Projects, Linux, networks, systems, finds and internet standards from 2013.
Claudio Guarnieri and Morgan Marquis-Boire show how states and commercial vendors use targeted malware for far-reaching surveillance. The talk covers a market for commercial surveillance technology worth billions. Offensive security markets turn vulnerabilities into assets that are kept secret for good.
Read the full post →
J. Alex Halderman presents ZMap, which scans the public IPv4 address space efficiently and thereby makes vulnerability, deployment and remediation measurable across the internet. Tools change research when measurements that used to take months become possible in minutes. Internet-wide visibility turns local misconfigurations into quantifiable global patterns.
Read the full post →
A GPU database system accelerated the TPC-H benchmark considerably compared with CPU-based systems.
Read the full post →
KG condenses the development of the universe from the Big Bang into the distant future and makes unimaginable periods of time comparable. Scales change meaning, because the same span of time seems tiny or overwhelming depending on the frame of reference. A temporal perspective links scientific facts with the question of human responsibility.
Read the full post →
Before Target’s public confirmation, Brian Krebs reports on card data stolen on a massive scale and shows the value of independent sources during ongoing security incidents. Target confirmed up to 40 million affected card accounts the following day. The confirmed attack window ran from 27 November to 15 December.
Read the full post →
DIYP adapts a large CPU cooler for a graphics card and achieves unusually low temperatures with it. The original video has the ID Iegpwo9SqSg. Unconventional combinations of parts can unlock thermal headroom cheaply.
Read the full post →
Hackaday presents playable Csound instruments for Raspberry Pi and BeagleBone and combines embedded Linux with algorithmic sound generation. The examples run on Raspberry Pi and BeagleBone. Csound is an audio programming language.
Read the full post →
In August 2013 PuTTY 0.63 closed four holes rated as critical in the SSH client widely used on Windows. They affected the modmul function, the handling of public key signatures, buffer overflows when checking DSA signatures, and the wiping of session keys and passphrases from memory. Since PuTTY had not been updated since 2011 and has no update function, users had to act themselves.
Read the full post →
In 2013 Linux 3.11 allowed temporary files that are not visible in the file system at all. For this purpose the open() and openat() system calls received the O_TMPFILE flag. This removes the basis for attacks in which attackers gain higher privileges via predictable names of temporary files, for example using symlinks.
Read the full post →
In August 2013 Greg Kroah-Hartman announced plans to maintain Linux 3.10 for two years as a longterm kernel; the LTSI kernel for device manufacturers was also to be based on it. Alongside it, the longterm branches 3.0, 3.2 and 3.4 continued with different end dates. Ben Hutchings wanted to maintain 3.2 until about 2016 because Debian 7 was based on it.
Read the full post →
The Ruby tool Hacklet switches wireless Modlet sockets and reads their power consumption via a USB dongle. A starter kit cost about 60 US dollars. One Modlet device controls two sockets.
Read the full post →
RFC 6973 provides systematic guidance for spotting privacy consequences as early as protocol design. Privacy is an architectural property and not just a user interface option. Unintended linkability often comes from identifiers that stay stable for a long time.
Read the full post →
Long before Snowden, the hacker community inferred comprehensive surveillance from technical possibilities and observations.
Read the full post →
Manuel Schmitt looks at the Raspberry Pi as a home server and explains why its small size only reduces hosting costs to a limited extent. Manuel planned to test the Raspberry Pi as a media server. The article names SMB and FTP as possible services.
Read the full post →
The forensic case study reconstructs a server break-in and the steps needed for a secure reinstallation.
Read the full post →
Johannes replaces the broken Windows of an Acer easyStore H340 with OpenMediaVault and sets up a mirrored data volume. The NAS has two hard drives of one terabyte each. The operating system initially runs from an external USB stick.
Read the full post →
In January 2013 Alan Cox announced a withdrawal for family reasons, giving up the job at Intel and kernel development. Cox, 44 at the time, had long been regarded as number two after Linus Torvalds and had been working on the kernel for Intel since 2008. Shortly before, Cox had criticised Fedora 18 as the “worst version I have ever seen”.
Read the full post →
In January 2013 an already actively exploited hole became known in the Security Manager of Java 7 up to and including Update 10. A combination of JMX MBean and internal JavaScript classes in an applet could be used to bypass the Security Manager and execute code from websites. US-CERT recommended disabling Java in the browser; there was no patch from Oracle yet.
Read the full post →
In January 2013 OpenVPN 2.3.0 appeared with full IPv6 support, as developer Gert Doering announced. A serious bug in the last beta version had delayed the release by a few days. Also new was the optional use of PolarSSL, which the Dutch government had already been using since 2011 as OpenVPN-NL.
Read the full post →