only about 0.2 percent of users could use IPv6 at the time, while the last large IPv4 blocks were being allocated.
Read the full postIn January 2011 the free web analytics software Piwik appeared in version 1.1 with security holes closed. As a precaution, the developers had commissioned Stefan Esser’s company SektionEins with a five-day review of the source code. Its hardening advice was incorporated into the new version.
Read the full post