Want to read Slashdot from your mobile device? Point it at m.slashdot.org and keep reading!

 



Forgot your password?
typodupeerror
×

Submission + - Intentional backdoor in consumer routers found (synacktiv.com)

janoc writes: Eloi Vanderbeken from Synacktiv has identified an intentional backdoor in a module by Sercomm used by major router manufacturers (Cisco, Linksys, Netgear ...). The backdoor was ostensibly fixed — by obfuscating it and making it harder to access.

The original report is here (pdf)

And yeah, there is an exploit available ...

Comment Re:They will take it seriously (Score 2) 54

Which is happening routinely. Many older birds don't require any authentication nor anything - they simply retransmit whatever they hear on one frequency on another one: http://spectregroup.wordpress....

And those are US NAVY (!!!) satellites!

Doing that with Iridium or Inmarsat hardware is a bit more complex, because the protocols are mostly digital, but not impossible neither.

Comment OSS security debate (Score 3, Interesting) 54

Wasn't it just yesterday that someone has posted a flamebait summary about the Heartbleed bug changing the "Open source is safer" discussion?

This is a great evidence of what happens when you rely on security by obscurity in proprietary software. Nobody is forced to fix things, sloppy coding is the norm and there are backdoors galore ...

Unfortunately, the bad guys laugh, the vendors play ostrich with the heads in sand and everyone else is suffering the consequences ...

Comment Likely joke posting or a really stupid scam (Score 1) 157

So, Indiegogo flexible funding campaign? I.e. they get money even if the campaign doesn't meet the goals? 4 years in development and nothing to show on the project page apart from a few renders that any kid can do in a day in 3DS Max or Blender? They throw big names like DASSAULT or Airbus around, ostensibly as being interested, but they need a few millions on Indiegogo? The perks are an obvious joke (40k euro for an old Renault Espace? You got to be kidding ...).

Mr. Chorostecki appears to be an economic consultant (nothing to do with aerospace whatsoever: http://www.figxy.com/ )
Mr. Buron is a design/creative consultant (with http://buron.phpnet.org/fre/ag... )
And the third founder Desauvage is, surprise, "creative director".

I wonder whether "inventor and designer" means "I have drawn something in Photoshop and now I only need someone to build it for me", because none of these guys has any relevant engineering qualifications whatsoever.

Oh and it seems they weren't very welcome in France for whatever reason in 2013 ( http://www.ladepeche.fr/articl... ), so that's why they want to go to Silicon Valley ... The article also mentions that the vehicle was to be all-electric (yeah right, pipe dreams ...).

The probability that any backers, who would put actually money into this, will see anything from this project, is pretty much zero, IMO.

Comment Re:Changing IMEI is illegal (Score 3) 109

That sounds as if the criminals actually cared about it being illegal. One of the guys has mugged someone to get the phone in the first place and the other one is dealing in them - both crimes with likely a lot stiffer sentence than a stupid IMEI change. C'mon ....

Don't be ridiculous - until there stops being demand for extremely cheap phones (so that one can show off in front of the peers) and the manufacturers and network operators actually start doing something about it (Why is IMEI changeable in the first place?), trade in stolen phones will continue. Unfortunately, it would have to stop being profitable for them. All those IMEI blocks and such by the operators are ineffective if the phone can have the IMEI changed and not even all of them are implementing those blocks.

The other issue is that when even BBC can easily find and film (!) fences dealing in stolen goods, then what is the police doing? Ah, right, that is UK, so they are likely busy detaining journalists as terrorists, there is no time to fight petty theft and muggers.

Comment Re:Database Scaleability. (Score 5, Insightful) 272

Databases don't scale for people who don't understand SQL, don't understand data normalization, indexing and want to use them as flat files. Unfortunately, a way too common anti-pattern :(

The second group are too-cool-to-learn kids using the latest development tool fad on the market to build yet another Facebook/Twitter/Instagram/whatever clone ...

Comment Energy (Score 1) 256

This sort of reaction is nice, but don't forget that it needs gobs and gobs of energy to build those hydrocarbons. Don't forget that the energy you use up by burning that fuel (and some, because of the poor engine efficiency, reaction losses, etc.) had to be "put in" first. No free lunch here ...

So yes, maybe a nuclear powered aircraft carrier could be producing jet fuel for its planes, but I don't see this supplanting the fossil fuels any time soon. It would be extremely expensive.

Comment Let's see (Score 4, Informative) 143

This topic has been re-hashed here before several times (e.g. here)

Let's see what is actually innovative or different on this printer when compared to the existing ones:

- automatic leveling - ok, but they seem to use a sensor ("motion sensor chip"?!) in the printer head (?!) and not moving bed. I am not really sure how this could actually work ...
- non-heated bed - they claim it is not needed because of autoleveling, but that is BS. You need heated bed for ABS to stick to it, level or not level, otherwise the moving head will lift the print or it will warp. Nothing to do with the bed being level.
- tiny working volume
- autocalibration - again some magical "motion sensor chip" is mentioned, without any explanation what that autocalibration is nor how it works ...
- they are keen on the artistic look of the thing, but I have serious reservations about the rigidity and accuracy of the device - the claimed 15um is only the theoretical resolution of the steppers, not actual resolution of the printer (depends on the nozzle size which is 0.45mm by default!). The ABS body doesn't instill much confidence!
- reduced power consumption is somehow supposed to make things lighter and cheaper (?!) - that argument seems backwards to me ...
- startup, they don't have any other products - who knows when they will actually be able to deliver. The August date is completely unrealistic.
- their team doesn't instill much confidence - 1 electronics guy, 1 CNC guy, 4 CAD people, 2 sw people, but they have 8 artists, 2 PR agencies and 4 lawyers! Not a healthy balance, IMO ...

- incredibly cheap price ($300), but you get what you pay for IMO
- they have exceeded their funding target 10x already ...

Honestly, I don't see how this printer will make 3D printing somehow accessible to the unwashed masses - there are still all those issues of CAD, mechanical design, toy-like device with nebulous claims and nothing to back it up.

Comment Re:What kind of code that do that? (Score 1) 196

It rather shows that Microsoft *still* does not review security-sensitive code properly. How this could have passed any code review is beyond me.

Either they are so incredibly sloppy and incompetent (do you really want to entrust them your credit card then?!) or this was intentional. I am not sure which one is actually worse ...

Comment Re:Problem with Kickstarter (Score 5, Informative) 535

I am one of the original Oculus Kickstarter backers. I have received my Rift development kit without any problem, so I think you are grossly unfair to Oculus as far as the Kickstarter campaign is concerned. The perks were the development kits, not company shares, so there is no reason why I should be getting a cut of those 2 billions.

Also, honestly, do you really believe the company is operating on the Kickstarter money? You would be naive - there are several large investors there, the Kickstarter money went mainly into the original development kit.

However, I do wonder what the heck is going to happen now. They better tread really carefully or they could alienate many of their customers and developers in no time if they try to aggressively push Facebook everywhere (like the payment system - seriously, if one of the stated reasons for getting acquired was to get access to the Facebook's payment system, that's nuts).

Comment Re:3D printers cannot be consumer hardware (Score 1) 251

I think you don't realize that a 3D printer is just that - a 3 axis CNC machine. Replace the extruder head with a spindle and you have a 3 axis CNC router (assuming your average printer has a frame rigid enough for the forces required, which it likely doesn't). There have been even some attempts to make a universal machine where you could choose to either mill/route or print depending on which tool head is installed. A CNC router can be trivially converted into a printer by simply installing the extruder head and/or heated bed. The machines even use exactly the same software, same protocols, are driven in the same way.

The only difference is that a mill/router removes material and a printer adds it and that routers/mills have to be better constructed (more rigid) because there are much higher lateral forces - a typical hobbyist 3D printer is a complete joke in this regard.

"Anyway, I think we're arguing at corossed purposes here. It is frankly indisputable that 3D printers are easier to use than CNC machine tools (a claim opposite would make me doubt you've used either, frankly)."

If you can operate a 3D printer, you could pretty much operate a similarly sized CNC mill/router, perhaps with a bit of basic safety training, because of the high-speed rotating bits that a typical printer doesn't have. The software, the design process, most of the maintenance, etc. is pretty much identical. It is not as if the 3D printing people have suddenly reinvented the machining world from scratch.

Slashdot Top Deals

It's a naive, domestic operating system without any breeding, but I think you'll be amused by its presumption.

Working...