Bluetooth is about to become a lot less hassle-prone. The wireless standard’s Special Interest Group has officially adopted the Bluetooth 5 spec, clearing the way for device makers to use the much-improved technology in everything from phones to wearables to smart home equipment. This doesn’t mean that you’ll see it right away, of course. The group expects Bluetooth 5-equipped products to hit the market in the next 2 to 6 months, or right around when the next wave of smartphones is likely to arrive. Again, the new spec is all about raw performance. You can expect up to four times the range, twice the speed and eight times the amount of data in broadcast messages. Those will be particularly helpful for smart appliances and the Internet of Things , where the existing Bluetooth 4.2 standard might not be powerful enough to connect an entire home. However, it should also make a difference anywhere that you notice Bluetooth’s existing limitations. Smartwatches could see a serious upgrade, for example — one of the biggest bottlenecks on wristwear is the slow connection to your phone. And regardless of the device you use, there are techniques to reduce interference with other wireless devices. Just don’t expect much of a boost to audio quality. While Bluetooth 5 could help with range, you won’t see improvements to audio compression, latency and power use until 2018. The newly adopted format is primarily about dragging Bluetooth’s range and speed into the modern era, and future efforts will build on top of that groundwork. Source: Bluetooth SIG
Read the original post:
Bluetooth 5’s faster, longer-ranged wireless is here
An anonymous reader quotes a report from BleepingComputer: For the past two months, a new exploit kit has been serving malicious code hidden in the pixels of banner ads via a malvertising campaign that has been active on several high profile websites. Discovered by security researchers from ESET, this new exploit kit is named Stegano, from the word steganography, which is a technique of hiding content inside other files. In this particular scenario, malvertising campaign operators hid malicious code inside PNG images used for banner ads. The crooks took a PNG image and altered the transparency value of several pixels. They then packed the modified image as an ad, for which they bought ad displays on several high-profile websites. Since a large number of advertising networks allow advertisers to deliver JavaScript code with their ads, the crooks also included JS code that would parse the image, extract the pixel transparency values, and using a mathematical formula, convert those values into a character. Since images have millions of pixels, crooks had all the space they needed to pack malicious code inside a PNG photo. When extracted, this malicious code would redirect the user to an intermediary ULR, called gate, where the host server would filter users. This server would only accept connections from Internet Explorer users. The reason is that the gate would exploit the CVE-2016-0162 vulnerability that allowed the crooks to determine if the connection came from a real user or a reverse analysis system employed by security researchers. Additionally, this IE exploit also allowed the gate server to detect the presence of antivirus software. In this case, the server would drop the connection just to avoid exposing its infrastructure and trigger a warning that would alert both the user and the security firm. If the gate server deemed the target valuable, then it would redirect the user to the final stage, which was the exploit kit itself, hosted on another URL. The Stegano exploit kit would use three Adobe Flash vulnerabilities (CVE-2015-8651, CVE-2016-1019 or CVE-2016-4117) to attack the user’s PC, and forcibly download and launch into execution various strains of malware. Read more of this story at Slashdot.