Clémentine Maurice and Daniel Gruss show how repeated memory accesses cause DRAM bit flips and how even JavaScript can become a hardware-level attack surface. Rowhammer.js demonstrated a remote, software-induced hardware fault from JavaScript. Abstraction boundaries do not prevent attacks on shared physical resources.
Daniel Lange and Felix Domke analyse Dieselgate technically, organisationally and procedurally and examine software extracted from real engine control units. For the analysis, control units from eBay and from Volkswagen were read out. Code can reproduce an organisational lie precisely and millions of times.
Hackaday describes LinuxCNC-Features, which creates simple machining sequences, exports them as G-code and visualises them directly in LinuxCNC. At the time of the report, LinuxCNC-Features had been available for about two years. The tool supports milling and turning.
KG explains qubits, superposition, entanglement and quantum algorithms without presenting quantum computers as universally faster machines. New models of computation rarely replace general-purpose computers but shift the limits of selected tasks. The real bottleneck lies between a theoretical algorithm and an error-corrected physical machine.
A handwritten tick-box note transfers Thomas de Maizière’s much-discussed wording about the Hanover terror warning to the harmless question “Will you go out with me?”. The Germany versus Netherlands football match was called off on 17 November 2015. The German interior minister justified withholding details by saying they could unsettle the public.
Johannes reads a cheap soil moisture sensor every two seconds through an analogue Arduino input. The sensor is connected to input A0. The serial output runs at 9600 baud.
Manuel Schmitt adds ECDSA and Ed25519 host keys for comparison to the setup and reinstallation emails for root servers. From September 2015, new root server customers received ECDSA and Ed25519 host keys. This also applied after a reinstallation.
Lenz Grimmer traces the path from local file systems through LVM and cluster file systems to distributed, parallel and fault-tolerant Linux storage. Every additional storage layer trades simplicity for flexibility or resilience. Distribution removes single hardware failures but creates new consistency and operational problems.
The special issue c’t Linux 2015 brought together guides to securing servers and a comparison of ten distributions with long-term support. Further topics were Linux containers, Btrfs as the default file system, console tools and the X11 successor Wayland. In addition there was KDE Plasma 5, a comparison of mail clients and a DVD with eight distributions.
In 2015 Freifunk initiatives provided refugee accommodation in Hamburg, Stuttgart, Hanover, Dortmund and other cities with free Wi-Fi. There was often no internet connection there; the Freifunk volunteers built the infrastructure, partly using directional radio, and financed it through donations. Authorities held back because of the German “Störerhaftung” (secondary liability), which the volunteers circumvented by routing the traffic via VPN to their own provider.
In August 2015 attackers exploited a hole in Firefox’s same-origin policy that only affected versions with the built-in PDF viewer. Code distributed via advertising on a Russian website sent local files to a server in Ukraine. It specifically looked for developer files: on Linux, for example, /etc/passwd, SSH configurations and shell histories; on Windows, FTP and Subversion configurations.
RFC 7540 introduces binary frames, parallel streams and header compression for HTTP. RFC 7540 was superseded by RFC 9113. Multiplexing reduces application delay but remains tied to TCP packet loss.
RFC 7519 defines compact JSON Web Tokens for transferable claims with signature or encryption. Self-contained tokens reduce lookups and make immediate revocation harder. Flexible cryptography requires strict checking of algorithms and claims.
A custom case and oversized heat sinks make a powerful computer very quiet, even under load. The original video has the ID RZoX7glIAS4. Building a case becomes systems engineering as soon as heat paths determine the shape.
Brian Krebs does not warn of a distant IoT risk but of millions of devices that were already reachable and could amplify DDoS attacks. For the report quoted, Arbor Networks surveyed almost 300 organisations. 38 percent reported more than 21 DDoS attacks per month.
In January 2015 O2 tested national roaming with the network of E-Plus, which had belonged to Telefónica since October 2014. Registered customers in the Gummersbach, Siegen and Altenkirchen area could use the E-Plus UMTS network, where O2’s coverage was poorer. LTE was explicitly excluded.
In January 2015 security researcher David Jorm found the first hole in North Korea’s Linux distribution Red Star OS 3.0. The udev rules file 85-hplj10xx.rules was writable by all users, so anyone could add a rule with arbitrary commands. udev executed it with root privileges as soon as a matching HP LaserJet printer (or, after adjustment, any USB device) was connected.
In early 2015 Google published a hole in Windows 8.1 after Microsoft had not closed it within 90 days. Via NtApphelpCacheControl, a user with restricted rights could gain administrator rights. Google’s experts had found the vulnerability at the end of September 2014 and informed Microsoft.