Follow Slashdot stories on Twitter

 



Forgot your password?
typodupeerror
×

Submission + - Researcher Finds Hidden Data-Dumping Services in iOS

Trailrunner7 writes: There are a number of undocumented and hidden features and services in Apple iOS that can be used to bypass the backup encryption on iOS devices and remove large amounts of users’ personal data. Several of these features began as benign services but have evolved in recent years to become powerful tools for acquiring user data.

Jonathan Zdziarski, a forensic scientist and researcher who has worked extensively with law enforcement and intelligence agencies, has spent quite a bit of time looking at the capabilities and services available in iOS for data acquisition and found that some of the services have no real reason to be on these devices and that several have the ability to bypass the iOS backup encryption. One of the services in iOS, called mobile file_relay, can be accessed remotely or through a USB connection can be used to bypass the backup encryption. If the device has not been rebooted since the last time the user entered the PIN, all of the data encrypted via data protection can be accessed, whether by an attacker or law enforcement, Zdziarski said.

Zdziarski discussed his findings in a talk at the HOPE X conference recently and published the slides and paper, as well. The file_relay service has been in iOS for some time and originally was benign, but Zdziarski said that in recent versions it has turned into a tool that can dump loads of user data on command. The file_relay tool can dump a list of the email and social media accounts, the address book, the user cache folder, which contains screenshots, offline content, copy/paste data, keyboard typing cache and other personal data. The tool can also provide a log of periodic location snapshots from the device.

Submission + - MIT's Ted Postol presents more evidence on Iron Dome failures (thebulletin.org) 1

Lasrick writes: In a controversial article last week, MIT physicist Ted Postol again questioned whether Israel's vaunted Iron Dome rocket defense system actually works. This week, he comes back with evidence in the form of diagrams, photos of Iron Dome intercepts and contrails, and evidence on the ground to show that Iron Dome in fact is effective only about 5% of the time. Postol believes the real reason there are so few Israeli casualties is that Hamas rockets have very small warheads (only 10 to 20 pounds), and also Israel's outstanding civil defense system, which includes a vast system of shelters and an incredibly sophisticated rocket attack warning system (delivered through smart phones, among other ways).

Comment Re:There's something touching about that comment (Score 2) 102

It's not the human *touch* that people crave in a complicated interaction with a system. It's human *versatility*.

Thus more personnel does no good, if those personnel are rigidly controlled, lack information to advise or authority to act. The fact that they're also expected to be jolly and upbeat as they follow their rigid and unyielding rules only turns the interaction with them into a travesty of a social interaction.

What would work better is a well-designed check-in system that handles routine situations nearly all the time, along with a few personnel who have the training and authority to solve any passenger problems that come up.

Comment Re: Hmmm (Score 1) 205

We have a minivan. We got it just before our first child was born 11 years ago. It was quite handy during the years when the kids required a ton of stuff for trips (stroller, seat to eat in, portable crib, ton of diapers, etc). Now it is overkill and the low mileage makes it expensive to drive on long trips. When the time comes to replace it, we're definitely getting something with better mpg.

Submission + - No RIF'd Employees Need Apply for Microsoft External Staff Jobs for 6 Months 1

theodp writes: So, what does Microsoft do for an encore after laying off 18,000 employees with a hilariously bad memo? Issue another bad memo — Changes to Microsoft Network and Building Access for External Staff — "to introduce a new policy [retroactive to July 1] that will better protect our Microsoft IP and confidential information." How so? "The policy change affects [only] US-based external staff (including Agency Temporaries, Vendors and Business Guests)," Microsoft adds, "and limits their access to Microsoft buildings and the Microsoft corporate network to a period of 18 months, with a required six-month break before access may be granted again." Suppose Microsoft feels that's where the NSA went wrong with Edward Snowden? And if any soon-to-be-terminated Microsoft employees hope to latch on to a job with a Microsoft external vendor to keep their income flowing, they best think again. "Any Microsoft employee who separated from Microsoft on or after July 1, 2014," the kick-em-while-they're-down memo explains, "will be required to take a minimum 6-month break from access between the day the employee separates from Microsoft and the date when the former employee may begin an assignment as an External Staff performing services for Microsoft."

Comment Re: The issue is big publishing (Score 2) 192

I can only go with the experience of my friends, who've gone both routes successfully.

It's true that traditional publishers expect mid-list authors to shoulder most of the promotion efforts these days. I never said they didn't. Fiction authors are now expected to maintain a platform, which used to be a non-fiction thing. Certainly traditional publishers have become more predatory and less supportive than they were twenty years ago. I don't have an inside track on why that is, but I suspect there are several causes. One is that POD allows publishers to make an reliable though modest profit from their mid-list authors, which ironically makes them more risk averse. But publishers still provide production and editing services on a MS that'd cost you maybe ten thousand dollars if you were contracting those services out. They also get your book in bricks-and-mortar bookstores, which is a bridge too far for most indy authors, even the successful ones.

A lot of the bad feeling that publishers get from indy authors comes from two sources. First, a long history with rejection. Second the lack of respect indy authors get relative to traditionally published authors. We can see it in this discussion elsewhere, where one poster puts "authors" in quotes when referring to indy authors. And it's easy to see why because most indy authors just aren't good enough to get traditionally published. *Some* indy authors put out a product that's every bit as good as the mid-list authors from the big publishing houses, but most just dump their terrible manuscripts on Amazon with a clip-art cover and no copy editing, much less developmental editing.

The statistic that most indy authors make their investment back plus 40% didn't impress me, because (a) that counts the author's labor as free and (b) most indy authors don't invest much cash in their projects. The percentage of indy authors that clear, say, five thousand dollars in profit are very small.

It's not that indy publishing doesn't have its points, and my traditionally published friends are certainly thinking about dipping their toe in the water. But it's not as cheap as it looks if you want a comparable product, and you give up certain things. I was in Manhattan recently and went to the 5th Avenue branch of the NYPL. My traditionally published friends' books were either on the shelves our out circulating. The NYPL had *none* of my indy author friends' books, even though at least one of them has made the New York Times best seller list.

Comment Re:The issue is big publishing (Score 1) 192

I don't think it's as simple as Amazon is good or Amazon is evil. Amazon is powerful, and that needs watching.

Now I have a number writer friends, one of whom is published both with traditional imprints like TOR and with Amazon's new in-house publishing imprints. She has good things to say about Amazon's imprints, but one thing you have to take into account is that nobody will stock your book *but* Amazon if you publish with them. That's giving up a lot, so they treat authors reasonably well. But that doesn't mean the corporation actually cares about authors. Amazon needs reliable mid-list authors to make their publishing ventures a success, and by cutting out the middleman can afford generous royalties. But if Amazon succeeds in putting a stake in the heart of traditional publishing, I wouldn't care to speculate on what will happen to authors.

Nor should what traditional publishers do for authors be underestimated. I have friends who are successful indy writers, but it's not like being a writer, it's more like running a small publishing house yourself. They hire story editors, copy editors and artists, and manage promotion and publicity. It's a lot of work; that plus actually writing pretty much precludes a day job. It's not for everyone.

It's a lot like being an engineer. Engineers are smart people who usually have a lot of insight into the companies they work for, but that doesn't mean that most engineers want to run businesses. Some do, but most would rather have other people take care of that stuff so they can concentrate on what they feel they're best at.

Many writers choose the indy market because it's the only way they'll ever get published. They just dump their manuscript on the market without editing, design or promotion and hope for the best. They rarely succeed. Others choose the indy route because they thrive on running and controlling their own small business, the way some engineers step naturally into the role of entrepreneur. They're well positioned for the future. But most writers need support to reach their full potential.

Comment Re:I disagree (Score 1) 390

That's a good point. Verizon is complaining about the asymmetric nature of their peering, but it's really their own fault. If you give your customers connections with vastly greater upstream speeds than downstream speeds, you shouldn't act surprised when you're pulling more data from your peering connections than you are sending. (Same goes for not allowing customers to run servers.)

Comment Re:Cure? (Score 1) 253

The headline is sensationalist. A "cure" could be to find a way for the body to start producing whatever variation on this hormone they come up with to address the insulin resistance, and the insulin sensitivity on it's own, without additional pharmacology. I'm not expecting that to happen though.

Comment The reasons why these samples went unnoticed... (Score 1) 55

...for so long.

I'm going with some agency who considered obscurity and secrecy to be effective means of insuring safety neglected to pass on the details of what they were securing to the appropriate agencies that were taking over the care and handling of these vials. That and the agency taking over the care and handling never bothered to review what information was being handed over, and possibly discarded and destroyed the records when they met the agencies 'retain until' date for some category that those records were filed under.

Submission + - New York state proposes sweeping Bitcoin regulations

An anonymous reader writes: On Thursday, Benjamin M. Lawsky, the superintendent of financial services, announced proposed regulations for virtual currency companies operating in New York. The “BitLicense” plan, which includes rules on consumer protection, the prevention of money laundering and cybersecurity, is the first proposal by a state to create guidelines specifically for virtual currency. "We have sought to strike an appropriate balance that helps protect consumers and root out illegal activity—without stifling beneficial innovation,” he said in a statement.

Slashdot Top Deals

A boss with no humor is like a job that's no fun.

Working...