Projects, Linux, networks, systems, finds and internet standards from 2014.
Zakir Durumeric examines Heartbleed with internet-wide measurements and shows its spread, key risks, speed of response and the vulnerable systems that remained. Small memory bugs can trigger global infrastructure crises through widely used libraries. An effective response needs inventory, patching, key changes and transparent communication together.
Read the full post →
Linux 3.19 prepared new graphics, storage, networking and hardware features for early 2015.
Read the full post →
After Shahar Tal’s DEF CON talk about holes in TR-069 remote maintenance servers, heise asked German providers in 2014 how they were protected. Telekom, Vodafone, 1&1 and others considered their networks secure because their routers reject self-signed certificates or only contact preset servers. Tal had shown that a hijacked Auto Configuration Server can redirect or read out thousands of routers.
Read the full post →
In 2014 heise Security found a hole in the MyFritz apps for Android and iOS through which attackers could access a FritzBox’s web interface without a password. The apps did not check the box’s SSL certificate sufficiently, so an attacker on someone else’s network could grab the session ID. AVM solved this with certificate pinning: the apps remember the certificate’s fingerprint on first contact and warn if it changes.
Read the full post →
In 2014 researchers at the French institute Eurécom automatically analysed 32,356 firmware files of networked devices. 693 images contained at least one hole, 38 of them previously unknown; more than 300 showed signs of backdoors, for example in a device from the Belkin Wemo series. They also collected 109 private RSA keys from more than 400 images.
Read the full post →
A used RAMVIK coffee table becomes a large computer case with visible hardware and integrated water cooling. The table cost 30 British pounds second-hand. The system uses water cooling.
Read the full post →
LibreSSL chose the small Signify instead of GnuPG to sign releases with less cryptographic complexity.
Read the full post →
KG explains the multi-stage immune defence as a coordinated interplay of barriers, phagocytes, messenger substances and specialised lymphocytes. Robust defence comes from overlapping layers rather than from a single perfect protective mechanism. Biological security has to remove intruders without excessively damaging its own organism.
Read the full post →
Maker Works builds a rigid CNC plasma router with servo drives, gear reduction and LinuxCNC as an open machine control. The project cost about 8,000 US dollars. X and Y use NEMA 34 servo motors.
Read the full post →
RFC 7258 explicitly declares large-scale passive monitoring a form of attack that protocol design must take into account. Threat models have to include powerful global observers. Encryption by default changes privacy for the whole network.
Read the full post →
Using a Raspberry Pi and a stepper motor, Hackaday explains why normal Linux fluctuates and which measures improve soft real-time behaviour. The experiment uses a 28BYJ-48 stepper motor. A ULN2003 drives its windings.
Read the full post →
Matthew Garrett summarises MITRE’s research from SyScan 2014: on many computers, Secure Boot can be bypassed from within the running operating system. The cause is not the cryptography but wrongly stored policies and missing lock bits in the chipset. Garrett still considers Secure Boot a real security gain whose obvious flaws will only disappear over several hardware generations.
Read the full post →
Manuel Schmitt describes an automated data centre scan for Heartbleed and the subsequent warning of affected customers. The scan covered HTTPS, IMAPS, POP3S, SMTP, submission, IMAP and POP3 with TLS. Affected customers were warned by email.
Read the full post →
The video shows a mechanical emergency method for hard drives whose read/write heads are stuck on the platters. The original video has the ID F5Y7BniaRXg. A risky DIY repair is only suitable when professional recovery is out of the question.
Read the full post →
nftables bundles packet filtering in a unified kernel infrastructure and replaces several older iptables tools.
Read the full post →
Hackaday traces the development from the teleprinter to the Unix terminal layer and explains historical terms in modern consoles. TTY stands for teletypewriter. Linux keeps a TTY subsystem layer of its own.
Read the full post →
In January 2014 OpenSSH 6.5 brought key exchange with Curve25519 and signatures with Ed25519, both developed by Daniel J. Bernstein. One reason was the Snowden revelations, since the widely used NIST curves came from an NSA employee. Ed25519 replaces ECDSA, which is vulnerable when random number generators are weak.
Read the full post →
According to the Norwegian newspaper Aftenposten, the British intelligence service pushed in the 1980s for GSM to be only weakly encrypted. Originally the standard was to offer 128 bits, but A5/1 ended up with an effective 54 bits; the British even wanted only 48 bits. Germany, fearing espionage by the Eastern Bloc, pushed for stronger encryption.
Read the full post →
Around the turn of 2013/2014, Eloi Vanderbeken discovered a backdoor on port 32764 on a Linksys WAG200G router. A script made it possible to execute commands and read out the configuration including passwords. Numerous models from Linksys, Netgear, Cisco and Diamond were apparently affected, presumably because of shared DSL modems from the Taiwanese manufacturer Sercomm.
Read the full post →