Become a fan of Slashdot on Facebook

 



Forgot your password?
typodupeerror
×
Android

Old Apache Code At Root of Android FakeID Mess 127

chicksdaddy writes: A four-year-old vulnerability in an open source component that is a critical part of Android leaves hundreds of millions of mobile devices susceptible to silent malware infections. The vulnerability affects devices running Android versions 2.1 to 4.4 ("KitKat"), according to a statement released by Bluebox. The vulnerability was found in a package installer in affected versions of Android. The installer doesn't attempt to determine the authenticity of certificate chains that are used to vouch for new digital identity certificates. In short, Bluebox writes, "an identity can claim to be issued by another identity, and the Android cryptographic code will not verify the claim."

The security implications of this are vast. Malicious actors could create a malicious mobile application with a digital identity certificate that claims to be issued by Adobe Systems. Once installed, vulnerable versions of Android will treat the application as if it was actually signed by Adobe and give it access to local resources, like the special webview plugin privilege, that can be used to sidestep security controls and virtual 'sandbox' environments that keep malicious programs from accessing sensitive data and other applications running on the Android device. The flaw appears to have been introduced to Android through an open source component, Apache Harmony. Google turned to Harmony as an alternative means of supporting Java in the absence of a deal with Oracle to license Java directly.

Work on Harmony was discontinued in November, 2011. However, Google has continued using native Android libraries that are based on Harmony code. The vulnerability concerning certificate validation in the package installer module persisted even as the two codebases diverged.

Comment Re: Nuke those terrorists (Score 1) 868

I'n not the one who left you looking "like some Palestinian-supporter", you took care of that nicely on your own. I don't really take a side in any war in the middle east, as I have been on the planet long enough to know better (Iraq, Lebanon, Syria, etc).

My point is that Hamas has been extremely aggressive in this go-round and has targeted civilian populations both for attacks as well as retaliations. Hamas is actually proud of the civilian death toll. For example today on Hamas TV: Dead Gaza civilians privileged to have died this way (Warning Graphic) https://www.youtube.com/watch?... Here is another example, Hamas members brutally beating civilians of Gaza who leave their homes following IDF warnings (Warning Graphic) https://www.youtube.com/watch?... Hamas sucks, there is no way around it, they are not the "good guys".

On the other hand Israel's destroying the only power plant in Gaza can in no way be considered legitimate unless there was a tunnel beneath it.

The idea that anyone there will ever set "aside generations of prejudices to actually put this shit behind us and move forward into a new era of peace" is a nice dream. Ask Anwar Sadat how that works out.

Comment The programming language for the next 20 years... (Score 5, Insightful) 315

C. Plain old C.

Entire Operating Systems are written in it. Userland tools for those operating systems are usually written in it. Any self-respecting developer knows at least C. The rest is just like fashion tips: next year they're outdated.

Although, as much as I hate to admit it, the same could be said for Java...

Space

Enceladus's 101 Geysers Blast From Hidden Ocean 39

astroengine writes: New observations from NASA's Saturn-orbiting Cassini spacecraft have revealed at least 101 individual geysers erupting from Enceladus' crust and, through careful analysis, planetary scientists have uncovered their origin. From the cracked ice in this region, fissures blast out water vapor mixed with organic compounds as huge geysers. Associated with these geysers are surface "hotspots" but until now there has been some ambiguity as to whether the hotspots are creating the geysers or whether the geysers are creating the hotspots. "Once we had these results in hand, we knew right away heat was not causing the geysers, but vice versa," said Carolyn Porco, leader of the Cassini imaging team from the Space Science Institute in Boulder, Colo., and lead author of one of the research papers. "It also told us the geysers are not a near-surface phenomenon, but have much deeper roots." And those roots point to a large subsurface source of liquid water — adding Enceladus as one of the few tantalizing destinations for future astrobiology missions.

Comment Re: What makes this a gigafactory? (Score 2) 95

So? They weren't SI units, but they used SI prefixes (wrongly.) Now the SI has made SI units based on the old ones that do conform. They even threw in some binary units for the times that they are actually useful. You're just pissed because it turns out people respect the SI more they do grumpy old computer geeks.

Comment Re:Considering his history... (Score 1) 144

Do you like movies about ponies?

Yeah. I don't really dislike superhero movies, but honestly the constant stream of super avenger-men movies made the whole thing kind of boring. It's like when all games were WW2 FPSes, except worse because Nazis are more interesting than comic book villains.

I neither like nor dislike movies about ponies. I like good movies. Is there a good movie about ponies? If so, I may watch it. I remember kind of liking "Black Stallion" when we saw it in the theater, but that was no pony. Looking forward to hearing your pony film recommendation.

Programming

Programming Languages You'll Need Next Year (and Beyond) 315

Nerval's Lobster writes: Over at Dice, there's a breakdown of the programming languages that could prove most popular over the next year or two, including Apple's Swift, JavaScript, CSS3, and PHP. But perhaps the most interesting entry on the list is Erlang, an older language invented in 1986 by engineers at Ericsson. It was originally intended to be used specifically for telecommunications needs, but has since evolved into a general-purpose language, and found a home in cloud-based, high-performance computing when concurrency is needed. "There aren't a lot of Erlang jobs out there," writes developer Jeff Cogswell. "However, if you do master it (and I mean master it, not just learn a bit about it), then you'll probably land a really good job. That's the trade-off: You'll have to devote a lot of energy into it. But if you do, the payoffs could be high." And while the rest of the featured languages are no-brainers with regard to popularity, it's an open question how long it might take Swift to become popular, given how hard Apple will push it as the language for developing on iOS.
Government

Senate Bill Would Ban Most Bulk Surveillance 176

An anonymous reader writes: Today Senator Patrick Leahy (D-VT) introduced a bill that would ban bulk collection of telephone records and internet data for U.S. citizens. This is a stronger version of the legislation that passed the U.S. House in May, and it has support from the executive branch as well. "The bill, called the USA Freedom Act, would prohibit the government from collecting all information from a particular service provider or a broad geographic area, such as a city or area code, according to a release from Leahy's office. It would expand government and company reporting to the public and reform the Foreign Intelligence Surveillance Court, which reviews NSA intelligence activities. Both House and Senate measures would keep information out of NSA computers, but the Senate bill would impose stricter limits on how much data the spy agency could seek."

Submission + - When Metrics Go Wrong - how to avoid bad metrics in open source projects (redhat.com) 1

An anonymous reader writes: Good metrics should lead to action, but if you're not careful, you can end up with results you didn't intend. (This is called "The Cobra Effect".) And typically there are three ways that metrics can cause these unintended results.

Submission + - Which is better, Adblock or Adblock Plus? (palant.de)

An anonymous reader writes: Wladimir Palant is the creator of the Adblock Plus browser extension, but he often gets asked how it compares to a similar extension for Chrome called Adblock. In the past, he's told people that they're achieve largely the same end in slightly different ways, but recent changes to the Adblock project have him worried. "AdBlock covertly moved from an open development model towards hiding changes from its users. Users were neither informed about that decision nor the reasons behind it." He goes through the changelog and highlights some changes that call into question the integrity of Adblock. For example, from an update on June 6th: "Calling home functionality has been extended. It now sends user’s locale in addition to the unique user ID, AdBlock version, operating system and whether Google Search ads are being allowed. Also, AdBlock will tell getadblock.com (or any other website if asked nicely) whether AdBlock has just been installed or has been used for a while — again, in addition to the unique user ID." Of course, Palant has skin in this game, and Adblock Plus has dealt with fallout from their "acceptable ads policy," but at least it's still developed in the open.
Stats

Better Living Through Data 38

jradavenport (3020071) writes "Using two years of continuous monitoring of my MacBook Air battery usage (once every minute), I have been able to study my own computer use patterns in amazing detail. This dataset includes 293k measurements, or more than 204 days of use over two years. I use the laptop over 50 hours per week on average, and my most productive day is Tuesday. Changes in my work/life balance have begun to appear over the two-year span, and I am curious whether such data can help inform how much computer use is healthy/productive."
Security

Put Your Code in the SWAMP: DHS Sponsors Online Open Source Code Testing 67

cold fjord (826450) writes with an excerpt from ZDNet At OSCon, The Department of Homeland Security (DHS) ... quietly announced that they're now offering a service for checking out your open-source code for security holes and bugs: the Software Assurance Marketplace (SWAMP). ... Patrick Beyer, SWAMP's Project Manager at Morgridge Institute for Research, the project's prime contractor, explained, "With open source's popularity, more and more government branches are using open-source code. Some are grabbing code from here, there, and everywhere." Understandably, "there's more and more concern about the safety and quality of this code. We're the one place you can go to check into the code" ... funded by a $23.4 million grant from the Department of Homeland Security Science & Technology Directorate (DHS S&T), SWAMP is designed by researchers from the Morgridge Institute, the University of Illinois-Champaign/Urbana, Indiana University, and the University of Wisconsin-Madison. Each brings broad experience in software assurance, security, open source software development, national distributed facilities and identity management to the project. ... SWAMP opened its services to the community in February of 2014 offering five open-source static analysis tools that analyze source code for possible security defects without having to execute the program. ... In addition, SWAMP hosts almost 400 open source software packages to enable tool developers to add enhancements in both the precision and scope of their tools. On top of that the SWAMP provides developers with software packages from the National Institute for Standards and Technology's (NIST) Juliet Test Suite. I got a chance to talk with Beyer at OSCON, and he emphasized that anyone's code is eligible — and that there's no cost to participants, while the center is covered by a grant.
Power

Gaza's Only Power Plant Knocked Offline 868

necro81 (917438) writes "Gaza's only power plant (see this profile at IEEE Spectrum — duct tape and bailing wire not included) has been knocked offline following an Israeli strike. Reports vary, but it appears that Israeli tank shells caused a fuel bunker at the plant to explode. Gaza, already short on electricity despite imports from Israel and Egpyt, now faces widening blackouts."
Portables

Ask Slashdot: Where Can I Find Resources On Programming For Palm OS 5? 170

First time accepted submitter baka_toroi (1194359) writes I got a Tungsten E2 from a friend and I wanted to give it some life by programming for it a little bit. The main problem I'm bumping up against is that HP thought it would be awesome to just shut down every single thing related to Palm OS development. After Googling a lot I found out CodeWarrior was the de facto IDE for Palm OS development... but I was soon disappointed as I learned that Palm moved from the 68K architecture to ARM, and of course, CodeWarrior was just focused on Palm OS 4 development.

Now, I realize Palm OS 4 software can be run on Palm OS 5, but I'm looking to use some of the 'newer' APIs. Also, I have the Wi-fi add-on card so I wanted to create something that uses it. I thought what I needed was PODS (Palm OS Development Suite) but not only I can't find it anywhere but also it seems it was deprecated during Palm OS's lifetime. It really doesn't help the fact that I'm a beginner, but I really want to give this platform some life. Any general tip, book, working link or even anecdotes related to all this will be greatly appreciated.

Slashdot Top Deals

"Ninety percent of baseball is half mental." -- Yogi Berra

Working...