Trusting iPhones plugged into bogus chargers get a dose of malware

The Mactans charger uses a BeagleBoard for its computational power. Billy Lau, Yeongjin Jang, and Chengyu Song Plugging your phone into a charger should be pretty safe to do. It should fill your phone with electricity, not malware. But researchers from Georgia Institute of Technology have produced fake chargers they’ve named Mactans that do more than just charge your phone: they install custom, malicious applications onto iPhones. Their bogus chargers—which do, incidentally, charge the phone—contain small computers instead of mere transformers. The iPhone treats these computers just as it does any other computer; instead of just charging, it responds to USB commands. It turns out that the iPhone is very trusting of USB-attached computers; as long as the iPhone is unlocked (if only for a split second) while attached to a USB host, then the host has considerable control over the iPhone. The researchers used their USB host to install an app package onto any iPhone that gets plugged in. iOS guards against installation of arbitrary applications with a strict sandboxing system, a feature that has led to the widespread practice of jailbreaking. This attack doesn’t need to jailbreak, however. Read 6 remaining paragraphs | Comments        

Link:
Trusting iPhones plugged into bogus chargers get a dose of malware

Rideshare drivers given citizen arrest by SF International Airport officials

Hopefully none of these cars at SFO are in for a citizen arrest. dreamagicjp Officials at the San Francisco International Airport (SFO) say they have been making citizen arrests of rideshare drivers throughout July. Airport spokesperson Doug Yakel told Ars on Tuesday that airport officials have made 12 such arrests since July 10. Rideshare companies like Uber, Lyft, and Sidecar use mobile apps to help city dwellers find rides in areas where cabs are scarce or expensive. But taxi service is heavily regulated in big cities nationwide, and rideshare companies have ruffled feathers by operating outside of traditional restraints placed on taxi drivers. Cities like New York and Chicago have made it difficult for rideshare companies to operate, and the California Public Utilities Commission (CPUC) slapped Uber, Lyft, and Sidecar with $20, 000 fines in November 2012 (although the commission later rescinded the fines ). In December of last year, the CPUC issued a proposal for examining the legality of the rideshare services, and the commission is expected to revisit the issue sometime this week. Read 7 remaining paragraphs | Comments        

See more here:
Rideshare drivers given citizen arrest by SF International Airport officials

First images from NASA’s Sun-staring IRIS satellite

NASA/SDO/IRIS Last month we told you about the launch of NASA’s Interface Region Imaging Spectrograph (IRIS) satellite, which was built to study a poorly understood layer of the Sun’s atmosphere. After its successful launch , the satellite settled into its orbit and NASA took the lens cap off the telescope on July 17. Now, NASA has released the first imagery from the telescope, and it is gorgeous . The image above shows the unprecedented detail of IRIS’s view (on the right) compared to the view from the Solar Dynamics Observatory, a satellite that has been studying the Sun since 2010. (The video below shows these images in motion.) The feathery features you see are the result of differences in density and temperature. It’s the movement of energy through this layer of the solar atmosphere that NASA scientists are trying to understand. It should help them figure out how the Sun’s upper atmosphere gets so hot, as well as how solar flares form. Read on Ars Technica | Comments        

More:
First images from NASA’s Sun-staring IRIS satellite

Poker player who won $1.5 million charged with running Android malware ring

A man who has won about $1.5 million in poker tournaments has been arrested and charged with running an operation that combined spam, Android malware, and a fake dating website to scam victims out of $3.9 million, according to Symantec. Symantec worked with investigators from the Chiba Prefectural Police in Japan, who earlier this week “arrested nine individuals for distributing spam that included e-mails with links to download Android.Enesoluty —a malware used to collect contact details stored on the owner’s device, ” Symantec wrote in its blog . Android.Enesoluty is a Trojan distributed as an Android application file. It steals information and sends it to computers run by hackers. It was discovered by security researchers in September 2012. Read 4 remaining paragraphs | Comments        

Visit link:
Poker player who won $1.5 million charged with running Android malware ring

Congress nearly shuts down NSA dragnet, in sudden 217-205 vote

Rep. Justin Amash (R-MI) sponsored the amendment that led to today’s close vote. Gage Skidmore / flickr A critical vote for intelligence funding today showed that Congress is sharply divided on the issue of NSA domestic surveillance. This afternoon, the House of Representatives narrowly shot down an amendment that would have stopped the NSA from engaging in any warrantless collection of telephone data on a 217-205 vote. The amendment was sponsored by Rep. Justin Amash (R-MI) and co-sponsored by John Conyers (D-MI). The summary of the amendment read: Ends authority for the blanket collection of records under the Patriot Act. Bars the NSA and other agencies from using Section 215 of the Patriot Act to collect records, including telephone call records, that pertain to persons who are not subject to an investigation under Section 215. Amash and Conyers sponsored a similar bill several weeks ago, but there’s been little movement on it. Their strategy this week was to propose the change as an amendment to a $600 billion defense spending bill being considered this week. That strategy quickly pushed the surveillance issue to the House floor. Read 8 remaining paragraphs | Comments        

Read more here:
Congress nearly shuts down NSA dragnet, in sudden 217-205 vote

Texas man raised over $4.5M in Bitcoin Ponzi scheme, feds allege

If you don’t follow the often-shady world of Bitcoin , you may not be familiar with Bitcoin Savings and Trust (BTCST), a virtual bitcoin-based hedge fund that many suspected of being a scam. BTCST shut down in August 2012, and on Wednesday the Securities and Exchange Commission (SEC) formally charged its founder, Trendon Shavers, with running a Ponzi scheme. In a statement , the SEC said Shavers “raised at least 700, 000 Bitcoin in BTCST investments, which amounted to more than $4.5 million based on the average price of Bitcoin in 2011 and 2012 when the investments were offered and sold.” The government’s financial regulator alleges that Shavers violated a number of federal financial regulations. In court documents , the SEC wrote: Read 2 remaining paragraphs | Comments        

More:
Texas man raised over $4.5M in Bitcoin Ponzi scheme, feds allege

Apple blames days-long Developer Center outage on “intruder”

Apple Since Thursday, registered Apple developers trying to download OS X 10.9, iOS 7, or any other Apple software from the company’s developer portal have been greeted with a notice that the site was down for “maintenance.” Today, the company issued a brief statement (above) blaming the extended outage on an “intruder, ” and that Apple “[has] not been able to rule out the possibility that some developers’ names, mailing addresses, and/or email addresses may have been accessed.” The notice says that “sensitive” information could not be accessed by the intruder because it was encrypted, and the company told MacWorld that the system in question is not used to store “customer information, ” application code, or data stored by applications. Anecdotal reports (including one from our own Jacqui Cheng ) point to a sudden spike in password reset requests for some Apple IDs, suggesting that email addresses have in fact been accessed and distributed but that passwords were not. In any case, we generally recommend that users change their passwords when any breach (or suspected breach) like this one occurs. “In order to prevent a security threat like this from happening again, we’re completely overhauling our developer systems, updating our server software, and rebuilding our entire database, ” the statement said. Apple has also given week-long extensions to any developers’ whose program subscriptions were scheduled to lapse during the outage, which will keep those developers’ applications from being delisted in Apple’s various App Stores. Read on Ars Technica | Comments        

View article:
Apple blames days-long Developer Center outage on “intruder”

VLC media player returns to the iOS App Store after 30-month hiatus

A selection of videos on VLC 2.0 running on an iPad. VLC After disappearing the better part of three years ago, the VLC media player app for iOS has made its triumphant return to Apple’s App Store. Its version number has been bumped to 2.0, and the app now includes features like Wi-Fi and Dropbox syncing as well as the ability to download files from the Web. A version of VLC created by the company Applidium first made its debut on the App Store back in November 2010, but it was pulled in January 2011 due to a licensing dispute . All versions of VLC were then open-source and licensed under GPLv2; the App Store imposes its own licensing and DRM restrictions on apps. One of VLC’s original developers, Rémi Denis-Courmont, claimed that the licensing policies did not mesh and filed a complaint against the app. It was shortly removed. VLC 2.0 for iOS is licensed under both the Mozilla Public License v2 as well as the GNU General Public License v2 (or later). “The MPLv2 is applicable for distribution on the App Store, ” Felix Paul Kühne of VideoLAN told Ars. Read 2 remaining paragraphs | Comments        

See the original post:
VLC media player returns to the iOS App Store after 30-month hiatus

The cops are tracking my car—and yours

Aurich Lawson OAKLAND, CA—The last time the Oakland Police Department (OPD) saw me was on May 6, 2013 at 6:38:25pm. My car was at the corner of Mandana Blvd. and Grand Ave. , just blocks away from the apartment that my wife and I moved out of about a month earlier. It’s an intersection I drive through fairly frequently even now, and the OPD’s own license plate reader (LPR) data bears that out. One of its LPRs—Unit 1825—captured my car passing through that intersection twice between late April 2013 and early May 2013. I have no criminal record, have committed no crime, and am not (as far as I know) under investigation by the OPD or any law enforcement agency. Since I first moved to Oakland in 2005, I’ve been pulled over by the OPD exactly once—for accidentally not making a complete stop while making a right-hand turn at a red light—four years ago. Nevertheless, the OPD’s LPR system captured my car 13 times between April 29, 2012 and May 6, 2013 at various points around the city, and it retained that data. My car is neither wanted nor stolen. The OPD has no warrant on me, no probable cause, and no reasonable suspicion of wrongdoing, yet it watches where I go. Is that a problem? Read 73 remaining paragraphs | Comments        

Read More:
The cops are tracking my car—and yours

UK gov’t approves autonomous cars on public roads before year’s end

The British government has announced that it will approve testing of driverless cars on public roads in the United Kingdom before the end of 2013. According to a new 80-page report published on Tuesday entitled “Action for Roads: A network for the 21st century, ” a team at Oxford University and Nissan have already begun work but have only been testing in private areas. The plan comes less than a year after Florida , California , and Nevada have approved similar testing. Michigan is not far behind, either. Read 3 remaining paragraphs | Comments        

Originally posted here:
UK gov’t approves autonomous cars on public roads before year’s end