The Ars guide to building a Linux router from scratch

The Homebrew Special—looking a bit blurry, because I wanted to take a low-light shot to try to capture the disco glow. 2 more images in gallery After finally reaching the tipping point with off-the-shelf solutions that can’t match increasing speeds available, we recently took the plunge. Building a homebrew router  turned out to be a better proposition than we could’ve ever imagined. With nearly any speed metric we analyzed, our little DIY kit outpaced routers whether they were of the $90- or $250-variety. Naturally, many readers asked the obvious follow-up—”How exactly can we  put that together?” Today it’s time to finally pull back the curtain and offer that walkthrough. By taking a closer look at the actual build itself (hardware and software), the testing processes we used, and why we used them, hopefully any Ars readers of average technical abilities will be able to put together their own DIY speed machine. And the good news? Everything is as open source as it gets—the equipment, the processes, and the setup. If you want the DIY router we used, you can absolutely have it. This will be the guide to lead you, step-by-step. What is a router, anyway? At its most basic, a router is just a device that accepts packets on one interface and forwards them on to another interface that gets those packets closer to their eventual destination. That’s not what most of us are really thinking when we think of “a router” in the sense of something we’ll plug into our home or office to get to the Internet, though. What do we need to have before any homebrew device looks like a router? Read 66 remaining paragraphs | Comments

View post:
The Ars guide to building a Linux router from scratch

Out-of-date apps put 3 million servers at risk of crypto ransomware infections

(credit: Dr F. Eugene Hester, U.S. Fish and Wildlife Service) More than 3 million Internet-accessible servers are at risk of being infected with crypto ransomware because they’re running vulnerable software, including out-of-date versions of Red Hat’s JBoss enterprise application , researchers from Cisco Systems said Friday. About 2,100 of those servers have already been compromised by webshells that give attackers persistent control over the machines, making it possible for them to be infected at any time, the Cisco researchers reported in a blog post . The compromised servers are connected to about 1,600 different IP addresses belonging to schools, governments, aviation companies, and other types of organizations. Some of the compromised servers belonged to school districts that were running the Destiny management system that many school libraries use to keep track of books and other assets. Cisco representatives notified officials at Destiny developer Follett Learning of the compromise, and the Follett officials said they fixed a security vulnerability in the program. Follett also told Cisco the updated Destiny software also scans computers for signs of infection and removes any identified backdoors. Read 2 remaining paragraphs | Comments

View post:
Out-of-date apps put 3 million servers at risk of crypto ransomware infections

Homebrew patch makes many Oculus VR games perfectly playable on HTC Vive [Updated]

What’re those SteamVR “chaperone” grid lines doing in an Oculus-exclusive game? Find out yourself if you own an HTC Vive and use the new Revive patch on many “exclusive” Oculus games. (credit: Sam Machkovech) In the race to the top of virtual reality, Oculus and HTC have kicked off a hardware showdown the likes of which we haven’t seen since the “Nintendon’t” days. However, the war includes a curious compatibility issue: HTC’s current software hub, SteamVR, can be accessible by Oculus headset wearers, but Oculus Home doesn’t currently support the HTC Vive. Oculus founder Palmer Luckey has publicly stated that “we can only extend our SDK to work with other headsets if the manufacturer allows us to do so,” seemingly passing the buck to HTC and Valve in regard to why its Oculus Store games don’t natively support the other leading PC headset. Valve has denied this assertion . Either way, we no longer have to wait for the companies to settle their legal and licensing differences, thanks to the efforts of the LibreVR plugin, dubbed Revive . Short version: it works, as proven by the above screenshot we snapped of pack-in Oculus game Lucky’s Tale running within the SteamVR interface (complete with its “chaperone” boundary lines). The author’s test system, which includes a 4.2 GHz i7 processor and a GTX 980Ti, ran all test games without hitches in performance, while other users have reported similarly smooth performance on “VR-ready” Windows 10 PCs. Read 6 remaining paragraphs | Comments

View original post here:
Homebrew patch makes many Oculus VR games perfectly playable on HTC Vive [Updated]

Chrome 50 ends support for Windows XP, OS X 10.6, other old versions

Google Chrome version 50 was released to the browser’s stable channel yesterday, and in addition to a handful of new features and security fixes , the update also ends support for a wide range of operating systems that have been supported since Chrome launched on those platforms. Windows XP, Windows Vista, OS X 10.6, OS X 10.7, and OS X 10.8 are no longer supported. This shouldn’t come as much of a surprise, since Google promised last November to end support for these older OS versions in April of 2016. Old versions of Chrome installed on these OSes won’t stop working (for now), but they’ll no longer receive updates and there’s no guarantee that things like Google account sign-in and data syncing will continue to work. If you’re still using one of these operating systems, you have a couple of options. One is to upgrade to a newer OS, assuming your hardware can handle it. Security patches for Windows XP stopped in April of 2014 , and patches for OS X 10.6 stopped a few months before that . Updates for OS X 10.7 and 10.8 ended roughly when versions 10.10 and 10.11 were released, respectively, since Apple’s unofficial policy is to provide security fixes for the most recent OS X release and the two previous releases. Windows Vista is still getting bare-minimum security patches from Microsoft, but that ends in April of 2017 . Read 1 remaining paragraphs | Comments

More:
Chrome 50 ends support for Windows XP, OS X 10.6, other old versions

Windows 10 roadmap: Control everything remotely

As Microsoft continues to court businesses and encourage them to upgrade to Windows 10, the company has taken the novel step of publishing a roadmap of Windows 10 features . This roadmap describes business-oriented features that are coming to Windows 10. Some, such as biometric authentication in the Edge browser, have already been announced as part of the forthcoming Anniversary Update and are currently available in the Insider Preview . But others are not. While some are so vague as to tell us nothing—the Passport API used for biometric authentication is being “enhanced” to improve enterprise functionality—other features are rather more concrete. Microsoft plans to add device-based PC unlocking, wherein Windows and Android phones can be used to store authentication credentials, and the feature can be used to both unlock the PC and authenticate apps and services that use Windows Hello and the Passport API. The same is also being enabled for what Microsoft calls “Companion devices” that integrate with a new API called the “Companion Device Framework.” The Microsoft Band 2 fitness device will plug into this framework, and third-party devices will also be able to join in. Read 6 remaining paragraphs | Comments

View original post here:
Windows 10 roadmap: Control everything remotely

All-bacterial battery makes a nutrient when charged, eats it to discharge

Diagram of a microbial fuel cell that runs on acetate, one half of the bacterial battery described here. (credit: Oak Ridge National Lab ) The chemical that powers most of our cellular processes is produced through something called the electron transport chain. As its name suggests, this system shuffles electrons through a series of chemicals that leaves them at a lower energy, all while harvesting some of the energy difference to produce ATP. But the ultimate destination of this electron transport chain doesn’t have to be a chemical. There are a variety of bacteria that ultimately send the electrons off into the environment instead. And researchers have figured out how to turn these into a fuel cell, harvesting the electrons to do something useful. While some of these designs were closer to a battery than others, all of them consumed some sort of material in harvesting the electrons. A team of researchers in the Netherlands figured out how to close the loop and create an actual bacterial battery. One half of the battery behaves like a bacterial fuel cell. But the second half takes the electrons and uses them to synthesize a small organic molecule that the first can eat. Its charging cycle is painfully slow and its energy density is atrocious, but the fact that it works at all seems rather noteworthy. Read 11 remaining paragraphs | Comments

Read More:
All-bacterial battery makes a nutrient when charged, eats it to discharge

Nvidia unveils first Pascal graphics card, the monstrous Tesla P100

The first full-fat GPU based on Nvidia’s all-new Pascal architecture is here. And while the Tesla P100 is aimed at professionals and deep learning systems rather than consumers, if consumer Pascal GPUs are anything like it—and there’s a very good chance they will be—gamers and enthusiasts alike are going to see a monumental boost in performance. The  Tesla P100 is the first full-size Nvidia GPU based on the TSMC 16nm FinFET manufacturing process—like AMD, Nvidia has been stuck using an older 28nm process since 2012—and the first to feature the second generation of High Bandwidth Memory (HBM2). Samsung began mass production of faster and higher capacity HBM2 memory back in January. While recent rumours suggested that both Nvidia and AMD wouldn’t use HMB2 this year due to it being prohibitively expensive—indeed, AMD’s recent roadmap suggests that its new Polaris GPUs won’t use HBM2 —Nvidia has at least taken the leap with its professional line of GPUs. The result of the P100’s more efficient manufacturing process, architecture upgrades, and HBM2 is a big boost in performance over Nvidia’s current performance champs like the Maxwell-based Tesla M40 and the Titan X/Quadro M6000. Nvidia says the P100 reaches 21.2 teraflops of half-precision (FP16) floating point performance, 10.6 teraflops of single precision (FP32), and 5.3 teraflops (1/2 rate) of double precision. By comparison, the Titan X and Tesla M40 offer just 7 teraflops of single precision floating point performance. Read 9 remaining paragraphs | Comments

Continue Reading:
Nvidia unveils first Pascal graphics card, the monstrous Tesla P100

A spiritual successor to Aaron Swartz is angering publishers all over again

Aaron Swartz would be proud of Alexandra Elbakyan. The 27-year-old is at the center of a lawsuit brought by a leading science publisher that is labeling her a hacker and infringer. (credit: Courtesy of Alexandra Elbakyan) Stop us if you’ve heard this before: a young academic with coding savvy has become frustrated with the incarceration of information. Some of the world’s best research continues to be trapped behind subscriptions and paywalls. This academic turns activist, and this activist then plots and executes the  plan. It’s time to free information from its chains—to give it to the masses free of charge. Along the way, this research Robin Hood is accused of being an illicit, criminal hacker. This, of course, describes the tale of the late Aaron Swartz . His situation captured the Internet’s collective attention as the data crusader attacked research paywalls. Swartz was notoriously charged as a hacker for trying to free millions of articles from popular academic hub JSTOR. At age 26, he tragically committed suicide just ahead of his federal trial in 2013. But suddenly in 2016, the tale has new life.  The Washington Post   decries it as academic research’s Napster moment, and it all stems from a 27-year-old bioengineer turned Web programmer from Kazakhstan (who’s living in Russia). Just as Swartz did, this hacker is freeing tens of millions of research articles from paywalls, metaphorically hoisting a middle finger to the academic publishing industry, which, by the way, has again reacted with labels like “hacker” and “criminal.” Read 30 remaining paragraphs | Comments

More:
A spiritual successor to Aaron Swartz is angering publishers all over again

Reddit removes “warrant canary” from its latest transparency report

(credit: Cyrus Farivar) Reddit has removed the warrant canary posted on its website, suggesting that the company may have been served with some sort of secret court order or document for user information. At the bottom of its 2014 transparency report , the company wrote: “As of January 29, 2015, reddit has never received a National Security Letter, an order under the Foreign Intelligence Surveillance Act, or any other classified request for user information. If we ever receive such a request, we would seek to let the public know it existed.” That language was conspicuously missing from the 2015 transparency report that was published Thursday morning. Read 3 remaining paragraphs | Comments

Read more here:
Reddit removes “warrant canary” from its latest transparency report

Maryland hospital group hit by ransomware

Baltimore’s Union Memorial is one of the hopitals hit by Samsam, an autonomous ransomware strain spread by exploiting JBoss servers. (credit: MedStar) Baltimore’s Union Memorial Hospital is the epicenter of a malware attack upon its parent organization, MedStar. Data at Union Memorial and other MedStar hospitals in Maryland have been encrypted by ransomware spread across the network, and the operators of the malware are offering a bulk deal: 45 bitcoins (about $18,500) for the keys to unlock all the affected systems. Reuters reports that the FBI issued a confidential urgent “Flash” message to the industry about the threat of Samsam on March 25, seeking assistance in fighting the ransomware and pleading, “We need your help!” The FBI’s cyber center also shared signature data for Samsam activity to help organizations screen for infections. But the number of potential targets remains vast, and the FBI was concerned that entire networks could fall victim to the ransomware. According to sources who spoke to the Baltimore Sun , the malware involved in MedStar’s outages is Samsam, also known as Samas and MSIL. The subject of a recent confidential FBI cyber-alert, Samsam is form of malware that uses well-known exploits in the JBoss application server and other Java-based application platforms. As Ars reported on Monday, Samsam uses exploits published as part of JexBoss , an open-source security and penetration testing tool for checking JBoss servers for misconfiguration. Read 3 remaining paragraphs | Comments

Original post:
Maryland hospital group hit by ransomware