Update: Researchers say Tor-targeted malware phoned home to NSA

A search reveals the address used in an attack on Tor users’ privacy referenced an IP address belonging to the NSA, routed through SAIC. Malware planted on the servers of Freedom Hosting — the “hidden service” hosting provider on the Tor anonymized network brought down late last week—may have de-anonymized visitors to the sites running on that service. This issue could send identifying information about site visitors to an Internet Protocol address that was hard-coded into the script the malware injected into browsers. And it appears the IP address in question belongs to the National Security Agency (NSA). This revelation comes from analysis done collaboratively by Baneki Privacy Labs , a collective of Internet security researchers, and VPN provider Cryptocloud . When the IP address was uncovered in the JavaScript exploit —which specifically targets Firefox Long-Term Support version 17, the version included in Tor Browser Bundle—a source at Baneki told Ars that he and others reached out to the malware and security community to help identify the source. The exploit attacked a vulnerability in the Windows version of the Firefox Extended Support Release  17 browser —the one used previously in the Tor Project’s Tor Browser Bundle (TBB).  That vulnerability had been patched by Mozilla in June, and the updated browser is now part of TBB. But the TBB configuration of Firefox doesn’t include automatic security updates, so users of the bundle would not have been protected if they had not recently upgraded. Read 6 remaining paragraphs | Comments        

View post:
Update: Researchers say Tor-targeted malware phoned home to NSA

Alleged Tor hidden service operator busted for child porn distribution

Catherine Scott On Friday, Eric Eoin Marques, a 28 year-old Dublin resident, was arrested on a warrant from the US on charges that he is, in the words of a FBI agent to an Irish court , “the largest facilitator of child porn on the planet.” The arrest coincides with the disappearance of a vast number of ” hidden services ” hosted on Tor, the anonymizing encrypted network. Marques is alleged to be the founder of Freedom Hosting, a major hidden services hosting provider. While Marques’ connection to Freedom Hosting was not brought up in court, he has been widely connected to the service—as well as the Tormail anonymized e-mail service and a Bitcoin exchange and escrow service called Onionbank—in discussions on Tor-based news and Wiki sites. All those services are now offline. And prior to disappearing, the sites hosted by Freedom Hosting were also distributing malware that may have been used to expose the users of those services. Tor hidden services are a lesser known part of the Tor “darknet.” They are anonymized Web sites, mail hosts, and other services which can only be reached by computers connected to Tor, or through a Tor hidden services proxy website, such as tor2web.org , and they have host names ending in .onion. Read 5 remaining paragraphs | Comments        

Originally posted here:
Alleged Tor hidden service operator busted for child porn distribution

Older iPhones won’t be banned as Obama Administration vetoes ITC decision

On Saturday, the Obama Administration vetoed the International Trade Commission’s potential ban on a few models of older Apple phones and tablets. Samsung opened the case against Apple with the ITC in 2011, and the commission decided in June that Apple had, in fact, infringed upon a Samsung patent, US Patent No 7, 706, 348 . The decision garnered attention because the patent is considered essential to industry standards, meaning Samsung is required to license the patent (rather than sit on it, or refuse license it to some competitors). The ITC ended up recommending a ban be placed on the infringing products brought forward in the case, which included AT&T models of the iPhone 4, the iPhone 3GS, iPhone 3, iPad 3G, and iPad 2 3G. In June of 2013, Ars wrote  of the ITC’s ban: ”The decision can only be appealed to the US Court of Appeals for the Federal Circuit, the nation’s top patent court. Theoretically, the President can also block an ITC-ordered import ban, but that hasn’t happened since the 1980s.” Read 4 remaining paragraphs | Comments        

See more here:
Older iPhones won’t be banned as Obama Administration vetoes ITC decision

Rideshare drivers given citizen arrest by SF International Airport officials

Hopefully none of these cars at SFO are in for a citizen arrest. dreamagicjp Officials at the San Francisco International Airport (SFO) say they have been making citizen arrests of rideshare drivers throughout July. Airport spokesperson Doug Yakel told Ars on Tuesday that airport officials have made 12 such arrests since July 10. Rideshare companies like Uber, Lyft, and Sidecar use mobile apps to help city dwellers find rides in areas where cabs are scarce or expensive. But taxi service is heavily regulated in big cities nationwide, and rideshare companies have ruffled feathers by operating outside of traditional restraints placed on taxi drivers. Cities like New York and Chicago have made it difficult for rideshare companies to operate, and the California Public Utilities Commission (CPUC) slapped Uber, Lyft, and Sidecar with $20, 000 fines in November 2012 (although the commission later rescinded the fines ). In December of last year, the CPUC issued a proposal for examining the legality of the rideshare services, and the commission is expected to revisit the issue sometime this week. Read 7 remaining paragraphs | Comments        

See more here:
Rideshare drivers given citizen arrest by SF International Airport officials

Thailand bans using Bitcoin in any way, local startup reports

A Bitcoin startup based in Thailand now says that it has suspended all operations  because the Bank of Thailand has effectively banned bitcoins in the southeast Asian country. As Bitcoin Co. Ltd. reports: At the conclusion of the meeting, senior members of the Foreign Exchange Administration and Policy Department advised that due to lack of existing applicable laws, capital controls, and the fact that Bitcoin straddles multiple financial facets the following Bitcoin activities are illegal in Thailand: – Buying bitcoins – Selling bitcoins – Buying any goods or services in exchange for bitcoins – Selling any goods or services for bitcoins – Sending bitcoins to anyone located outside of Thailand – Receiving bitcoins from anyone located outside of Thailand This appears to be the first time that any country has outright banned the digital crypto currency . Further, it remains unclear exactly how Thailand would even enforce such a ban. Ars has been unable to confirm the ban with the Bank of Thailand , when this ban goes into effect, and how this decision came about. Bank representatives did not immediately respond to Ars’ request for comment. Read 1 remaining paragraphs | Comments        

Continue reading here:
Thailand bans using Bitcoin in any way, local startup reports

Poker player who won $1.5 million charged with running Android malware ring

A man who has won about $1.5 million in poker tournaments has been arrested and charged with running an operation that combined spam, Android malware, and a fake dating website to scam victims out of $3.9 million, according to Symantec. Symantec worked with investigators from the Chiba Prefectural Police in Japan, who earlier this week “arrested nine individuals for distributing spam that included e-mails with links to download Android.Enesoluty —a malware used to collect contact details stored on the owner’s device, ” Symantec wrote in its blog . Android.Enesoluty is a Trojan distributed as an Android application file. It steals information and sends it to computers run by hackers. It was discovered by security researchers in September 2012. Read 4 remaining paragraphs | Comments        

Visit link:
Poker player who won $1.5 million charged with running Android malware ring

Congress nearly shuts down NSA dragnet, in sudden 217-205 vote

Rep. Justin Amash (R-MI) sponsored the amendment that led to today’s close vote. Gage Skidmore / flickr A critical vote for intelligence funding today showed that Congress is sharply divided on the issue of NSA domestic surveillance. This afternoon, the House of Representatives narrowly shot down an amendment that would have stopped the NSA from engaging in any warrantless collection of telephone data on a 217-205 vote. The amendment was sponsored by Rep. Justin Amash (R-MI) and co-sponsored by John Conyers (D-MI). The summary of the amendment read: Ends authority for the blanket collection of records under the Patriot Act. Bars the NSA and other agencies from using Section 215 of the Patriot Act to collect records, including telephone call records, that pertain to persons who are not subject to an investigation under Section 215. Amash and Conyers sponsored a similar bill several weeks ago, but there’s been little movement on it. Their strategy this week was to propose the change as an amendment to a $600 billion defense spending bill being considered this week. That strategy quickly pushed the surveillance issue to the House floor. Read 8 remaining paragraphs | Comments        

Read more here:
Congress nearly shuts down NSA dragnet, in sudden 217-205 vote

Apple blames days-long Developer Center outage on “intruder”

Apple Since Thursday, registered Apple developers trying to download OS X 10.9, iOS 7, or any other Apple software from the company’s developer portal have been greeted with a notice that the site was down for “maintenance.” Today, the company issued a brief statement (above) blaming the extended outage on an “intruder, ” and that Apple “[has] not been able to rule out the possibility that some developers’ names, mailing addresses, and/or email addresses may have been accessed.” The notice says that “sensitive” information could not be accessed by the intruder because it was encrypted, and the company told MacWorld that the system in question is not used to store “customer information, ” application code, or data stored by applications. Anecdotal reports (including one from our own Jacqui Cheng ) point to a sudden spike in password reset requests for some Apple IDs, suggesting that email addresses have in fact been accessed and distributed but that passwords were not. In any case, we generally recommend that users change their passwords when any breach (or suspected breach) like this one occurs. “In order to prevent a security threat like this from happening again, we’re completely overhauling our developer systems, updating our server software, and rebuilding our entire database, ” the statement said. Apple has also given week-long extensions to any developers’ whose program subscriptions were scheduled to lapse during the outage, which will keep those developers’ applications from being delisted in Apple’s various App Stores. Read on Ars Technica | Comments        

View article:
Apple blames days-long Developer Center outage on “intruder”

VLC media player returns to the iOS App Store after 30-month hiatus

A selection of videos on VLC 2.0 running on an iPad. VLC After disappearing the better part of three years ago, the VLC media player app for iOS has made its triumphant return to Apple’s App Store. Its version number has been bumped to 2.0, and the app now includes features like Wi-Fi and Dropbox syncing as well as the ability to download files from the Web. A version of VLC created by the company Applidium first made its debut on the App Store back in November 2010, but it was pulled in January 2011 due to a licensing dispute . All versions of VLC were then open-source and licensed under GPLv2; the App Store imposes its own licensing and DRM restrictions on apps. One of VLC’s original developers, Rémi Denis-Courmont, claimed that the licensing policies did not mesh and filed a complaint against the app. It was shortly removed. VLC 2.0 for iOS is licensed under both the Mozilla Public License v2 as well as the GNU General Public License v2 (or later). “The MPLv2 is applicable for distribution on the App Store, ” Felix Paul Kühne of VideoLAN told Ars. Read 2 remaining paragraphs | Comments        

See the original post:
VLC media player returns to the iOS App Store after 30-month hiatus

UK gov’t approves autonomous cars on public roads before year’s end

The British government has announced that it will approve testing of driverless cars on public roads in the United Kingdom before the end of 2013. According to a new 80-page report published on Tuesday entitled “Action for Roads: A network for the 21st century, ” a team at Oxford University and Nissan have already begun work but have only been testing in private areas. The plan comes less than a year after Florida , California , and Nevada have approved similar testing. Michigan is not far behind, either. Read 3 remaining paragraphs | Comments        

Originally posted here:
UK gov’t approves autonomous cars on public roads before year’s end