Encrypted or not, Skype communications prove “vital” to NSA surveillance

Last year, Ars documented how Skype encryption posed little challenge to Microsoft abuse filters that scanned instant messages for potentially abusive Web links. Within hours of newly created, never-before-visited URLs being transmitted over the service, the scanners were able to pluck them out of a cryptographically protected stream and test if they were malicious. Now comes word that the National Security Agency is also able to work around Skype crypto—so much so that analysts have deemed the Microsoft-owned service “vital” to a key surveillance regimen known as PRISM . “PRISM has a new collection capability: Skype stored communications,” a previously confidential NSA memo from 2013 declared. “Skype stored communications will contain unique data which is not collected via normal real-time surveillance collection.” The data includes buddy lists, credit card information, call records, user account data, and “other material” that is of value to the NSA’s special source operations. The memo, which was leaked by former NSA contractor Edward Snowden and released Tuesday by Glenn Greenwald to coincide with the publication of his book No Place to Hide , said the FBI’s Electronic Communications Surveillance Unit had approved “over 30 selectors to be sent to Skype for collection.” Read 2 remaining paragraphs | Comments

View post:
Encrypted or not, Skype communications prove “vital” to NSA surveillance

Teen arrested for 30 “swatting” attacks against schools, security reporter

Police in the Canadian city of Ottawa said they arrested a 16-year-old male charged with carrying out so-called “swatting” attacks that targeted 30 North American targets. One of the targets included KrebsOnSecurity reporter Brian Krebs , who was previously on the receiving end of a vicious swatting attack that resulted in a team of police pointing guns at him as he opened the front door of his Virginia home. Krebs said the recent attacks were preceded by taunts from someone controlling the Twitter handle @ProbablyOnion . The last tweet made from that account, made on Thursday, stated: “Still awaiting for the horsies to bash down my door.” The individual didn’t have long to wait. That same day, the 16-year-old was arrested, according to press releases here and here issued by the Ottawa Police Service and the FBI, respectively. Swatting refers to the act of knowingly giving authorities false information about bomb threats, the taking of hostages, or similar threats in progress with the goal of tricking heavily armed police to raid the location of an innocent person or group. According to authorities, the unnamed 16-year-old allegedly carried out swatting attacks on 30 targets, including schools in North America that responded with lockdowns or evacuations. The minor was charged with 60 criminal offenses, including public mischief, mischief to property, uttering death threats, and conveying false info with intent to alarm. Read 1 remaining paragraphs | Comments

Continued here:
Teen arrested for 30 “swatting” attacks against schools, security reporter

YouTube shuts down public RSS feeds of user subscriptions

If you’re a news junky, you probably use an RSS reader like Feed.ly to keep up with stuff on the Web. One of the nicest ways to consume YouTube subscriptions was to use an RSS feed of new videos, allowing them to show up just like news articles do. You might not have noticed yet, but Google quietly shut down this feature a few days ago. The RSS feed, which used to be http://gdata.youtube.com/feeds/base/users/[username]/newsubscriptionvideos, now throws out a “403 Forbidden” error. Previously, the URL would provide a publicly accessible feed of new subscriptions from any YouTube account, provided users didn’t choose to turn off public subscription retrieval. The feed was part of the YouTube Data API v2, which was deprecated in March of this year. The replacement—predictably named YouTube Data API v3—doesn’t offer a comparable data stream. Bug reports filed for this regression as early as January 2013 have gone unanswered, save for a single response in January 2014 (yes, a year later) saying, “Patch is in the works, however we can’t comment on the expected date.” Now it’s five months later, the feature is gone, and there’s no solution in sight. Read 3 remaining paragraphs | Comments

See more here:
YouTube shuts down public RSS feeds of user subscriptions

New Intel chipsets speed up your storage, but they’re missing new CPUs

The 9-series chipsets pile a few new features on top of the previous-generation 8-series chipsets. Intel Last year at around this time, Intel was releasing its brand-new Haswell CPU architecture and its 8-series chipsets out into the world for back-to-school season. About a year before that, it was doing the same for its Ivy Bridge architecture and 7-series chipsets. This year, we’re getting more new chipsets, but they aren’t coming with a new CPU architecture—just some mildly refreshed Haswell processors, some of which we’ve covered already . We’ll get to the new chipsets in a moment, but first let’s talk about the elephant in the room: Intel’s near-silence on the next-generation Broadwell CPUs. We’ve had a few snippets of information about the company’s next CPU architecture, but since announcing a delay late last year the company has said little on the issue. Mass production was supposed to ramp up in the first quarter of 2014, and that quarter has come and gone. Read 14 remaining paragraphs | Comments

More:
New Intel chipsets speed up your storage, but they’re missing new CPUs

Router company that threatened a reviewer loses Amazon selling license

The Medialink router that was reviewed. Mediabridge Update 5/8/2014 19:44 CT:  On Thursday, Mediabridge Products posted an official statement about this incident to its Facebook page, clarifying its position and saying that Amazon has revoked its selling privileges. (Thanks to PrimalxConvoy for the tip). In the statement, the company says that it did not actually sue the Amazon reviewer, but that it did insist that the reviewer’s “untrue, damaging, and disparaging statements” be taken down. “It’s our sincere belief that reasonable people understand that not only is it within our rights to take steps to protect our integrity, but that it should be expected that we would do so when it is recklessly attacked,” Mediabridge Products wrote. “The reviewer has since changed his review completely to remove the libelous statements, but unfortunately not before having an army attack us on the internet.” The company did not give any clue as to the terms of Amazon’s rescinding of Mediabridge’s selling license, but only said at the end of its statement “Unfortunately, as a result of our attempt to get this reviewer to do the right thing & remove his untrue statements about our company, Amazon has revoked our selling privileges. Many hard-working employees whose livelihood depended on that business will likely be put out of a job, by a situation that has been distorted & blown out of proportion.” Read 8 remaining paragraphs | Comments

Read More:
Router company that threatened a reviewer loses Amazon selling license

Four weeks on, huge swaths of the Internet remain vulnerable to Heartbleed

Aurich Lawson / Thinkstock More than four weeks after the disclosure of the so-called Heartbleed bug found in a widely used cryptography package , slightly more or slightly less than half the systems affected by the catastrophic flaw remain vulnerable, according to two recently released estimates. A scan performed last month by Errata Security CEO Rob Graham found 615,268 servers that indicated they were vulnerable to attacks that could steal passwords, other types of login credentials, and even the extremely sensitive private encryption keys that allow attackers to impersonate websites or monitor encrypted traffic. On Thursday, the number stood at 318,239. Graham said his scans counted only servers running vulnerable versions of the OpenSSL crypto library that enabled the “Heartbeat” feature where the critical flaw resides. A separate scan using slightly different metrics arrived at an estimate that slightly less than half of the servers believed to be vulnerable in the days immediately following the Heartbleed disclosure remain susceptible. Using a tool the researcher yngve called TLS Prober, he found that 5.36 percent of all servers were vulnerable to Heartbleed as of April 11, four days after Heartbleed came to light. In a blog post published Wednesday , he said 2.33 percent of servers remained vulnerable. It’s important to remember the results don’t include the number of Heartbleed-vulnerable servers providing services such a virtual private networks or e-mail. Read 3 remaining paragraphs | Comments

More:
Four weeks on, huge swaths of the Internet remain vulnerable to Heartbleed

Epic announces crowdsourced dev model for next Unreal Tournament

It’s been a long six-and-a-half years since we’ve gotten a new Unreal Tournament game (not counting expansion packs), but today marks the beginning of the end for that wait. Epic announced  that work on a new game, simply titled Unreal Tournament , begins today for PC, Mac, and Linux, and the process will heavily involve participation from the modding and player community from the get go. While a “small team of UT veterans” at Epic will be spearheading the development of the game, everything from design decisions to art direction will primarily “happen in the open, as a collaboration between Epic, UT fans, and [Unreal Engine 4] developers,” Epic says. The developers are inviting everyone from regular players to experienced modders from sites like Polycount to sign up at the Unreal Engine forums and use an official wiki to take direct part in driving the game’s direction. Already, mere minutes after the announcement, those forums are filled with players discussing everything from series maps and weapons they’d like to see return to things like VR headset compatibility. Epic says it will be “many months” until the game is in any sort of playable state, but when it is playable it “will be free. Not free to play, just free.” Source code will be made available directly from GitHub as it is updated, and modders will even be able to fork their own builds if they want to take the project in a new direction. Read 2 remaining paragraphs | Comments

Follow this link:
Epic announces crowdsourced dev model for next Unreal Tournament

Google Announces "Classroom"

theodp (442580) writes “Meet your new ‘Room Mom’, kids! On Tuesday, Google announced a preview of Classroom, a new, free tool in the Google Apps for Education suite. From the announcement: ‘With Classroom, you’ll be able to: [1] Create and collect assignments: Classroom weaves together Google Docs, Drive and Gmail to help teachers create and collect assignments paperlessly. They can quickly see who has or hasn’t completed the work, and provide direct, real-time feedback to individual students. [2] Improve class communications: Teachers can make announcements, ask questions and comment with students in real time—improving communication inside and outside of class. [3] Stay organized: Classroom automatically creates Drive folders for each assignment and for each student. Students can easily see what’s due on their Assignments page.’ Addressing privacy concerns, Google reassures teachers, ‘We know that protecting your students’ privacy is critical. Like the rest of our Apps for Education services, Classroom contains no ads, never uses your content or student data for advertising purposes, and is free for schools.’ After the recent torpedoing of Bill Gates’ $100M inBloom initiative, Google might want to have a privacy pitch ready for parents, too!” Read more of this story at Slashdot.

See the original post:
Google Announces "Classroom"

ARM: The $20 smartphone will be possible “in the next few months”

Basic smartphones are cheap—and getting cheaper. ARM Smartphone prices have been creeping ever downward in the last few years, and ARM is betting that they’re going to go even lower. AnandTech is reporting from ARM’s Tech Day today , and one of the company’s slides predicts that the cost of a phone with a single-core Cortex A5 chip in it will go as low as $20 within the next few months. Of course, these ultra-low-cost phones won’t be devices tech enthusiasts lust after. ARM notes that even a $25 phone like the Firefox handsets announced at Mobile World Congress  have to cut down on RAM and other specs to hit that price point, and it’s unlikely that something with such low specs could run something like Android satisfactorily. More expensive phones like the $179 Moto G will still be necessary if you want that full smartphone experience on a budget. Still, for those ever-important emerging markets where the smartphone has yet to take off, any OEM that can provide a decent experience for this price is going to fill an important niche. In other news from ARM’s Tech Day, ARM shared some new performance estimates for its upcoming 64-bit Cortex A53 and A57 architectures. The company predicts that chips based on these architectures will be about 1.5 times as fast as the Cortex A7 and A15 architectures they replace when the SoCs are all built on the same 28nm manufacturing process. When moved to a newer 20nm or 16nm manufacturing process, though, the A57 in particular will supposedly be nearly twice as fast as the older A15. Read 1 remaining paragraphs | Comments

View article:
ARM: The $20 smartphone will be possible “in the next few months”

Level 3 claims six ISPs dropping packets every day over money disputes

Network operator Level 3, which has asked the FCC to protect it from ” arbitrary access charges ” that ISPs want in exchange for accepting Internet traffic, today claimed that six consumer broadband providers have allowed a state of “permanent congestion” by refusing to upgrade peering connections for the past year. Level 3 and Cogent, another network operator, have been involved in disputes with ISPs over whether they should pay for the right to send them traffic. ISPs have demanded payment in exchange for accepting streaming video and other data that is passed from the network providers to ISPs and eventually to consumers. When the interconnections aren’t upgraded, it can lead to congestion and dropped packets, as we wrote previously regarding a dispute between  Cogent and Verizon . In a blog post today , Level 3 VP Mark Taylor wrote: Read 4 remaining paragraphs | Comments

Read the article:
Level 3 claims six ISPs dropping packets every day over money disputes