Mac malware that infected Facebook bypassed OS X Gatekeeper protection

Researchers have identified the Mac malware that infected employees of Apple, Facebook, and Twitter, and say it may have been used to compromise machines in other US organizations, including auto manufacturers, government agencies, and a leading candy maker, according to a published report. Pintsized.A is a new family of Mac malware that uses an exploit to bypass Gatekeeper, an OS X protection that allows end users to tightly control which sources are permitted to install apps , according to an article published Monday by The Security Ledger. Mac antivirus provider Intego says  the trojan masquerades on infected machines as Linux printing software known as cupsd, although it runs from a different location than the legitimate title. It’s unclear exactly how the malware gets around Gatekeeper. Once installed, Pintsized establishes a reverse shell to a command and control server controlled by the attackers. It uses a modified version of the OpenSSH utility to encrypt traffic, a measure that can help it remain undetected on infected networks. One of the domain names that hosted such a server was corp-aapl.com. It caught the attention of members of Facebook’s security team, tipping them off that there was an infected machine inside their network . When they later took control of the domain, they discovered multiple other companies were also compromised by the same attackers. Around the same time, Apple , Twitter , and Microsoft were also hit with attacks that meet the same pattern. Read 1 remaining paragraphs | Comments

Link:
Mac malware that infected Facebook bypassed OS X Gatekeeper protection

How two volunteers built the Raspberry Pi’s operating system

Aurich Lawson When you buy a Raspberry Pi, the $35 computer doesn’t come with an operating system. Loading your operating system of choice onto an SD card and then booting the Pi turns out to be pretty easy. But where do Pi-compatible operating systems come from? With the Raspberry Pi having just  turned one year old , we decided to find out how  Raspbian —the officially recommended Pi operating system—came into being. The project required 60-hour work weeks, a home-built cluster of ARM computers, and the rebuilding of 19,000 Linux software packages. And it was all accomplished by two volunteers. Like the Raspberry Pi itself, an unexpected success story Although there are numerous operating systems for the Pi, the Raspberry Pi Foundation recommends one for the general populace. When the Pi was born a year ago, the  recommended operating system was a version of Red Hat’s Fedora tailored to the computer’s ARM processor. But within a few months, Fedora fell out of favor on the Pi and was replaced by Raspbian. It’s a version of Debian painstakingly rebuilt for the Raspberry Pi by two volunteers named Mike Thompson and Peter Green. Read 53 remaining paragraphs | Comments

Read the article:
How two volunteers built the Raspberry Pi’s operating system

Newly spotted miles-wide comet bearing down on Mars

A comet spotted earlier this year may pass close enough for Mars to feel the rock’s hot breath down its neck, according to new reports that surfaced Monday and Tuesday. The comet, named C/2013 A1, may pass within a few tens of thousands of miles of Mars’ center, with a remote chance that the miles-wide comet will collide with the planet. C/2013 A1 “Siding Spring,” a comet between 5 and 30 miles wide, was spotted January 3 by astronomer Robert H. McNaught. Researchers were able to look back in the image history of the Catalina Sky Survey in Arizona and spot signs of the comet as early as December 8, 2012. NASA states that other archives have traced sightings back to October 4, 2012. According to scientists at NASA’s Near-Earth Object Program Office , Siding Spring originates from the Oort Cloud of our Solar System and has been journeying to this point for more than a million years. In less than two years, around October 19, 2014, the comet will pass very close to Mars. Read 2 remaining paragraphs | Comments

See the original article here:
Newly spotted miles-wide comet bearing down on Mars

Five features iOS should steal from Android

Aurich Lawson, Age 5 If you’ve come anywhere near a tech site in the last year or so, you’ve heard it all before. “iOS is getting stale compared to Android! It needs some new ideas!” Whether that’s actually true is up for (heated) debate, but those with an open mind are usually willing to acknowledge that Apple and Google could afford to swap a few ideas when it comes to their mobile OSes. So in a fantasy world where we could bring over some of the better Android features to iOS, which features would those be? Among the Ars staff, we sometimes have spirited “conversations” about what aspects would be the best for each company to photocopy. So, we thought we’d pick a few that might go over well with iOS users. Don’t worry, we have a companion post of features that Android could afford to steal from iOS. The copying can go both ways. No one wants iOS to become Android or vice versa. This is about recognizing how to improve iOS with features that would be useful to people depending on their smartphones for more than the occasional text or phone call. We recognize that Apple tries to keep an eye towards elegant implementation, too. So which features are we talking about? Glad you asked… Read 18 remaining paragraphs | Comments

See the original article here:
Five features iOS should steal from Android

Five-year-old runs up $2,500 in-app purchase tab with Apple

Five-year-olds know as well as adults do: iPads are fun to play with. Parents who regularly hand their iDevices over to their children, take note: you can still be burned by kids making in-app purchases. The  BBC published a story on Friday highlighting a five-year-old’s impressive feat in running up a £1,700 iTunes bill—about $2,500—after his father entered a passcode to allow him to download a “free” game from the App Store. The details of the situation reveal a series of unfortunate events that led to the truly epic tab, though Apple has since refunded the money. There are a few things the Kitchens could have done better when their son, Danny, began using an iPad to play games. The article doesn’t specify whether Danny’s father entered a passcode for the device, for the App Store, or within the app itself, but the last scenario listed seems most likely. Entering a password to download apps in the App Store used to mean the user could begin charging in-app purchases without re-entering that password for 15 minutes as the default iOS behavior. Apple made that more difficult with iOS 4.3 in early 2011 by requiring the App Store password a second time when in-app purchases are made. Assuming the family’s iPad was running a more recent version of iOS, it sounds like Danny’s father entered his password when Danny began to make purchases, not realizing what he was authorizing. Read 4 remaining paragraphs | Comments

Read More:
Five-year-old runs up $2,500 in-app purchase tab with Apple

Bitcoin reaches an all-time trading high of over $33

After rising steadily over the last several months, Bitcoin has reached an all-time high according to data on Bitcoin Charts . As of this writing, Mt. Gox , the most popular Bitcoin trading site (which announced on Wednesday that  its operations  would move to Silicon Valley), recorded a high price of $33.22 per Bitcoin. There’s no single explanation as to why Bitcoin has continued to rise, accelerating particularly over the last month. That said, it’s been clear that interest in the digital currency has been rapidly rising, as any regular reader of Ars knows. It’s likely that online gambling has played a part. As we’ve reported earlier this year, one Bitcoin-based site took in $500,000 in profit in just six months in 2012—and Bitcoin gambling is set to get even bigger . For now, gambling with the cryptocurrency, like using Bitcoins in general, remains in a legal grey area  (which may be part of the appeal as well). Read 3 remaining paragraphs | Comments

View article:
Bitcoin reaches an all-time trading high of over $33

Internet Explorer 10 finally released for Windows 7

Four months after Microsoft released Internet Explorer 10 with and for Windows 8, Redmond has finally released a version of the company’s newest browser for its 700 million Windows 7 users in 95 other languages too. The new browser will be available as an optional update immediately. Anyone with the release preview installed will have it sent as an “important” update. That’s significant because Windows Update will, in its default configuration, install it silently and automatically. Over coming months, Microsoft will classify Internet Explorer 10 as “important” in more and more markets to ensure it is installed automatically as widely as possible. This marks a significant change from Microsoft’s past practices. Traditionally, the company has released new browsers only as optional updates, and further, as interactive updates that required clicking through a EULA before installation actually took place. In late 2011, the company changed this policy, converting Internet Explorer 9 to an automatic (“important”) update. Read 3 remaining paragraphs | Comments

More:
Internet Explorer 10 finally released for Windows 7

The Pirate Bay leaves Sweden for friendlier waters

The Swedish Pirate Party has stopped hosting the notorious website The Pirate Bay, according to TorrentFreak. While no one knows where the site is actually run from, Web-hosting services have been provided through the Swedish Pirate Party for a few years now. Now, the site’s hosting will be taken care of by the Pirate Parties in Norway and Sweden. TPB is being forced to move because the Swedish Pirate Party is under pressure from Rights Alliance, a Swedish anti-piracy group representing large music and movie interests. Rights Alliance threatened legal action against the Pirate Party if the group didn’t stop hosting the site by tomorrow. Spain in particular could turn out to be a safe haven for the piracy-driven website, since judges in that country have found simply linking to other infringing sites is not a basis for copyright liability. The sports-streaming site Rojadirecta, for example, was exonerated after legal action against it was initiated in Spain. (That didn’t stop it from having its domain name grabbed by a US agency, before being given back last summer.) Read 1 remaining paragraphs | Comments

See more here:
The Pirate Bay leaves Sweden for friendlier waters

Earthquakes’ booms big enough to be detected from orbit

Artist’s impression of GOCE satellite. European Space Agency Last year, we reported on some mysterious booms in a small Wisconsin town that turned out to be small earthquakes. While it was an unusual story, it’s actually not that uncommon of an occurrence. Early in the summer of 2001, folks in Spokane, Washington started reporting similar booms. The sounds continued, off and on, for about five months. The mystery didn’t last long, as the earthquakes responsible were picked up by seismometers in the area. (A particularly loud one that took place exactly one month after the September 11, 2001 terrorist attacks in New York did rattle some nerves, however.) In total, 105 earthquakes were detected, with a couple as large as magnitude 4.0. For most of them, there wasn’t good enough seismometer coverage to really pinpoint locations, but some temporary units deployed around the city in July located a number of events pretty precisely: the earthquakes were centered directly beneath the city itself. While a dangerously large earthquake is pretty unlikely in Wisconsin, the possibility can’t be ignored in Washington. The 2011 earthquake in Christchurch, New Zealand was only a magnitude 6.3, but the damage was extensive because the epicenter was so close to the city. In L’Aquila, Italy, a swarm of small earthquakes in 2009 was followed by a deadly magnitude 6.3. (The poor public communication of risk during that swarm netted six seismologists manslaughter convictions .) Read 10 remaining paragraphs | Comments

View article:
Earthquakes’ booms big enough to be detected from orbit