Getting a Linux box corralled into a DDoS botnet is easier than many think

Enlarge (credit: Aurich Lawson and Getty) Getting a Linux server hacked and made part of a botnet is easier than some people may think. As two unrelated blog posts published in the past week demonstrate, running a vulnerable piece of software is often all that’s required. Witness, for example, a critical vulnerability disclosed earlier this year in Elasticsearch , an open source server application for searching large amounts of data. In February, the company that maintains it warned it contained a vulnerability that allowed hackers to execute commands on the server running it. Within a month, a hacking forum catering to Chinese speakers provided all the source code and tutorials needed for people with only moderate technical skills to fully identify and exploit susceptible servers. A post published Tuesday by security firm Recorded Future deconstructs that hacker forum from last March. It showed how to scan search services such as Shodan and ZoomEye to find vulnerable machines. It includes an attack script written in Python that was used to exploit one of them and a separate Perl script used to make the newly compromised machine part of a botnet of other zombie servers. It also included screenshots showing the script being used against the server. The tutorial underscores the growing ease of hacking production servers and the risk of being complacent about patching. Read 5 remaining paragraphs | Comments

See the article here:
Getting a Linux box corralled into a DDoS botnet is easier than many think

New diabetes cases finally on the decline

(credit: Steven Depolo/Flickr ) After more than a quarter of a century of rising diabetes rates, the number of new cases seems to be on a downward trend. From 1980 to 2009, the annual number of new diabetes cases more than tripled in the US, going from 493,000 to 1.7 million diagnoses a year in people aged 18 to 79. But since 2009, case numbers appear to have slumped, though the decline had not registered as statistically significant. Now, using newly released data from 2014 , the Centers for Disease Control and Prevention announced that case numbers are definitely on their first sustained decline. In 2014, the number of diagnosed cases was down to 1.4 million. “It seems pretty clear that incidence rates have now actually started to drop,” said Edward Gregg, one of the CDC’s top diabetes researchers told the New York Times . “Initially it was a little surprising because I had become so used to seeing increases everywhere we looked.” Read 2 remaining paragraphs | Comments

See the article here:
New diabetes cases finally on the decline

HGST beats Seagate to market with helium-filled 10TB hard drive

Western Digital’s HGST division has released the world’s first helium-filled 10TB hard drive for everyday use—assuming you have about £600 burning a hole in your pocket, anyway. Meanwhile, despite reiterating that it would have a 10TB drive on the market this year, Seagate hasn’t yet moved past the 8TB mark. The Ultrastar He10 is notable for two reasons: it’s hermetically sealed and filled with helium, which is still a rather novel idea; and it has seven platters crammed into a standard-height 25.4mm (1-inch) hard drive. PMR vs. SMR. With SMR, there’s almost no guard space between tracks, which increases density but can reduce write speed (if you want to rewrite a track in the middle, you may also have to rewrite the adjacent tracks as well). (credit: Seagate) The platters themselves are impressive, too: instead of using shingled magnetic recording (SMR) to boost areal density, these platters use conventional perpendicular magnetic recording (PMR). PMR has been the standard hard drive recording tech since 2005, when it replaced longitudinal recording. The move to PMR has increased the maximum platter density by an order of magnitude—from about 100Gb per square inch to 1000Gb—but now, alas, we’re beginning to hit the limits of PMR. Read 6 remaining paragraphs | Comments

See original article:
HGST beats Seagate to market with helium-filled 10TB hard drive

Thunderbird “a tax” on Firefox development, and Mozilla wants to drop it

Mozilla would like to drop Thunderbird from its list of projects. (credit: Andrew Cunningham) You might know Mozilla primarily for its Firefox browser, but for many years the company has also developed an e-mail client called Thunderbird. The two projects use the same rendering engine and other underlying technology, but Mozilla Executive Chairwoman Mitchell Baker has announced that Mozilla would like to stop supporting Thunderbird, calling its continuing maintenance “a tax” on the more important work of developing Firefox. “Many inside of Mozilla, including an overwhelming majority of our leadership, feel the need to be laser-focused on activities like Firefox that can have an industry-wide impact,” Baker writes. “With all due respect to Thunderbird and the Thunderbird community, we have been clear for years that we do not view Thunderbird as having this sort of potential.” Mozilla doesn’t plan to drop Thunderbird immediately, however—the current maintenance schedule will continue and Thunderbird users can continue to use the product. But the end goal for Mozilla, according to Baker, is to find “the right kind of legal and financial home” for the Thunderbird project, and “[separate] itself from reliance on Mozilla development systems and in some cases, Mozilla technology.” In other words, the company would like to give Thunderbird to people who will take care of it, freeing the Firefox team from having to worry about it. Read 1 remaining paragraphs | Comments

Read More:
Thunderbird “a tax” on Firefox development, and Mozilla wants to drop it

Apple’s A9X has a 12-core GPU and is made by TSMC

Enlarge / A die shot of the A9X. The ratio of GPU to CPU is becoming pretty insane. (credit: Chipworks via AnandTech ) Apple makes interesting chips for its mobile devices, but it doesn’t talk about them much aside from extremely high-level relative performance comparisons. That means it’s up to experts like the ones at Chipworks to open them up and figure it out, and they’ve partnered up with AnandTech to dig into the A9X in the iPad Pro. The most significant news is about the GPU, which is a 12-core Imagination Technologies PowerVR Series 7XT design. The company doesn’t generally offer a 12-core design, as shown in the chart below, but the architecture is designed to be easily scalable and it wouldn’t be the first time Apple had gotten something from a supplier that other companies couldn’t get. The standard A9 in the iPhone 6S and 6S Plus uses a 6-core version of the same GPU. Apple feeds that GPU with a 128-bit memory bus, something that it’s also included in other iPads to boost memory bandwidth and GPU performance. The Series 7XT lineup. The iPad Pro’s GPU falls somewhere in between the stock 8-cluster and 16-cluster designs. (credit: Imagination Technologies) Imagination’s chart for the Series 7XT GPU puts a hypothetical 12-core design in the same general performance neighborhood as an Nvidia GeForce GT 730M, a low-end discrete GPU that’s a bit slower than the stuff Apple is shipping in its high-end MacBook Pros. Our own graphics benchmarks place it a bit higher than that, but as some of you have pointed out , iOS may have a small advantage in some of these tests because of differences between the mobile OpenGL ES API in iOS and the standard OpenGL API used in OS X. Read 2 remaining paragraphs | Comments

Read More:
Apple’s A9X has a 12-core GPU and is made by TSMC

Tesla Model X production starts in earnest, pricing revealed

(credit: Tesla) Several months ago we found out pricing for the fully loaded “Signature” edition Tesla Model X electric SUV. Now, we’ve got a better idea of what the cheapest Model X will set you back: $80,000 before any options and tax rebates or incentives. That’s for the 70D, which has all-wheel drive (a motor for each axle) and a 70kWh battery (pricing for the 90D and P90D haven’t been announced). That’s $5000 more than the equivalent Model S sedan , which hits 60mph a little quicker and has a slightly longer range than the SUV but not the same funky rear doors. The distinctive Falcon wing doors are Tesla’s approach to making an SUV with all the utility of a minivan; that was how Elon Musk described the design brief back in September. By opening up and out, they’re supposed to give better access to the rear seats while taking up less space than a traditional door. There are three different interior layouts. The base 70D is a five seater, but there’s also a six seat version (three rows of two) for an extra $3000 and seven seats are yours for $4500. Tesla released the pricing information for the 70D Model X at the same time it told customers with preorders that they can begin configuring their vehicles. Screenshots of the online configurator provided by Tesla to Ars state that Model X deliveries will begin in early 2016, starting with range-topping P90D orders. “Lesser” 90D Model Xs follow by mid-year, with 70D deliveries before 2017. Read 1 remaining paragraphs | Comments

View article:
Tesla Model X production starts in earnest, pricing revealed

TrueCrypt is safer than previously reported, detailed analysis concludes

(credit: Khürt Williams ) The TrueCrypt whole-disk encryption tool used by millions of privacy and security enthusiasts is safer than some studies have suggested, according to a comprehensive security analysis conducted by the prestigious Fraunhofer Institute for Secure Information Technology. The extremely detailed 77-page report comes five weeks after Google’s Project Zero security team disclosed two previously unknown TrueCrypt vulnerabilities . The most serious one allows an application running as a normal user or within a low-integrity security sandbox to elevate privileges to SYSTEM or even the kernel. The Fraunhofer researchers said they also uncovered several additional previously unknown TrueCrypt security bugs. Despite the vulnerabilities, the analysis concluded that TrueCrypt remains safe when used as a tool for encrypting data at rest as opposed to data stored in computer memory or on a mounted drive. The researchers said the vulnerabilities uncovered by Project Zero and in the Fraunhofer analysis should be fixed but that there’s no indication that they can be exploited to provide attackers access to encrypted data stored on an unmounted hard drive or thumb drive. According to a summary by Eric Bodden , the Technische Universität Darmstadt professor who led the Fraunhofer audit team: Read 4 remaining paragraphs | Comments

View article:
TrueCrypt is safer than previously reported, detailed analysis concludes

FDA approves first GM food animal—Atlantic salmon

(credit: Artizone/Flickr ) After two decades of deliberation, the Food and Drug Administration has approved the first ever genetically engineered food animal, a fast-growing Atlantic Salmon called AquAdvantage salmon. According the agency, which announced the approval Thursday , the modified salmon are safe to eat, equally nutritious as other salmon, and should pose no threat to the environment. First created in 1989 and submitted to the agency for approval in 1995, the Atlantic salmon are modified to carry a growth hormone gene from Chinook salmon. That gene is further engineered to be under the control of a tiny bit of DNA, called a promoter, from the eel-like ocean pout fish. In general, DNA promoters are non-coding sequences that help control the expression level of a gene—how much protein product is synthesized from the gene. With the engineered promoter boosting hormone production, the modified salmon grow to market-size in about half the time of conventional Atlantic salmon. Read 4 remaining paragraphs | Comments

View original post here:
FDA approves first GM food animal—Atlantic salmon

Visual Studio now supports debugging Linux apps; Code editor now open source

The Visual Studio Code editor, now open source, editing TypeScript on OS X. (credit: Microsoft) NEW YORK—Developers can now debug apps running on Linux servers or IoT devices from the comfort of Visual Studio. Microsoft today released a preview of a Visual Studio extension that adds remote debugging using GDB of Linux software. This was one of many announcements made at Microsoft’s Connect developer event today as the company aims to give its developer platform the broadest reach it’s ever had, able to handle Android, iOS, and Linux development, alongside the more expected Azure, Office, and Windows. Visual Studio 2015 already made big strides in this direction, and Microsoft is pushing ahead to try to make Visual Studio the best development environment around. The free and cross-platform Chromium-based code editor Visual Studio Code is being open sourced today. A new build has also been published, adding an extension mechanism to the editor. There are already some 60 extensions available, including new language support (such as Go language), richer debugging, code linters, and more. Read 10 remaining paragraphs | Comments

Link:
Visual Studio now supports debugging Linux apps; Code editor now open source