TrueCrypt Windows encryption app has critical security flaws

If you’re still using TrueCrypt to protect your Windows disks, even though its developers abandoned it and said it was “not secure” last year, you may want to stop that. Google Project Zero researcher James Forshaw found two “privilege elevation” holes in the popular software that would give attackers full access to your data. Worse yet, TrueCrypt was audited earlier this by a crowdfunded team of iSec security researchers and found to be error-free. Google’s James Forshaw said on Twitter that the miss was understandable, though: “iSec phase 1 audit reviewed this specific code but Windows drivers are complex beasts (and) easy to miss.” Forshaw hasn’t disclosed the bugs yet, saying he usually waits seven days after a patch is released. He and other researchers agree that the vulnerabilities — which can reportedly be exploited by “abusive drive letter handling” — weren’t deliberately installed. And they won’t, of course, be fixed in the original program’s code. @v998n @VeraCrypt_IDRIX I don’t tend to open up security bug reports until 7 days or so after the release of the patch, just in case 🙂 — James Forshaw (@tiraniddo) September 27, 2015 However, if you’re using TrueCrypt because “free” is a good price, there are other options –VeraCrypt and CipherShed are open source forks of TrueCrypt, and VeraCrypt has already patched the bugs. Suffice to say, you should stop using TrueCrypt within the seven day window before Forshow releases the exploitable code. Even if you do, however, we likely haven’t heard the end of this type of Windows vulnerability. VeraCrypt’s Mounir Idrassi gold Threatpost that “These are the kind of vulnerabilities that exist in (lots of) software on Windows, ” and that will be (and have been) used by hackers for years. Via: PC World Source: James Forshaw (Twitter)

Read the original:
TrueCrypt Windows encryption app has critical security flaws

Raytheon signs $1 billion contract to protect government websites

Homeland Security has signed a five-year contract with Raytheon, which could be worth a whopping $1 billion. While the defense contractor is more known for weapons development, DHS hasn’t joined forces with it to create more missiles , lasers, warheads and UAVs . No, the agency has asked the company’s help to secure government websites. According to Raytheon’s announcement , it will aid the government in developing, deploying and supporting technologies that watch out for and mitigate cyberattacks. Reuters says the company will also help around 100 agencies manage their network security within the duration of the partnership as the prime contractor for DHS’ National Cybersecurity Protection System and Network Security Deployment divisions. After that massive Office of Personnel Management hack earlier this year (and the knowledge that other .gov websites are susceptible to attacks), it’s clear that the government believes it could use the cybersecurity upgrade Raytheon promises to bring to the table. And since the White House wants to start being more aggressive in securing its networks, this isn’t the government’s only anti-cyberattack project in the works. The Pentagon, for one, is building an automated system that can detect and prevent security breaches. [Image credit: Getty Images/Caiaimage] Via: Reuters Source: Raytheon

See more here:
Raytheon signs $1 billion contract to protect government websites

Uber starts testing pre-paid service for events in NYC

Uber is launching yet another new product , but this one targets a specific group of people: event organizers, especially those tired of fielding calls from guests who can’t make it due to car troubles. The service called UberEvents allows organizers to buy and secure passes ahead of the occasion to send to guests, clients or whoever needs one to get to the location via email. Guests will only have to enter the code under the Promotions section of the Uber app to hail a ride. Now, nobody will be able to use car issues as an excuse anymore, and party planners won’t have to worry about how to send drunk guests home. Uber is initially making Events available to Business users and select people in New York City, though the service will be accessible by everyone in the metropolis within the coming weeks. Via: TechCrunch Source: Uber

See more here:
Uber starts testing pre-paid service for events in NYC

‘Ta.co’ Bell now offers online ordering

Got a hankering for Taco Bell but just can’t bring yourself to wait the 3.5 minutes it takes to slop your order together? Well, you’re in luck. The fast food franchise chain recently debuted a new, faster way to order your Chalupas: no, not your mobile phone , the internet! The online menu is available at Ta.co (or just Tacobell.com/food if you’re unhip). Simply click on the food and drinks you want, customize each item with everything from black beans and guacamole on your Nacho Cheese Doritos Locos Tacos Supreme to Lava sauce and a three cheese blend on yourDouble Decker Taco Supreme (or other equally-silly named edible). Once you’ve finalized your order, the system will direct you to the nearest participating Taco Bell for pick up. Unfortunately, no, Taco Bell won’t also deliver it — unless you live in one of a few select cities . Via: HuffPo Source: ta.co

Read the original post:
‘Ta.co’ Bell now offers online ordering

AmpMe daisy-chains a bunch of phones to create a multi-speaker setup

Generally speaking, if you thought you might want to blast music while out and about, you’d invest in a Bluetooth speaker. If the sound quality there wasn’t quite robust enough, you’d either get yourself a bigger speaker , or maybe even link together a few smaller ones . Either way, prepare to spend a few hundred dollars. Or not. A new app called AmpMe promises to achieve the same effect, except instead of asking you to shell out for new hardware, it daisy-chains an unlimited number of smartphones so that they stream the same song in sync, combining each handset’s speaker into something… cacaphonous.Slideshow-322368 The free app, available for iOS and Android, doesn’t use Bluetooth or WiFi, but rather, plays an audio “fingerprint” on the host device (a series of beeps, to the human ear) that gets picked up by the mic on the receiving phone. Everyone involved needs to have the app installed, and anyone joining in needs to request a passkey for the music party before receiving that unique audio code. The host can shut down the party at any time with the push of a button, whereas receivers can pause the music for, say, a phone call, and pick back up with the rest of the group, wherever they happen to be in the song. For now, the app only works with Soundcloud. Founder Martin-Luc Archambault says that’s because Soundcloud is free, making it accessible to the most people, but that his team is working on inking deals with other streaming services as well. Ultimately, he says, he wants it to be “Sonos for cellphones.” In a brief demo last week, the various phones and tablets that were paired together did indeed play music in sync, without any latency on any of the devices. AmpMe has clearly shown, then, that it’s possible to turn a series of mobile devices into an ad hoc multi-speaker setup — no small feat. The problem is that the audio quality on most phones and tablets is frankly terrible. Unless you happen to have, say, an HTC phone with BoomSound , you’re probably working with tinny, contained audio that only gets more distorted as you crank the volume. Or, in this case, create a chorus of equally tinny-sounding devices. It’s great to know that the technology has evolved such that it’s possible to daisy-chain phones like this and have them stream music perfectly in sync. Now we just need to wait the phone makers to catch up. Source: iTunes , Google Play

Continued here:
AmpMe daisy-chains a bunch of phones to create a multi-speaker setup

For the first time, a paraplegic has walked without a robotic suit

A paraplegic has walked without robotics using his own brain waves, thanks to research done at Southern California’s UC Irvine . Scientists used a computer to “link” 28-year-old Adam Fritz’s brain to his legs over a Bluetooth connection, bypassing the severed region of his spinal cord. An EEG then picked up signals from his brain, which were relayed by a “brain-control interface” (BCI) computer to electrodes on his knee, triggering walking movements. Though Fritz was supported and only walked haltingly for 12 feet, the research is being heralded as a milestone — so far, paralyzed patients have only be able to walk using suits like that from Ekso Bionics . It wasn’t just a matter of strapping on the EEG cap and taking a stroll. Prior to the attempt, Fritz underwent extensive physical rehab to strengthen his muscles and learned to control a virtual avatar using the BCI device. He also made similar movements in the lab while suspended slightly above the floor. During a conversation with Sky News , Fritz dubbed the interface a “mind walker, ” and said, “it’s complete concentration. You have to think about every single step when you’re doing it.” Despite the success, the team said there’s still a lot of work to be done before patients can gain any mobility. The next step is to reduce the EEG components enough that they can be implanted in the brain, which could give patients more precise control the and the ability to “sense” pressure. Meanwhile, Fritz described the experience as “incredible, ” saying, “when you’re first injured, you’re sitting in hospital hoping you’ll walk again, but when it actually happened it was a dream come true.” Source: JNER

Visit link:
For the first time, a paraplegic has walked without a robotic suit

Watch the first trailer for ‘The Angry Birds Movie’

Yes, folks, it’s all happening. The first trailer for The Angry Birds Movie has arrived. Directed by Clay Kaytis and Fergal Reilly (both first timers), and written by Jon Vitty ( The Simpsons ), the animated film seems to focus on the origin story of why these famous birds are, well, angry. Red, perhaps the most popular character, is voiced by Jason Sudeikis, while Danny McBride does the honors for Bomb — you know, the black bird who likes to blow up. The rest of the cast is made up by other well-known stars , including Bill Hader, Josh Gad, Maya Rudolph and Peter Dinklage. Interestingly enough, The Angry Birds Movie is now slated to hit theaters in May 2016, a couple of months earlier than originally announced . Source: Angry Birds (YouTube)

View article:
Watch the first trailer for ‘The Angry Birds Movie’

Ultimate VR simulator throws you around in mid-air

Virtual reality headsets can trick our eyes and ears into believing we’re someplace else. Fooling the rest of the body is a little trickier though. Companies have tried spinning chairs and omnidirectional treadmills , but nothing comes close to the ” Cable Robot Simulator ” developed at the Max Planck Institute for Biological Cybernetics. The player wears a wireless VR headset inside a carbon fibre cage, which is then suspended in mid-air and thrown around the room using eight steel cables. The exposed pod is able to tilt, bank and move with an acceleration of up to 1.5g in response to the VR experience. Researchers have shown off some basic flight and racing simulations, but we’re already imagining how it could be used in our favorite video games. A dogfight in Star Wars: Battlefront ? Tearing around corners in F-Zero GX ? The possibilities are endless. It’s still very much a prototype, and hardly suitable for home use, but we’re desperate to have a go ourselves. [Image Credit: Max Planck Institute for Biological Cybernetics, Tübingen] Via: Eurogamer Source: Max Planck Institute for Biological Cybernetics

View post:
Ultimate VR simulator throws you around in mid-air

Is a Roku 4 with 4K coming this way?

It was 2013 the last time that Roku launched a new flagship streaming box, and while we still adore the 3 , the hardware can’t avoid the ravages of time. Our friends over at Zatz Not Funny are reporting that the company is gearing up to replace it with a new high-end unit, the imaginatively-named Roku 4. As well as being the fourth in the series, the hardware expected to launch with 4K video playback as its primary selling point. The rumor began when streaming service Cinema Now accidentally launched a promotion for free HD rentals with every new Roku 4. Whoops. That’s not the only piece of evidence on the rap sheet, either. UKRokuChannels discovered a 4K Showcase offering on the platform’s channel store, which was swiftly pulled by the company. It’ll come as no surprise that the company is embracing the standard, since it revealed in January that it was working on a 4K reference design . In addition, now that Amazon has added the feature to the new Fire TV , it’s only a matter of time before Roku joined in. The firm wasn’t able to respond in time for publication, but we’ll keep a beady eye on the FCC’s website over the next few weeks — just in case. Source: CinemaNow (Cached) , Zatz Not Funny , UKRokuChannels

See the article here:
Is a Roku 4 with 4K coming this way?

4chan sells to the founder of the site that inspired it

If you know your internet message board history, you know that Chris Poole’s legendary 4chan was inspired by 2channel, a board dedicated to anime and other aspects of Japanese culture. Well, things are about to come full circle: Poole (aka Moot) just sold 4chan to Hiroyuki Nishimura, 2channel’s founder and the current editor in chief for Variety Japan . The terms of the deal aren’t public, but Poole notes to the New York Times that there’s a “lot of opportunity” to grow his site with the “right resources.” That wouldn’t be hard. Unlike some other community mainstays, such as Reddit, 4chan has never really been run as a full-fledged business. If you’re a loyal 4chan user, the handover might be worrying. Part of its appeal is that homebrew, almost-anything-goes vibe that has frequently made it both the launching point for internet memes and a bastion of open, anonymous expression. However, Poole believes that he’s putting his creation in good hands. Nishimura is the “only person in the world” with as much experience running a message board like this — if anyone can understand what makes 4chan popular, it’s him. The real question is whether or not he can (or wants to) make it a profitable venture without compromising its spirit. Reddit has already taken some flak for cleaning up some of its hate communities in its bid for mainstream success. While 4chan already has experience with this kind of backlash (the notorious 8chan board exists partly to house 4chan exiles), it’s still considered more laissez-faire than its commercial cousin. It risks losing that image if it goes too far in sanitizing the experience for the sake of advertisers. [Image credit: Johannes Simon/Getty Images] Source: New York Times

Continue reading here:
4chan sells to the founder of the site that inspired it