Active malware campaign steals Apple passwords from jailbroken iPhones

Sophos Security researchers have uncovered an active malware campaign in the wild that steals the Apple ID credentials from jailbroken iPhones and iPads. News of the malware, dubbed “unflod” based on the name of a library that’s installed on infected devices, first surfaced late last week on a pair of reddit threads here and here . In the posts, readers reported their jailbroken iOS devices recently started experiencing repeated crashes, often after installing jailbroken-specific customizations known as tweaks that were not a part of the official Cydia market , which acts as an alternative to Apple’s App Store. Since then, security researcher Stefan Esser has performed what’s called a static analysis on the binary code that the reddit users isolated on compromised devices. In a blog post reporting the results , he said unflod hooks into the SSLWrite function of an infected device’s security framework. It then scans it for strings accompanying the Apple ID and password that’s transmitted to Apple servers. When the credentials are found, they’re transmitted to attacker-controlled servers. Read 6 remaining paragraphs | Comments

Link:
Active malware campaign steals Apple passwords from jailbroken iPhones

Comcast bills lowered $2.4 million by scammers who accessed billing system

Alyson Hurt Two men pleaded guilty to a scam that lowered the bills of 5,790 Comcast customers in Pennsylvania by a total of $2.4 million. They now face prison time and will have to pay their ill-gotten wealth back to Comcast. 30-year-old Richard Justin Spraggins of Philadelphia pleaded guilty in February and was “ordered to make $66,825 in restitution and serve an 11- to 23-month sentence,” the Times-Herald of Norristown wrote at the time. Scaggins was described as the second-in-command of the operation. The accused ringleader, 30-year-old Alston Buchanan, pleaded guilty last week . “Buchanan faces up to 57½ to 115 years in prison, although Buchanan will likely serve a lesser sentence than the maximum,” the newspaper wrote. Read 3 remaining paragraphs | Comments

Read the original post:
Comcast bills lowered $2.4 million by scammers who accessed billing system

Digital Public Library of America to add millions of records to its archive

Aquarium, Battery Park, New York City [Postcard], ca. 1931. This is just one of the many resources you can find online through the DPLA website or through apps using its API. New York Aquarium Postcards collection of the Wildlife Conservation Society Archives. Via Empire State Digital Network. Today marks the Digital Public Library of America’s  one-year anniversary. To celebrate the occasion, the non-profit library network announced six new partnerships with major archives, including the US Government Printing Office and the J. Paul Getty Trust. The DPLA is best described as a platform that connects the online archives of many libraries around the nation into a single network. You can search all of these archives through the digital library’s website, and developers can build apps around the DPLA’s metadata collection using the publicly available API. It’s easy to find historical documents, public domain works, and vintage photos online through a search on the DPLA’s website, although sometimes a library will merely offer the data about an item, and retain the actual resource at the library. Still, having that data accessible through a single public portal is more useful for a researcher than having to search for it library by library. Read 7 remaining paragraphs | Comments

Visit link:
Digital Public Library of America to add millions of records to its archive

Lavabit held in contempt of court for printing crypto key in tiny font

Image by Rene Walter A federal appeals court on Wednesday upheld a contempt of court ruling against Ladar Levison and his now-defunct encrypted e-mail service provider, Lavabit LLC, for hindering the government’s investigation into the National Security Agency leaks surrounding Edward Snowden. In the summer of 2013, Lavabit was ordered to  provide real-time e-mail monitoring  of one particular user of the service, believed to be Snowden, the former NSA contractor turned whistleblower. Instead of adequately complying with the order to turn over the private SSL keys that protected his company’s tens of thousands of users from the government’s prying eyes, Levison chose instead to shut down Lavabit last year after weeks of stonewalling the government. However, Levison reluctantly turned over his encryption keys to the government, although not in a manner that the government deemed useful, and instead provided a lengthy printout with tiny type, a move the authorities said was objectionable. “The company had treated the court orders like contract negotiations rather than a legal requirement,” US Attorney Andrew Peterson, who represented the government, told  PC World . Read 5 remaining paragraphs | Comments

Read More:
Lavabit held in contempt of court for printing crypto key in tiny font

Fingerprint lock in Samsung Galaxy 5 easily defeated by whitehat hackers

SRLabs The heavily marketed fingerprint sensor in Samsung’s new Galaxy 5 smartphone has been defeated by whitehat hackers who were able to gain unfettered access to a PayPal account linked to the handset. The hack, by researchers at Germany’s Security Research Labs , is the latest to show the drawbacks of using fingerprints, iris scans, and other physical characteristics to authenticate an owner’s identity to a computing device. While advocates promote biometrics as a safer and easier alternative to passwords, that information is leaked every time a person shops, rides a bus, or eats at a restaurant, giving attackers plenty of opportunity to steal and reuse it. This new exploit comes seven months after a separate team of whitehat hackers bypassed Apple’s Touch ID fingerprint scanner less than 48 hours after it first became available. “We expected we’d be able to spoof the S5’s Finger Scanner, but I hoped it would at least be a challenge,” Ben Schlabs, a researcher at SRLabs, wrote in an e-mail to Ars. “The S5 Finger Scanner feature offers nothing new except—because of the way it is implemented in this Android device—slightly higher risk than that already posed by previous devices.” Read 7 remaining paragraphs | Comments

More here:
Fingerprint lock in Samsung Galaxy 5 easily defeated by whitehat hackers

After Netflix pays Comcast, speeds improve 65%

Netflix’s decision to pay Comcast for a direct connection to the Comcast network has resulted in significantly better video streaming performance for customers of the nation’s largest broadband provider. Netflix has bemoaned the payment, asking the government to prevent Comcast from demanding such interconnection ” tolls .”But there’s little doubt the interconnection has benefited consumers in the short term. Average Netflix performance for Comcast subscribers rose from 1.51Mbps to 1.68Mbps from January to February, though the interconnection didn’t begin until late February. In data released today, Netflix said average performance on Comcast has now risen further  to 2.5Mbps , a 65 percent increase since January. Comcast’s increased speed allowed it to pass Time Warner Cable, Verizon, CenturyLink, AT&T U-verse, and others in Netflix’s rankings. Comcast remains slower than Cablevision, Cox, Suddenlink, Charter, and Google Fiber. Read 4 remaining paragraphs | Comments

Continue reading here:
After Netflix pays Comcast, speeds improve 65%

Aftermarket CarPlay console coming this fall, costs between $500 and $700

Soon, you’ll be able to use Apple’s CarPlay without buying a whole new car. Apple So far, consoles compatible with Apple’s CarPlay feature have only been integrated into a handful of high-end cars. If you want to use the feature without buying an entirely new vehicle, Alpine Electronics will soon be able to hook you up—Nikkei reports that the company will begin selling a standalone CarPlay console in the US and Europe this fall. The console is “likely” to have a 7-inch display and will reportedly cost between $500 and $700. Alpine already sells a lineup of entertainment and navigation systems , and it’s possible that this new CarPlay-compatible version will offer similar features when there’s no iPhone connected to it. Current CarPlay-compatible vehicles offer the CarPlay interface when an iPhone is connected, but it’s available as an alternative to the automakers’ own software solutions rather than a complete replacement. CarPlay was first demonstrated as “iOS in the Car” at Apple’s Worldwide Developers Conference last year and was officially released earlier this year as part of the iOS 7.1 update . It provides access to Apple Maps’ turn-by-turn navigation features, your music and podcasts, and a handful of third-party streaming services approved by Apple; as of this writing, there’s no public API that developers can use to support the feature independently. CarPlay requires a compatible in-dash display and an iPhone 5, 5C, or 5S connected via a Lightning cable. Rumors of a wireless version of CarPlay persist, but it’s not clear whether these first CarPlay-compatible displays will be able to operate wirelessly when (and if) that capability arrives. Read on Ars Technica | Comments

Link:
Aftermarket CarPlay console coming this fall, costs between $500 and $700

FBI to have 52 million photos in its NGI face recognition database by next year

The EFF Jennifer Lynch is a senior staff attorney with the Electronic Frontier Foundation and works on open government, transparency and privacy issues, including drones, automatic license plate readers and facial recognition. New documents released by the FBI show that the Bureau is well on its way toward its goal of a fully operational face recognition database by this summer. The EFF received these records in response to our Freedom of Information Act lawsuit for information on Next Generation Identification (NGI) —the FBI’s massive biometric database that may hold records on as much as one-third of the US population. The facial recognition component of this database poses real threats to privacy for all Americans. Read 21 remaining paragraphs | Comments

Taken from:
FBI to have 52 million photos in its NGI face recognition database by next year

Flowing salt water over graphene generates electricity

An image of graphene, showing defects in its single-atom thickness. UC Berkeley Hydroelectricity is one of the oldest techniques for generating electrical power, with over 150 countries using it as a source for renewable energy. Hydroelectric generators only work efficiently at large scales, though—scales large enough to interrupt river flow and possibly harm local ecosystems. And getting this sort of generation down to where it can power small devices isn’t realistic. In recent years, scientists have investigated generating electrical power using nano-structures. In particular, they have looked at generating electricity when ionic fluids—a liquid with charged ions in it—are pushed through a system with a pressure gradient. However, the ability to harvest the generated electricity has been limited because it requires a pressure gradient to drive ionic fluid through a small tube. But scientists have now found that dragging small droplets of salt water on strips of graphene generates electricity without the need for pressure gradients. In their study, published in Nature Nanotechnology , researchers from China grew a layer of graphene and placed a droplet of salt water on it. They then dragged the droplet across the graphene layer at different velocities and found that the process generated a small voltage difference. Read 6 remaining paragraphs | Comments

Continue Reading:
Flowing salt water over graphene generates electricity

Here’s how Windows 8.1 Update tries to give you the right UI on any device

The Windows 8.1 Update that introduces a bunch of interface changes to Windows 8.1 is designed to enhance the experience of mouse and keyboard users, but what about the growing number of happy touch users? About 40 percent (and increasing) of PCs available at retail have a touchscreen (compared to just 4 percent when Windows 8 launched), and for the most part, their buyers enjoy how they work. With touch interfaces a growing part of the Windows ecosystem, Microsoft didn’t want to make the touch experience worse. While many desktop users may want their systems to boot straight to the desktop, this is unlikely to be a popular option for tablet users. Touch laptop users could easily go either way. Microsoft’s goal, therefore, was to pick a sensible default based on the kind of system being used. The way the update does this is based on something called the power platform role , a setting found in the computer’s firmware specified by the manufacturer. For Windows PCs, it will typically be “desktop,” “mobile,” or “slate,” for desktops, laptops, and tablets, respectively. Read 9 remaining paragraphs | Comments

Original post:
Here’s how Windows 8.1 Update tries to give you the right UI on any device