Want to read Slashdot from your mobile device? Point it at m.slashdot.org and keep reading!

 



Forgot your password?
typodupeerror
×
Encryption

CNN iPhone App Sends iReporters' Passwords In the Clear 40

chicksdaddy (814965) writes The Security Ledger reports on newly published research from the firm zScaler that reveals CNN's iPhone application transmits user login session information in clear text. The security flaw could leave users of the application vulnerable to having their login credential snooped by malicious actors on the same network or connected to the same insecure wifi hotspot. That's particularly bad news if you're one of CNN's iReporters — citizen journalists — who use the app to upload photos, video and other text as they report on breaking news events. According to a zScaler analysis, CNN's app for iPhone exposes user credentials in the clear both during initial setup of the account and in subsequent mobile sessions. The iPad version of the CNN app is not affected, nor is the CNN mobile application for Android. A spokesman for CNN said the company had a fix ready and was working with Apple to have it approved and released to the iTunes AppStore.
Cellphones

Amazon Fire Phone Reviews: Solid But Overly Ambitious 58

An anonymous reader writes: Amazon's Fire Phone launches later this week, and the reviews have started to come in. The hardware: "There's nothing terribly special about the Fire Phone's hardware, but there's very little to turn you off either." "The nice-looking IPS display in the Fire Phone gets bright enough for outdoor viewing, and it has nice viewing angles—a necessity for a phone that's meant to be tilted around and looked at from every which way." "An indistinct slab of glass and plastic, the Fire Phone looks more like a minimalist prototype than a finished product."

Software: "Firefly can recognize lots of things, but it's incredibly, hilariously inconsistent." "Firefly is the one Fire Phone feature you'll want on any phone you're currently using. Let's hope that it gets enough developer support that it isn't just a link to Amazon's storefronts." "First, and to be absolutely clear, Dynamic Perspective will impress you the first time you see it, and Amazon is pretty good at showing it off. ... But if there's some cool, useful functionality to be had from super-aggressive, super-accurate face tracking, the Fire Phone doesn't have it." Conclusion: "Smartphones are for work, for life. They're not toys, they're tools. Amazon doesn't understand that, and the Fire Phone doesn't reflect it."

Comment Re:Yeah, students will use bandwidth (Score 1) 285

Rather than telling other people to "grow up," how about focusing on their actual arguments? That's something you didn't really do to begin with.

Well I would, had there been any arguments present. There weren't. It was all pure opinion. It is not "a fact" that walled gardens are bad - it's an opinion. You should really learn the difference.

Bug

Researchers Test Developer Biometrics To Predict Buggy Code 89

rjmarvin writes: Microsoft Research is testing a new method for predicting errors and bugs while developers write code: biometrics. By measuring a developer's eye movements, physical and mental characteristics as they code, the researchers tracked alertness and stress levels to predict the difficulty of a given task with respect to the coder's abilities. In a paper entitled "Using Psycho-Physiological Measures to Assess Task Difficulty in Software Development," the researchers summarized how they strapped an eye tracker, an electrodermal sensor and an EEG sensor to 15 developers as they programmed for various tasks. Biometrics predicted task difficulty for a new developer 64.99% of the time. For a subsequent tasks with the same developer, the researchers found biometrics to be 84.38% accurate. They suggest using the information to mark places in code that developers find particularly difficult, and then reviewing or refactoring those sections later.
Google

The "Rickmote Controller" Can Hijack Any Google Chromecast 131

redletterdave writes Dan Petro, a security analyst for the Bishop Fox IT consulting firm, built a proof of concept device that's able to hack into any Google Chromecasts nearby to project Rick Astley's "Never Gonna Give You Up," or any other video a prankster might choose. The "Rickmote," which is built on top of the $35 Raspberry Pi single board computer, finds a local Chromecast device, boots it off the network, and then takes over the screen with multimedia of one's choosing. But it gets worse for the victims: If the hacker leaves the range of the device, there's no way to regain control of the Chromecast. Unfortunately for Google, this is a rather serious issue with the Chromecast device that's not too easy to fix, as the configuration process is an essential part of the Chromecast experience.
Privacy

Researcher Finds Hidden Data-Dumping Services In iOS 98

Trailrunner7 writes There are a number of undocumented and hidden features and services in Apple iOS that can be used to bypass the backup encryption on iOS devices and remove large amounts of users' personal data. Several of these features began as benign services but have evolved in recent years to become powerful tools for acquiring user data.

Jonathan Zdziarski, a forensic scientist and researcher who has worked extensively with law enforcement and intelligence agencies, has spent quite a bit of time looking at the capabilities and services available in iOS for data acquisition and found that some of the services have no real reason to be on these devices and that several have the ability to bypass the iOS backup encryption. One of the services in iOS, called mobile file_relay, can be accessed remotely or through a USB connection can be used to bypass the backup encryption. If the device has not been rebooted since the last time the user entered the PIN, all of the data encrypted via data protection can be accessed, whether by an attacker or law enforcement, Zdziarski said.
Update: 07/21 22:15 GMT by U L : Slides.
Cellphones

Why My LG Optimus Cellphone Is Worse Than It's Supposed To Be 291

Bennett Haselton writes My LG Optimus F3Q was the lowest-end phone in the T-Mobile store, but a cheap phone is supposed to suck in specific ways that make you want to upgrade to a better model. This one is plagued with software bugs that have nothing to do with the cheap hardware, and thus lower one's confidence in the whole product line. Similar to the suckiness of the Stratosphere and Stratosphere 2 that I was subjected to before this one, the phone's shortcomings actually raise more interesting questions — about why the free-market system rewards companies for pulling off miracles at the hardware level, but not for fixing software bugs that should be easy to catch. Read below to see what Bennett has to say.

Slashdot Top Deals

THEGODDESSOFTHENETHASTWISTINGFINGERSANDHERVOICEISLIKEAJAVELININTHENIGHTDUDE

Working...