Crypto attack that hijacked Windows Update goes mainstream in Amazon Cloud

Underscoring just how broken the widely used MD5 hashing algorithm is, a software engineer racked up just 65 cents in computing fees to replicate the type of attack a powerful nation-state used in 2012 to hijack Microsoft’s Windows Update mechanism. Nathaniel McHugh ran open source software known as HashClash to modify two separate images—one of them depicting funk legend James Brown and the other R&B singer/songwriter Barry White—that generate precisely the same MD5 hash, e06723d4961a0a3f950e7786f3766338. The exercise—known in cryptographic circles as a hash collision—took just 10 hours and cost only 65 cents plus tax to complete using a GPU instance on Amazon Web Service. In 2007, cryptography expert and HashClash creator Marc Stevens estimated it would require about one day to complete an MD5 collision using a cluster of PlayStation 3 consoles . The MD5 hash for this picture—e06723d4961a0a3f950e7786f3766338—is precisely the same for the one below. Such “collisions” are a fatal flaw for hashing algorithms and can lead to disastrous attacks. The practical ability to create two separate inputs that generate the same hash is a fundamental flaw that makes MD5 unsuitable for most purposes. (The exception is password hashing. Single iteration MD5 hashing is horrible for passwords but for an entirely different reason that is outside the scope of this post.) The susceptibility to collisions can have disastrous consequences, potentially for huge swaths of the Internet. Read 4 remaining paragraphs | Comments

Visit site:
Crypto attack that hijacked Windows Update goes mainstream in Amazon Cloud

LED bulb efficiency clearly pulling ahead of compact fluorescents

US EIA A few years back, when I got my first LED-based lightbulb, it seemed natural to stick it into a wattmeter to get a sense of its efficiency. At under 15 Watts of power drawn, it clearly beat any incandescent bulbs I’d ever put into the same lamp. But I was disappointed to find that it wasn’t any better than a compact fluorescent bulb. Based on the graph shown above, my experience was hardly unique; in fact, it was decidedly average. Although the technology behind LEDs had the potential to be far more efficient than any other lighting source, the complete LED bulb package wasn’t doing that much better at the time than the far more mature fluorescent bulbs, which output roughly 60 lumens for every Watt put in. After some small boosts in 2013, however, a new generation of more efficient LEDs hit the market this year, raising the typical efficiency to nearly 100 lumens per Watt. The increased efficiency is coming at a time when prices for the bulbs continue to drop; given their expected lifetimes, they’re now far and away the most economical choice for most uses. Read 1 remaining paragraphs | Comments

See original article:
LED bulb efficiency clearly pulling ahead of compact fluorescents

In Detroit and other cities, nearly 40 percent go without Internet

It may be hard to believe, but there are big cities in the US where 30 to 40 percent of residents have no Internet access at all. And among those who are online in America’s worst-connected cities, a sizable percentage get by with only cellular Internet. That’s according to 2013 census data compiled by Bill Callahan, director of  Connect Your Community 2.0 , a group promoting Internet access for residents of Cleveland, OH, and Detroit, MI. Callahan published charts on his blog yesterday  showing how many households lack Internet access in the 25 worst connected cities in the US (out of 176 that have at least 50,000 households). In Laredo, TX, 40.2 percent of the 65,685 households have no Internet access, not even mobile broadband on a phone. Detroit was second in this list with 39.9 percent of households lacking Internet. In all 25 cities, at least 29.8 percent lacked Internet access. The 25 cities varied in size from 52,588 households (Kansas City, KS) to 255,322 households (Detroit). Read 7 remaining paragraphs | Comments

See more here:
In Detroit and other cities, nearly 40 percent go without Internet

“The Devil had possessed his netbook”—and other tales of IT terror

Few things are scarier than 4Chan. But our readers told a few stories that spooked us. Paul van der Werf Earlier this week, we asked readers to share their most frightening tales of technology terror and support horror. And via both comments and Twitter (using the hashtag #ITTalesofTerror), in poured stories that raised goosebumps from those of us who have worked in IT at one point or another. After reading through them, we’ve picked out some reader favorites and a few of our own. Some of us at Ars were inspired to recount further tales of horror from our own IT careers—including one of mine that I’ve saved for last; it should cause a shudder of recognition from our more veteran readers and a bit of schadenfreude from those too young to remember five-and-a-quarter-inch floppy disks. The chamber of horrors Many readers had short tales of terror about mishaps in the closed spaces where we hide our network infrastructure. Eli Jacobowitz (@creepdr on Twitter) shared a short, shocking scenario by tweet : “Raccoons in the network closet (not kidding).” David Mohundro shared another story of a somewhat more smelly infrastructure invasion that brings new meaning to “data scrubbing”: “I saw our IT guys lugging shop vacs through the lower parking deck one day. There was a sewage backup into the server room.” Read 24 remaining paragraphs | Comments

Original post:
“The Devil had possessed his netbook”—and other tales of IT terror

FTC fines online dating service $616,000 for using “virtual cupids”

More and more people are becoming familiar with the joys—and frustrations—of online dating. A recent Pew study found that 10 percent of the US public is using online dating services, and a full 38 percent of those people say they are “single and looking.” There’s enough money to be made as an Internet matchmaker that it’s apparently sparking some companies to push the boundaries of what’s legal. Yesterday, the Federal Trade Commission disclosed that  it reached a settlement with JDI Dating Ltd. , a UK company that runs 18 dating sites that it claims have over 12 million members. The sites include CupidsWand.com, FlirtCrowd.com, and FindMeLove.com. JDI will have to pay $616,165 in redress, and it must stop business practices that were said to violate both the FTC Act and a newer law that regulates recurring billing online. JDI’s dating sites would make fake profiles, which the company called “virtual cupids,” and have them send computer-generated messages to new users who had created profiles but hadn’t yet paid. On JDI’s websites, users received an e-mail notifying them that another user sent them a “wink” within minutes of joining. Then they got additional winks, messages, and photo requests, supposedly from other members in their geographic area. Read 10 remaining paragraphs | Comments

Continued here:
FTC fines online dating service $616,000 for using “virtual cupids”

Beyond gaming, the VR boom is everywhere—from classrooms to therapy couches

Aurich Lawson / Thinkstock Welcome to Ars UNITE, our week-long virtual conference on the ways that innovation brings unusual pairings together. Today, a look at how virtual reality excitement is happening beyond the world of gaming. Join us this afternoon for a live discussion on the topic with article author Kyle Orland and his expert guests; your comments and questions are welcome. When Oculus almost single-handedly revived the idea of virtual reality from its ‘90s vaporware grave, it chose the 2012 Electronic Entertainment Expo as the place to unveil the first public prototype of the Rift headset. The choice of a gaming convention isn’t that surprising, as the game industry has been the quickest and most eager to jump on potential applications for VR. Gaming has already demanded the majority of the attention and investments in the second VR boom that Oculus has unleashed. But just as the Rift itself is the result of what Oculus calls a “peace dividend from the smartphone wars,” other fields are benefiting from virtual reality’s gaming-driven growth. Creators all over the world are looking beyond entertainment to adapting head-mounted displays for everything from psychotherapy, special-needs education, and space exploration to virtual luxury car test drives, virtual travel, and even VR movies. The well-worn idea of “gaming on the holodeck” may be driving much of the interest in virtual reality, but the technology’s non-gaming applications could be just as exciting in the long term. Read 42 remaining paragraphs | Comments

Read the original:
Beyond gaming, the VR boom is everywhere—from classrooms to therapy couches

MPAA, movie theaters announce “zero tolerance” policy against wearables

Biblioteca de Art A movie theater industry group and the Motion Picture Association of America updated their anti-piracy policies and said that “wearable devices” must be powered off at show time. “Individuals who fail or refuse to put the recording devices away may be asked to leave. If theater managers have indications that illegal recording activity is taking place, they will alert law enforcement authorities when appropriate, who will determine what further action should be taken,” said a joint statement  from the MPAA and the National Association of Theatre Owners, which maintains 32,000 screens across the United States. Read 3 remaining paragraphs | Comments

Original post:
MPAA, movie theaters announce “zero tolerance” policy against wearables

It came from the server room: Halloween tales of tech terror

It’s never a good day when the Halon discharges in the server room. Keith4048 It all began when the monitors started bursting into flames. Well, at least that’s when I knew I had walked into a tech support horror story. Back in the day when the cathode-ray tube was still the display of choice and SVGA really was super, I was working as a network engineer and tech support manager for a government contractor at a large military research lab. I spent two years on the job, and I learned in the process that Murphy was an optimist. The experience would provide me with enough tech horror stories and tales of narrow escape through the most kludged of hardware and software hacks ever conceived to last a lifetime—and to know that I would much rather be a writer than work in tech support ever again. Of course, all of us have tech horror stories to tell, especially those of us who were “early adopters” before the term was de rigueur. So we’re looking for you, our readers, to share yours. The most bone-chilling and entertaining of which we’ll publish tomorrow in honor of Halloween—that day each year when some people change their Twitter handles to pseudo-spooky puns, and others just buy bags of candy to have ready for the traditional wave of costumed home invaders. Read 10 remaining paragraphs | Comments

Read the original:
It came from the server room: Halloween tales of tech terror

Newspaper outraged after FBI creates fake Seattle Times page to nab suspect

YoungToymaker In 2007, the FBI wrote a fake news story about bomb threats in Thurston County, Washington, and then sent out e-mail links “in the style of the Seattle Times .” The details have now been published by that very same newspaper , which today carries a story including outraged quotes from a Seattle Times editor. The FBI put an Associated Press byline on the fake news story, which was about the bomb threats in Thurston County that they were investigating. “We are outraged that the FBI, with the apparent assistance of the US Attorney’s Office, misappropriated the name of The Seattle Times to secretly install spyware on the computer of a crime suspect,” said Seattle Times  editor Kathy Best. “Not only does that cross a line, it erases it.” Read 10 remaining paragraphs | Comments

See the original article here:
Newspaper outraged after FBI creates fake Seattle Times page to nab suspect

Leader of “most sophisticated cybercrime ring” sentenced to 11 years

An Estonian man who US authorities said was a leader in one of the world’s “most sophisticated” illegal hacking organizations was handed an 11-year prison sentence in connection to a scheme that got away with $9.4 million from ATMs across the globe. The sentence handed to Sergei Nicolaevich Tšurikov on Friday is among the largest ever given a hacker in the US. The biggest term , 20 years, was first given to Albert Gonzalez in 2010 for being the ringleader of the hack of retail outlet TJX . “A leader of one of the most sophisticated cybercrime rings in the world has been brought to justice and sentenced,” United States Attorney Sally Quillian Yates of Atlanta  said  about Tšurikov’s sentencing. “In just one day in 2008, an American credit card processor was hacked in perhaps one of the most sophisticated and organized computer fraud attacks ever conducted.” Read 4 remaining paragraphs | Comments

Taken from:
Leader of “most sophisticated cybercrime ring” sentenced to 11 years