Follow Slashdot stories on Twitter

 



Forgot your password?
typodupeerror
×

Submission + - XKEYSCORE: NSA'S Google for the World's Private Communications (firstlook.org)

Advocatus Diaboli writes: "The NSA’s ability to piggyback off of private companies’ tracking of their own users is a vital instrument that allows the agency to trace the data it collects to individual users. It makes no difference if visitors switch to public Wi-Fi networks or connect to VPNs to change their IP addresses: the tracking cookie will follow them around as long as they are using the same web browser and fail to clear their cookies. Apps that run on tablets and smartphones also use analytics services that uniquely track users. Almost every time a user sees an advertisement (in an app or in a web browser), the ad network is tracking users in the same way. A secret GCHQ and CSE program called BADASS, which is similar to XKEYSCORE but with a much narrower scope, mines as much valuable information from leaky smartphone apps as possible, including unique tracking identifiers that app developers use to track their own users."

also

"Other information gained via XKEYSCORE facilitates the remote exploitation of target computers. By extracting browser fingerprint and operating system versions from Internet traffic, the system allows analysts to quickly assess the exploitability of a target. Brossard, the security researcher, said that “NSA has built an impressively complete set of automated hacking tools for their analysts to use.” Given the breadth of information collected by XKEYSCORE, accessing and exploiting a target’s online activity is a matter of a few mouse clicks. Brossard explains: “The amount of work an analyst has to perform to actually break into remote computers over the Internet seems ridiculously reduced — we are talking minutes, if not seconds. Simple. As easy as typing a few words in Google.”

Comment Re:ipv6 incompetence is nothing new. (Score 1) 65

The idea of solving the problem by reclaiming IPv4 addresses was considered, but the math doesn't work:

Now, average daily assignment rates have been running at above 10 /8s per year, for 2010, and approached 15 /8s towards the end. This means any reclamation effort has to recover at least 15 /8s per year just to break even on 2010’s growth. That’s 5.9% of the total IPv4 address space, or 6.8% of the assignable address space.

Looking at the /8 blocks assigned to organizations other than regional NICs, there are 40 of them. So even if we could persuade all those organizations to give up their /8s, and even if we could organize it all quickly enough, the best we could do would be to put off the problem for 3 more years.

In addition, reclaiming IPv4 addresses is far more expensive than rolling out IPv6, and it's hard enough to persuade companies that they need to roll out IPv6.

And the calculation for class B allocations is even worse, because you have to deal with a lot more organizations; the cost is higher for far lower returns.

Comment Re:Iran is not trying to save money (Score 1) 409

Well, you have to factor in the Iranian cultural mania for disagreeing with each other. The Shah couldn't keep them under his thumb, neither can the mullahs, who have their hands full disagreeing with each other.

From a tyrant's perspective Iran is ungovernable, which doesn't mean elements in the government don't give tyranny a go on a regular basis. It's an ideal setup for producing martyrs. The futility of cracking down means you have a little space to rake some muck before official anger overcomes reason.

Education

Struggling University of Phoenix Lays Off 900 133

An anonymous reader writes: The struggles facing for-profit colleges continue. The University of Phoenix announced poor quarterly earnings yesterday, and the institution has laid off 900 workers since September. Enrollment is down 14% since last year, and the CEO of its parent company, Apollo Education Group, says enrollment is likely to drop from 206,000 to about 150,000 next year. Apollo's stock has lost more than half its value since the beginning of the year. "Tighter regulations on for-profits and the Obama administration's push to make community college free top the list of headwinds. And non-profit universities have entered the online education space, where for-profit schools once held center stage."
Operating Systems

People Are Obtaining Windows 7 Licenses For the Free Windows 10 Upgrade 172

jones_supa writes: Windows 7 has quickly started increasing its market share of desktop operating systems, nearing 61%. If you're wondering why this is happening when Windows 10 is almost here, the reason is this: Windows 10 will be available as a free upgrade for those running Windows 7 and 8, and the new OS will have the exact same hardware requirements as its predecessor, so the majority of PCs should be able to run it just as well. Because Windows 7 was launched in 2009, a license is more affordable than for Windows 8, so many users are switching to this version to take advantage of the Windows 10 free upgrade offer.

Comment Re:Virtulize it (Score 1) 66

Comment Re:i switched back from chrome to safari (Score 3, Interesting) 311

I also use Safari, though I'm still pissed off with them for combining the URL bar and search box (which means that I keep typing one-word search terms and having it try to resolve them as domains, which then go in my history and so become the subject of autocomplete. The only way to avoid it is to get into the habit of hitting space at the end of a search, which is no saving on hitting tab at the start to jump to the search box). Chrome doesn't properly integrate with the keychain. I use Firefox on Android (self destructing cookies makes it the first browser I've used with a sane cookie management policy), but overall the UI for Safari does exactly what I want from a browser: stay out of the way.

TFS is nonsense though. Developers don't know what's going to be in the next version of Safari? Why don't they download the nightly build and see?

Comment iOS users feel it (Score 1, Insightful) 311

I currently have a web radio transceiver front panel application that works on Linux, Windows, MacOS, Android, Amazon Kindle Fire, under Chrome, Firefox, or Opera. No porting, no software installation. See blog.algoram.com for details of what I'm writing.

The one unsupported popular platform? iOS, because Safari doesn't have the function used to acquire the microphone in the web audio API (and perhaps doesn't have other parts of that API), and Apple insists on handicapping other browsers by forcing them to use Apple's rendering engine.

I don't have any answer other than "don't buy iOS until they fix it".

Privacy

Surveillance Court: NSA Can Resume Bulk Surveillance 161

An anonymous reader writes: We all celebrated back in May when a federal court ruled the NSA's phone surveillance illegal, and again at the beginning of June, when the Patriot Act expired, ending authorization for that surveillance. Unfortunately, the NY Times now reports on a ruling from the Foreign Intelligence Surveillance Court, which concluded that the NSA may temporarily resume bulk collection of metadata about U.S. citizens's phone calls. From the article: "In a 26-page opinion (PDF) made public on Tuesday, Judge Michael W. Mosman of the surveillance court rejected the challenge by FreedomWorks, which was represented by a former Virginia attorney general, Ken Cuccinelli, a Republican. And Judge Mosman said that the Second Circuit was wrong, too. 'Second Circuit rulings are not binding' on the surveillance court, he wrote, 'and this court respectfully disagrees with that court's analysis, especially in view of the intervening enactment of the U.S.A. Freedom Act.' When the Second Circuit issued its ruling that the program was illegal, it did not issue any injunction ordering the program halted, saying that it would be prudent to see what Congress did as Section 215 neared its June 1 expiration."

Comment Re:Big giant scam ... (Score 1) 843

I distinctly remember it being promised that the F-35 would beat anything but an F-22 in air-to-air combat, at a fraction of the price. It was not part of the original concept for the system but it was definitely sold politically as being capable of acting as a poor man's F22.

I wonder about the helmet mounted display, whether that's something you'd consider absolutely necessary in an aircraft whose job is to hit surface targets in contested airspace.

Comment Re:Big giant scam ... (Score 1) 843

As a supposed air-superiority platform, this is an utter failure.

To be fair, that was not the original justification for the thing. That was mission creep.

I think the original impetus was to have something stealthy that could do ground strikes in enemy territory. And it makes sense to do a naval version of the same thing. If they'd just focused on that they'd have been done a long time ago with a solid design, which of course in engineering nearly always turns out to be more versatile than you planned for. Adding STOVL and the whizbang helmet (cool as that may be) as necessary elements of the system turned this into an "everything for everyone" project, which almost always turns out less versatile than you hoped.

Comment Re:Dogfights?! What year is it?! (Score 1) 843

Sure you can identify scenarios where the A-10 is useless. But in the last twenty years it's been extremely useful in a number scenarios we've actually faced.

The idea that a system ought to play every role in every conceivable situation is why the F35 performs none of them very well. In hindsight the idea of accommodating the Marines' need for a STOVL aircraft in the same basic design probably dictated too many compromises in the plane's other roles.

Slashdot Top Deals

He has not acquired a fortune; the fortune has acquired him. -- Bion

Working...