Want to read Slashdot from your mobile device? Point it at m.slashdot.org and keep reading!

 



Forgot your password?
typodupeerror
×
Transportation

Uber's Hiring Plans Show Outlines of Self-Driving Car Project 45

itwbennett writes The most interesting people that Uber is now hiring aren't drivers: they're engineers. The mobile ride-hailing app has listed a slew of jobs at its new Advanced Technologies Center in Pittsburgh. In particular, Uber is looking for engineers in the areas of robotics, machine learning, communications, traffic simulation, vehicle testing, and software and hardware development.

Submission + - FREAK Attack Threatens SSL Clients (threatpost.com)

msm1267 writes: For the nth time in the last couple of years, security experts are warning about a new Internet-scale vulnerability, this time in some popular SSL clients. The flaw allows an attacker to force clients to downgrade to weakened ciphers and break their supposedly encrypted communications through a man-in-the-middle attack.

Researchers recently discovered that some SSL clients, including OpenSSL, will accept weak RSA keys–known as export-grade keys–without asking for those keys. Export-grade refers to 512-bit RSA keys, the key strength that was approved by the United States government for export overseas. This was an artifact from decades ago and it was thought that most servers and clients had long ago abandoned such weak ciphers.

The vulnerability affects a variety of clients, most notably Apple’s Safari browser. The bug was discovered by a large group of researchers from Microsoft Research and the French National Institute for Research in Computer Science and Control, and they found that given a server that supports export-grade ciphers and a client that accepts those weak keys, an attacker with a man-in-the-middle position could force a client to downgrade to the weak keys. He could then take the key and factor it, which researchers were able to do in about seven and a half hours, using Amazon EC2. And because it’s resource-intensive to generate RSA keys, servers will generate one and re-use it indefinitely.

Slashdot Top Deals

8 Catfish = 1 Octo-puss

Working...