Fitbit trackers can be hacked in ’10 seconds’

Fitbit trackers have a whopper of a vulnerability that can let somebody within Bluetooth range quickly hack them, according to security company Fortinet . Worse yet, once the attackers are in, the device will infect any computer that tries to sync with the device. Via Twitter , Senior Fortinet researcher Axelle Apvrille told Engadget “you don’t need physical access (to the tracker), but you do need to be close (Bluetooth range). It does not matter if it is paired (to another device) or not.” When in range, a bad actor could infect the device in as little as 10 seconds. Apvrille informed Fitbit of the vulnerability back in March, but the wearable outfit has yet to fix the issue, according to the Register . In addition, the vulnerability remains in the wearable even after it’s reset. Once infected, the device can install a virus, trojan or other vulnerability on your computer, even days later. “An attacker sends an infected packet to a fitness tracker nearby at Bluetooth distance then the rest of the attack occurs by itself, without any special need for the attacker being near, ” Apvrille said . While the Fitbit uses encryption, the Bluetooth transmitter itself is apparently wide open, allowing attackers in. If you want to find out more, Apvrille will present her findings via a video demonstration at the 2015.Hack.lu conference tomorrow in Luxembourg. @AaronIsSocial you don’t need physical access, but you need to be close (bluetooth range). It does not matter if it is paired or not. — Axelle Ap. (@cryptax) October 21, 2015 Via: The Register Source: Axelle Apvrille (Twitter)

View post:
Fitbit trackers can be hacked in ’10 seconds’

How We Figure Out the Composition of a Substance by Hurling Neutrons at It

Archaeologists can figure out how old a substance is by radiocarbon dating, but to do that they need to know what the substance is—and that’s not always clear. Radioactive material comes to the rescue again! Read more…

Continue Reading:
How We Figure Out the Composition of a Substance by Hurling Neutrons at It

iOS and OS X updates arrive with a ton of new emoji

If you’ve ever wanted to text taco pics from your iPhone or give the middle finger from your Mac, today’s your lucky day. Apple has released iOS 9.1 and OS X El Capitan 10.11.1 , both of which add a slew of new Unicode emoji ranging from Mexican food through to rude gestures. There are some important under-the-hood fixes, too. Your iPhone 6s or 6s Plus is now smart enough to stop recording Live Photos when you lower the device, and OS X shouldn’t run into trouble with Office 2016 . Whichever platform you’re using, you’ll likely want to update pronto — if just to see the cutesy characters you’d otherwise miss. [Image credit: Emojipedia ] Source: MacRumors (1) , (2)

Continued here:
iOS and OS X updates arrive with a ton of new emoji

Support scams that plagued Windows users for years now target Mac customers

Enlarge (credit: Malwarebytes) For years, scammers claiming that they’re “calling from Windows” have dialed up Microsoft customers and done their best to trick them into parting with their money or installing malicious wares. Now, the swindlers are turning their sights on Mac users. Researchers at antivirus provider Malwarebytes spotted a Web-based campaign that attempts to trick OS X and iOS users into thinking there’s something wrong with their devices . The ruse starts with a pop-up window that’s designed to look like an official OS notification. “Critical Security Warning!” it says. “Your Device (iPad, iPod, iPhone) is infected with a malicious adward [sic] attack.” It goes on to provide a phone number people can call to receive tech support. The site ara-apple.com is designed to masquerade as https://ara.apple.com/ , Apple’s official remote technical support page. People who are experiencing problems with their Macs can go there to get an official Apple tech support provider to remotely access the person’s computer desktop. Ara-apple provides links to the remote programs the supposed technician will use to log in to targets’ Macs. Read 1 remaining paragraphs | Comments

Read this article:
Support scams that plagued Windows users for years now target Mac customers

Build a Simple Door Detector with IFTTT Alerts Using an Arduino

One of the essential parts of any home security system is a door detector that lets you know when a door opens. Over on Adafruit, they show you how to build your own that hooks into IFTTT so you can be alerted any way you like when the door opens. Read more…

Follow this link:
Build a Simple Door Detector with IFTTT Alerts Using an Arduino

14 Things You Can Do in Android Marshmallow That You Couldn’t Do in Lollipop

Whether you’ve put in an order for a Nexus 6P or you’re patiently waiting for Android version 6.0 to reach your Galaxy S6 , you’ll want to know what Marshmallow can do for you. It’s not a dramatic leap forward for Google’s mobile OS, but there are still a number of useful new features you’re going to want to know about. Read more…

View original post here:
14 Things You Can Do in Android Marshmallow That You Couldn’t Do in Lollipop

The Keurig Kold Is A Space Oddity In The World Of Soft Drinks

 The Keurig Kold is such an odd product that it almost looks like it came from an distant world where no one cares about corn syrup ingestion. Clad in white plastic and covered in grills, the case is far bigger than anything else in your kitchen and makes a noise like Darth Vader taking a nap. It takes two hours to prime and then, in a minute or so, can produce a glass of fizzy beverage without… Read More

See the original article here:
The Keurig Kold Is A Space Oddity In The World Of Soft Drinks

Breaking 512-bit RSA with Amazon EC2 is a cinch. So why all the weak keys?

(credit: martinak15 ) The cost and time required to break 512-bit RSA encryption keys has plummeted to an all-time low of just $75 and four hours using a recently published recipe that even computing novices can follow. But despite the ease and low cost, reliance on the weak keys to secure e-mails, secure-shell transactions, and other sensitive communications remains alarmingly high. The technique, which uses Amazon’s EC2 cloud computing service , is described in a paper published last week titled Factoring as a Service . It’s the latest in a 16-year progression of attacks that have grown ever faster and cheaper. When 512-bit RSA keys were first factored in 1999, it took a supercomputer and hundreds of other computers seven months to carry out. Thanks to the edicts of Moore’s Law – which holds that computing power doubles every 18 months or so – the factorization attack required just seven hours and $100 in March, when “FREAK,” a then newly disclosed attack on HTTPS-protected websites with 512-bit keys , came to light. In the seven months since FREAK’s debut, websites have largely jettisoned the 1990s era cipher suite that made them susceptible to the factorization attack. And that was a good thing, since the factorization attack made it easy to obtain the secret key needed to cryptographically impersonate the webserver or to decipher encrypted traffic passing between the server and end users. But e-mail servers, by contrast, remain woefully less protected. According to the authors of last week’s paper, the RSA_EXPORT cipher suite is used by an estimated 30.8 percent of e-mail services using the SMTP protocol , 13 percent of POP3S servers . and 12.6 percent of IMAP-based e-mail services . Read 6 remaining paragraphs | Comments

See more here:
Breaking 512-bit RSA with Amazon EC2 is a cinch. So why all the weak keys?

This Discounted, 4TB External Drive Doesn’t Need a Power Cord

It wasn’t long ago that portable, USB-powered external hard drives maxed out at 2TB, but Seagate’s new Backup Plus manages to double that, and you can pick one up for an all-time low $150 today. That price even includes 200GB of Microsoft OneDrive storage for two years, which is a $96 value on its own. Read more…

Read the original post:
This Discounted, 4TB External Drive Doesn’t Need a Power Cord