Your Cisco phone is listening to you: 29C3 talk on breaking Cisco phones

Here’s a video of Ang Cui and Michael Costello’s Hacking Cisco Phones talk at the 29th Chaos Communications Congress in Berlin. Cui gave a show-stealing talk last year on hacking HP printers, showing that he could turn your printer into a inside-the-firewall spy that systematically breaks vulnerable machines on your network, just by getting you to print out a document. Cui’s HP talk showed how HP had relied upon the idea that no one would ever want to hack a printer as its primary security. With Cisco, he’s looking at a device that was designed with security in mind. The means by which he broke the phone’s security is much more clever, and makes a fascinating case-study into the cat-and-mouse of system security. Even more interesting is the discussion of what happened when Cui disclosed to Cisco, and how Cisco flubbed the patch they released to keep his exploit from working, and the social issues around convincing people that phones matter. We discuss a set of 0-day kernel vulnerabilities in CNU (Cisco Native Unix), the operating system that powers all Cisco TNP IP phones. We demonstrate the reliable exploitation of all Cisco TNP phones via multiple vulnerabilities found in the CNU kernel. We demonstrate practical covert surveillance using constant, stealthy exfiltration of microphone data via a number of covert channels. We also demonstrate the worm-like propagation of our CNU malware, which can quickly compromise all vulnerable Cisco phones on the network. We discuss the feasibility of our attacks given physical access, internal network access and remote access across the internet. Lastly, we built on last year’s presentation by discussing the feasibility of exploiting Cisco phones from compromised HP printers and vice versa. We present the hardware and software reverse-engineering process which led to the discovery of the vulnerabilities described below. We also present methods of exploiting the following vulnerabilities remotely. Hacking Cisco Phones [29C3] ( Thanks, Ang! )

Read this article:
Your Cisco phone is listening to you: 29C3 talk on breaking Cisco phones

13 Technologies You Won’t See in 2013

It seems like only yesterday we were planning for the Mayan apocalypse, but like so many other products, the 14th b’ak’tun (next era) has been delayed due to bugs and lack of pre-orders. Yet if you talked to some pundits back in 2011, they’d have told you that the end of days was coming out in Q4 of 2012, along with its competitor, BlackBerry 10. More »

Excerpt from:
13 Technologies You Won’t See in 2013

This Crazy Map Has One Dot for Every Person in the United States

The amount of people in the whole world is pretty wildly unfathomable. For that matter, even a subset like just the 300,000,000 or so that live in the United States can be hard to wrap your head around. This interactive map by Brandon M-Anderson helps by showing one dot for each of them . It’s pretty wild. More »

See original article:
This Crazy Map Has One Dot for Every Person in the United States

China’s Princelings: descendants of Mao’s generals who control the country’s wealth

This long-read from Bloomberg about China’s “Princelings” — the generation of hyper-rich oligarchs’ children, descended from Mao’s generals — is endlessly fascinating. Wealth in China is even more concentrated than Russia, Brazil or the USA, and the Chinese looter-class use complex screens that take advantage of different ways of representing their names in English, Cantonese and Mandarin to obscure the ownership of former state assets, flogged at pennies on the dollar in sweetheart deals for the hyper-privileged. The Princelings are western-educated, mostly in the USA, and flaunt expensive luxury-brand accessories on their social media profiles. The accompanying interactive graphic lets you explore the intertwining relationships between the families of the “eight immortals.” Opportunities for the princelings surged in the 1990s after Deng kick-started another wave of economic changes. They jumped into booming industries including commodities and real estate as new factories and expanding cities transformed China’s landscape. Two of Deng’s children — Deng Rong, 62, and her brother, Deng Zhifang — were among the first to enter real estate, even before new rules in 1998 commercialized the mainland’s mass housing market. Two years after Deng Rong accompanied her father on his famous 1992 tour of southern China to showcase the success of emerging export center Shenzhen, she was in Hong Kong to promote a new development she headed in Shenzhen. Some apartments in the 32-story complex were priced at about $240,000 each, according to a front-page story in the South China Morning Post. Corporate records show that by the late 1990s half of the company was owned by two people with the same names as Deng Rong’s sister-in-law, Liu Xiaoyuan, and the granddaughter of Wang Zhen, Wang Jingjing. Deng Rong and Deng Zhifang didn’t respond to questions sent by fax to their respective offices in Beijing. Liu couldn’t be reached for comment through one of the companies with which she’s associated. Wang Jingjing didn’t respond to questions couriered to her office in the Chinese capital and a reporter who visited on two occasions was told she wasn’t there. Heirs of Mao’s Comrades Rise as New Capitalist Nobility [Bloomberg News]

View original post here:
China’s Princelings: descendants of Mao’s generals who control the country’s wealth

Linus Chews Up Kernel Maintainer For Introducing Userspace Bug

An anonymous reader points out just how thick a skin it takes to be a kernel developer sometimes, linking to a chain of emails on the Linux Kernel Mailing List in which Linus lets loose on a kernel developer for introducing a change that breaks userspace apps (in this case, PulseAudio). “Shut up, Mauro. And I don’t _ever_ want to hear that kind of obvious garbage and idiocy from a kernel maintainer again. Seriously. I’d wait for Rafael’s patch to go through you, but I have another error report in my mailbox of all KDE media applications being broken by v3.8-rc1, and I bet it’s the same kernel bug. And you’ve shown yourself to not be competent in this issue, so I’ll apply it directly and immediately myself. WE DO NOT BREAK USERSPACE! Seriously. How hard is this rule to understand? We particularly don’t break user space with TOTAL CRAP. I’m angry, because your whole email was so _horribly_ wrong, and the patch that broke things was so obviously crap. … The fact that you then try to make *excuses* for breaking user space, and blaming some external program that *used* to work, is just shameful. It’s not how we work,” writes Linus, and that’s just the part we can print. Maybe it’s a good thing, but there’s certainly no handholding when it comes to changes to the heart of Linux. Read more of this story at Slashdot.

See more here:
Linus Chews Up Kernel Maintainer For Introducing Userspace Bug