Hacker exploits printer Web interface to install, run Doom

Doom on a printer’s menu screen! Personally, we can’t wait until someone makes Descent playable on a toaster. Context Internet Security On Friday, a hacker presenting at the 44CON Information Security Conference in London picked at the vulnerability of Web-accessible devices and demonstrated how to run unsigned code on a Canon printer via its default Web interface. After describing the device’s encryption as “doomed,” Context Information Security consultant Michael Jordon made his point by installing and running the first-person shooting classic  Doom on a stock Canon Pixma MG6450. Sure enough, the printer’s tiny menu screen can render  a choppy and discolored but playable version of id Software’s 1993 hit, the result of Jordon discovering that Pixma printers’ Web interfaces didn’t require any authentication to access. “You could print out hundreds of test pages and use up all the ink and paper, so what?” Jordon wrote at Context’s blog report about the discovery , but after a little more sniffing, he found that the devices could also easily be redirected to accept any code as legitimate firmware. A vulnerable Pixma printer’s Web interface allows users to change the Web proxy settings and the DNS server. From there, an enterprising hacker can crack the device’s encryption in eight steps, the final of which includes unsigned, plain-text firmware files. The hacking possibilities go far beyond enabling choppy, early ’90s gaming: “We can therefore create our own custom firmware and update anyone’s printer with a Trojan image which spies on the documents being printed or is used as a gateway into their network,” Jordon wrote. Read 4 remaining paragraphs | Comments

Read More:
Hacker exploits printer Web interface to install, run Doom

OneDrive finally gets file sharing as easy as Dropbox

We reported last week that Microsoft’s OneDrive cloud service was finally syncing files larger than 2GB. The company today confirmed the change, and disclosed what the new size limit is: 10GB. Not quite enough for a Blu-Ray, but it should solve the file size problem for most users. That’s not the only improvement that Microsoft has made. The desktop client will, at long last, make it easy to share files in OneDrive with other people; right clicking the file in Explorer will have a straightforward “Share a OneDrive link” menu item to create a link that can be e-mailed, tweeted, or otherwise passed around. The lack of such a feature has long made using OneDrive much more annoying than using the competing Dropbox service. The new menu item is rolling out to OneDrive users on Windows 7 and Windows 8 over the next few weeks. The client for Windows 8.1 and OS X will be updated at some time after that. Read 1 remaining paragraphs | Comments

More:
OneDrive finally gets file sharing as easy as Dropbox

Intel demos next-next-gen “Skylake” processors, coming in late 2015

A Core M CPU package based on the Broadwell architecture. Intel Intel’s Broadwell CPU architecture has only just started rolling out , and most of the processors that use it aren’t even supposed to launch until early next year. The new 14nm manufacturing process is causing the delay , but yesterday at the Intel Developer Forum the company tried to demonstrate that Broadwell’s lateness wouldn’t affect the rest of its roadmap. To that end, Intel highlighted a couple of working developer systems based on the new “Skylake” architecture, as summarized here by Anandtech . The company didn’t go into specific performance or power consumption numbers (both because it’s early and because Intel probably doesn’t want to take the wind out of Broadwell’s sails), but it showed working silicon rendering 3D games and playing back 4K video to prove that the chips are working. The first Skylake processors are reportedly due out late in 2015 following the beginning of volume production in the second half of the year. Here are the basic facts we already know about Skylake: it’s a “tock” on Intel’s roadmap, meaning it introduces a new architecture on a manufacturing process that’s already up and running. In this case, that’s Intel’s 14nm process, which Intel  insists has recovered from its early problems . Some of the CPUs in Intel’s lineup—specifically  mid-to-low-end socketed desktop CPUs —will get their next refresh using Skylake instead of Broadwell. Whether this is because Intel wants to reserve 14nm manufacturing capacity for lower-power, higher-margin chips or because it just doesn’t think the power-consumption-obsessed Broadwell is a good fit for regular desktops is anyone’s guess. Read 1 remaining paragraphs | Comments

See more here:
Intel demos next-next-gen “Skylake” processors, coming in late 2015

Epic makes Unreal Engine 4 free for students

On Thursday, Epic Games announced that it would make the complete Unreal Engine 4 suite free to use for universities and students on a case-by-case basis. Interested teachers and students can now submit their credentials via Epic’s official site , and upon acceptance, they will have access to the suite without having to pay the standard $19 per month fee . “There’s no separate ‘academic’ version or anything like that,” UE4 General Manager Ray Davis said to Ars in a phone interview. “The cool thing is, as a student, even if you don’t decide to subscribe upon graduation, you’ll still retain access to any version of the engine you had at that point. We’re not leaving people hanging at the end of a school year or anything like that.” Though UE4’s university-specific offer isn’t quite as accessible as Crytek’s CryENGINE, which can be downloaded by anybody on a non-commercial basis, Epic’s revision does stem from feedback the company received after it announced UE4’s pricing structure during this year’s Game Developers Conference . Read 3 remaining paragraphs | Comments

View article:
Epic makes Unreal Engine 4 free for students

Haswell-E arrives, bringing a $999 8-core desktop CPU with it

Most of Intel’s announcements lately have focused on low-power chips, but every now and again it throws a bone to its high-end desktop users. Today we’re getting our first look at Haswell-E and a new Core i7 Extreme Edition CPU, a moniker reserved for the biggest and fastest of Intel’s consumer and workstation CPUs (if you want something faster than that, you’ll need to start looking at Xeons). We already got a little bit of information on these chips back in March , when Intel made announcements related to refreshed Haswell chips (“Devil’s Canyon”) and a handful of other desktop processors. Though much of today’s information has already leaked, we’ll run down the most important stuff for those of you who don’t follow every leaked slide that makes its way to the public. The CPUs Read 16 remaining paragraphs | Comments

Read More:
Haswell-E arrives, bringing a $999 8-core desktop CPU with it

Heartbleed is the gift that keeps on giving as servers remain unpatched

Within four days of the first public reports of a major flaw in OpenSSL’s software for securing communications on the Internet, mass attacks searched for and targeted vulnerable servers. In  a report  released this week, IBM found that while the attacks have died down, approximately half of the original 500,000 potentially vulnerable servers remain unpatched, leaving businesses at continuing risk of the Heartbleed flaw. On average, the company currently sees 7,000 daily attacks against its customers, down from a high of 300,000 attacks in a single 24-hour period in April, according to the report based on data from the company’s Managed Security Services division. “Despite the initial rush to patch systems, approximately 50 percent of potentially vulnerable servers have been left unpatched—making Heartbleed an ongoing, critical threat,” the report stated. Read 6 remaining paragraphs | Comments

View original post here:
Heartbleed is the gift that keeps on giving as servers remain unpatched

Mapping Wi-Fi dead zones with physics and GIFs

A simulated map of the WiFi signal in Jason Cole’s two-bedroom apartment. Jason Cole A home’s Wi-Fi dead zones are, to most of us, a problem solved with guesswork. Your laptop streams just fine in this corner of the bedroom, but not the adjacent one; this arm of the couch is great for uploading photos, but not the other one. You avoid these places, and where the Wi-Fi works becomes a factor in the wear patterns of your home. In an effort to better understand, and possibly eradicate, his Wi-Fi dead zones, one man took the hard way: he solved the Helmholtz equation . The Helmholtz equation models “the propagation of electronic waves” that involves using a sparse matrix to help minimize the amount of calculation a computer has to do in order to figure out the paths and interferences of waves, in this case from a Wi-Fi router. The whole process is similar to how scattered granular material, like rice or salt, will form complex patterns on top of a speaker depending on where the sound waves are hitting the surfaces. The author of the post in question , Jason Cole, first solved the equation in two dimensions, and then applied it to his apartment’s long and narrow two-bedroom layout. He wrote that he took his walls to have a very high refractive index, while empty space had a refractive index of 1. Read 3 remaining paragraphs | Comments

See the article here:
Mapping Wi-Fi dead zones with physics and GIFs

Apple’s wearable device will be revealed September 9, Re/code says

A sixth-generation iPod Nano embedded in a watch band. Aaron Muszalski Re/code is reporting that Apple will introduce a wearable device on September 9 alongside two next-generation iPhones. Such a device from Apple has been highly anticipated since the wearable market received newcomers from Samsung, LG, and Motorola . Apple’s entry into this market was originally expected sometime in October based on an earlier report from Re/code. The site has had a good track record of correctly predicting the timing of Apple product releases since the AllThingsD days. John Paczkowski, who reported the news, says that the coming device will certainly be equipped to make use of Apple’s HealthKit platform for its Health app, as well as HomeKit, which is a platform to connect devices to smart appliances and light bulbs. Read 1 remaining paragraphs | Comments

View original post here:
Apple’s wearable device will be revealed September 9, Re/code says

US courts trash a decade’s worth of online documents, shrug it off

US Court of Appeals for the 11th Circuit in Atlanta. Kevin / flickr The US Administrative Office of the Courts (AOC) has deleted nearly a decade’s worth of documents from four US appeals courts and one bankruptcy court. The deletion is part of an upgrade to a new computer system for the database known as Public Access to Court Electronic Records, or PACER. Court dockets and documents at the US Courts of Appeals for the 2nd, 7th, 11th, and Federal Circuits, as well as the Bankruptcy Court for the Central District of California, were maintained with “locally developed legacy case management systems,” said AOC spokesperson Karen Redmond in an e-mailed statement . Those five courts aren’t compatible with the new PACER system. Read 12 remaining paragraphs | Comments

See the original post:
US courts trash a decade’s worth of online documents, shrug it off

Jawbone opens a window to our humanity-tracking future

Jawbone’s graph of users who were woken up by the earthquake in California early Sunday. Jawbone Wearable computing company Jawbone released a graph  on Monday showing its users being woken up by the 6.0-magnitude earthquake centered in the Napa Valley region of California on Sunday morning. 120 people were injured, a lot of wine went to waste, and a few people wearing Jawbone’s Up fitness bands lost some sleep, according to a huge spike in the percentage of users who were up and moving in affected regions at about 3:20am (close to 80 percent in Berkeley, Vallejo, and Napa Valley itself). The graph accurately plots the nexus of the earthquake, with smaller spikes of activity in more distant regions, including San Francisco and Oakland (around 60 percent of users), Sacramento and San Jose (25 percent), and Modesto and Santa Cruz, with only a tiny bump of a few percent from the baseline. Together, the locations form a basic map of the earthquake’s reach, not dependent on scientific measurements and existing equipment waiting for a disaster, but just a large, distributed population wearing tracking devices . The Up bands don’t collect location data themselves, so they can’t pinpoint where a user was asleep with perfect certainty. Rather, the data is based on the locations logged by the app used to store users’ information, which always records a user’s location when the app is opened. Read 5 remaining paragraphs | Comments

View the original here:
Jawbone opens a window to our humanity-tracking future