Follow Slashdot blog updates by subscribing to our blog RSS feed

 



Forgot your password?
typodupeerror
×
Encryption

First Phase of TrueCrypt Audit Turns Up No Backdoors 171

msm1267 (2804139) writes "A initial audit of the popular open source encryption software TrueCrypt turned up fewer than a dozen vulnerabilities, none of which so far point toward a backdoor surreptitiously inserted into the codebase. A report on the first phase of the audit was released today (PDF) by iSEC Partners, which was contracted by the Open Crypto Audit Project (OCAP), a grassroots effort that not only conducted a successful fundraising effort to initiate the audit, but raised important questions about the integrity of the software.

The first phase of the audit focused on the TrueCrypt bootloader and Windows kernel driver; architecture and code reviews were performed, as well as penetration tests including fuzzing interfaces, said Kenneth White, senior security engineer at Social & Scientific Systems. The second phase of the audit will look at whether the various encryption cipher suites, random number generators and critical key algorithms have been implemented correctly."
Medicine

Jenny McCarthy: "I Am Not Anti-Vaccine'" 588

Hugh Pickens DOT Com (2995471) writes "Jenny McCarthy is claiming she has been misunderstood and is not anti-vaccine. In an op-ed in the Chicago Sun-Times, McCarthy tries to ignore everything she's been saying about vaccines for years and wipe the record clean. 'People have the misconception that we want to eliminate vaccines,' McCarthy told Time magazine science editor Jeffrey Kluger in 2009. 'Please understand that we are not an anti-vaccine group. We are demanding safe vaccines. We want to reduce the schedule and reduce the toxins.' But Kluger points out that McCarthy left the last line out of that quotation: 'If you ask a parent of an autistic child if they want the measles or the autism, we will stand in line for the f--king measles.' That missing line rather changes the tone of her position considerably, writes Phil Plait and is a difficult stance to square with someone who is not anti-vaccine. As Kluger points out, her entire premise is false; since vaccines don't cause autism, no one has to make the choice between measles (and other preventable, dangerous diseases) and autism. Something else McCarthy omitted from her interview with Kluger: 'I do believe sadly it's going to take some diseases coming back to realize that we need to change and develop vaccines that are safe,' said McCarthy. 'If the vaccine companies are not listening to us, it's their f*cking fault that the diseases are coming back. They're making a product that's sh*t. If you give us a safe vaccine, we'll use it. It shouldn't be polio versus autism.' Kluger finishes with this: 'Jenny, as outbreaks of measles, mumps and whooping cough continue to appear in the U.S.—most the result of parents refusing to vaccinate their children because of the scare stories passed around by anti-vaxxers like you—it's just too late to play cute with the things you've said.' For many years McCarthy has gone on and on and on and on and on and on about vaccines and autism. 'She can claim all she wants that she's not anti-vax,' concludes Plait, 'but her own words show her to be wrong.'"
Medicine

Racing To Contain Ebola 112

An anonymous reader writes "Ebola, one of the most deadly diseases known to humans, started killing people in Guinea a few months ago. There have been Ebola outbreaks in the past, but they were contained. The latest outbreak has now killed over 100 people across three countries. One of the biggest difficulties in containing an outbreak is knowing where the virus originated and how it spread. That problem is being addressed right now by experts and a host of volunteers using Open Street Map. 'Zoom in and you can see road networks and important linkages between towns and countries, where there were none before. Overlay this with victim data, and it can help explain the rapid spread. Click on the colored blobs and you will see sites of confirmed deaths, suspected cases that have been overturned, sites where Ebola testing labs have been setup or where the emergency relief teams are currently located.'"
The Almighty Buck

Comcast PAC Gave Money To Every Senator Examining Time Warner Cable Merger 133

An anonymous reader writes in with news about money and politics that is sure to shock no one."It's no surprise that Comcast donates money to members of Congress. Political connections come in handy for a company seeking government approval of mergers, like Comcast's 2011 purchase of NBCUniversal and its proposed acquisition of Time Warner Cable (TWC). But just how many politicians have accepted money from Comcast's political arm? In the case of the Senate Judiciary Committee, which held the first congressional hearing on the Comcast/TWC merger yesterday, the answer is all of them."
Businesses

Double Take: Condoleezza Rice As Dropbox's Newest Board Member 313

Condoleezza Rice, Secretary of State under George W. Bush, and defender of Bush-era (and onward) policies about surveillance by wiretapping and other means, has landed at an interesting place: she's just become a part of the small board at Dropbox. TechDirt calls the appointment "tone deaf," and writes "At a time when people around the globe are increasingly worried about American tech firms having too close a connection to the intelligence community, a move like this seems like a huge public relations disaster. While Rice may be perfectly qualified to hold the role and to help Dropbox with the issues it needs help with, it's hard not to believe that there would be others with less baggage who could handle the job just as well." Some people are doing more than looking for an alternative for themselves, too, as a result.
Crime

Stung By File-Encrypting Malware, Researchers Fight Back 85

itwbennett (1594911) writes "When Jose Vildoza's father became the victim of ransomware, he launched his own investigation. Diving into CryptoDefense's code, he found its developers had made a crucial mistake: CryptoDefense used Microsoft's Data Protection API (application programming interface), a tool in the Windows operating system to encrypt a user's data, which stored a copy of the encryption keys on the affected computer. Vildoza and researcher Fabian Wosar of the Austrian security company Emsisoft collaborated on a utility called the Emsisoft Decrypter that could recover the encrypted keys. In mid-March Vildoza had launched a blog chronicling his investigation, purposely not revealing the mistake CryptoDefense's authors had made. But Symantec then published a blog post on March 31 detailing the error."
Books

Online Skim Reading Is Taking Over the Human Brain 224

Hugh Pickens DOT Com (2995471) writes "Michael S. Rosenwald reports in the Washington Post that, according to cognitive neuroscientists, humans seem to be developing digital brains with new circuits for skimming through the torrent of information online at the expense of traditional deep reading circuitry... Maryanne Wolf, one of the world's foremost experts on the study of reading, was startled last year to discover her brain was apparently adapting, too. After a day of scrolling through the Web and hundreds of e-mails, she sat down one evening to read Hermann Hesse's challenging novel The Glass Bead Game. 'I'm not kidding: I couldn't do it,' says Wolf. 'It was torture getting through the first page. I couldn't force myself to slow down so that I wasn't skimming, picking out key words, organizing my eye movements to generate the most information at the highest speed. I was so disgusted with myself.'

The brain was not designed for reading and there are no genes for reading like there are for language or vision. ... Before the Internet, the brain read mostly in linear ways — one page led to the next page, and so on. The Internet is different. With so much information, hyperlinked text, videos alongside words and interactivity everywhere, our brains form shortcuts to deal with it all — scanning, searching for key words, scrolling up and down quickly. This is nonlinear reading, and it has been documented in academic studies. ... Some researchers believe that for many people, this style of reading is beginning to invade our ability to deal with other mediums. 'We're spending so much time touching, pushing, linking, scrolling and jumping through text that when we sit down with a novel, your daily habits of jumping, clicking, linking is just ingrained in you,' says Andrew Dillon."
Power

Qualcomm Announces Next-Gen Snapdragon 808 and 810 SoCs 47

MojoKid (1002251) writes "Qualcomm has announced two fundamentally new chips today with updated CPU cores as well as Qualcomm's new Adreno 400-class GPU. The Snapdragon 808 and the Snapdragon 810 have been unveiled with a host of new architectural enhancements. The Snapdragon 810 will be the highest-end solution, with a quad-core ARM Cortex-A57 paired alongside four low-power Cortex-A53 cores.

The Snapdragon 808 will also use a big.Little design, but the core layouts will be asymmetric — two Cortex-A57's paired with four Cortex-A53's. The Cortex-A57 is, by all accounts, an extremely capable processor — which means a pair of them in a dual-core configuration should be more than capable of driving a high-end smartphone. Both SoC's will use a 20nm radio and a 28nm RF transceiver. That's a major step forward for Qualcomm (most RF today is built on 40nm). RF circuits typically lag behind digital logic by at least one process node. Given that RF currently accounts for some 15% of the total area and 30-40% of the PCB, the benefits of moving to a smaller manufacturing process for the RF circuit are significant."
To clarify, the 810 can use a combination of the Cortex-A57 and Cortex-A53 cores so a single task that needs a lot of power won't cause as large of a power jump. All of the chips are 64-bit ARM too.
Data Storage

Seagate Releases 6TB Hard Drive Sans Helium 147

Lucas123 (935744) writes "Seagate has released what it said is the industry's fastest hard drive with up to a 6TB capacity, matching one released by WD last year. WD's 6TB Ultrastar He6 was hermetically sealed with helium inside, something the company said was critical to reducing friction for additional platters, while also increasing power savings and reliability. Seagate, however, said it doesn't yet need to rely on Helium to achieve the 50% increase in capacity over its last 4TB drive. The company used the same perpendicular magnetic recording technology that it has on previous models, but it was able to increase areal density from 831 bits per square inch to 1,000. The new drive also comes in 2TB, 4TB and 5TB capacities and with either 12Gbps SAS or 6Gbps SATA connectivity. The six-platter, enterprise-class drive is rated to sustain about 550TB of writes per year — 10X that of a typical desktop drive."
Australia

UAV Operator Blames Hacking For Malfunction That Injured Triathlete 178

jaa101 (627731) writes "The owner of a drone which fell and reportedly hit an athlete competing in a triathlon in Western Australia's Mid West has said he believes the device was 'hacked' into." From the article: "Mr Abrams said an initial investigation had indicted that someone nearby "channel hopped" the device, taking control away from the operator. ... Mr Abrams said it was a deliberate act and it would be difficult to determine who was responsible as something as common as a mobile phone could be used to perform a channel hop. The videographer added that there had been a similar incident when the drone was flown earlier in the day."
The Almighty Buck

Facebook and Google's Race To Zero 53

theodp (442580) writes "As Facebook and Google battle to bring the Internet to remote locations, Alicia Levine takes an interesting look at the dual strategy of Zero Rating and Consolidated Use employed by Google's FreeZone and Facebook's 0.facebook.com, websites which offer free access to certain Google and Facebook services via partnerships with mobile operators around the world. By reducing the cost to the user to zero, Levine explains, the tech giants not only get the chance to capture billions of new eyeballs to view ads in emerging markets, they also get the chance to effectively become "The Internet" in those markets. "If I told you that Facebook's strategy was to become the next Prodigy or AOL, you'd take me for crazy," writes Levine. "But, to a certain degree, that's exactly what they're trying to do. In places where zero-rating for Facebook or Google is the key to accessing the Internet, they are the Internet. And people have started to do every normal activity we would do on the Internet through those two portals because it costs them zero. This is consolidated use. If Facebook is my free pass to the Internet, I'm going to try to do every activity possible via Facebook so that it's free." The race to zero presents more than just a business opportunity, adds Levine — it also presents a chance for tech companies to improve lives. And if Google and Facebook fall short on that count, well, at least there's still Wikipedia Zero."
Intel

Intel Releases $99 'MinnowBoard Max,' an Open-Source Single-Board Computer 97

A few months back, we posted a video interview with some of the folks behind the Linux-friendly, x86-based MinnowBoard. TechCrunch reports the release of a more powerful version of the same all-in-one computer, now with a 1.91GHz Atom E3845 processor. According to the linked article, "The board's schematics are also available for download and the Intel graphics chipset has open-source drivers so hackers can have their way with the board. While it doesn’t compete directly with the Raspberry Pi – the Pi is more an educational tool and already has a robust ecosystem – it is a way for DIYers to mess around in x86 architected systems as well as save a bit of cash. The system uses break-out boards called Lures to expand functionality."
United Kingdom

UK Government Pays Microsoft £5.5M For Extended Support of Windows XP 341

whoever57 (658626) writes "The UK Government has signed a contract worth £5.5M (almost $9M) for extended support and security updates for Windows XP for 12 months after April 8. The deal covers XP, Exchange 2003 and Office 2003 for users in central and local government, schools and the National Health Service. The NHS is in need of this deal because it was estimated last September that 85% of the NHS's 800,000 computers were running XP."
Android

Illustrating the Socioeconomic Divide With iOS and Android 161

An anonymous reader writes: "Android has a huge market share advantage over iOS these days, but it hasn't had as much success at following the money. iOS continues to win over many app developers and businesses who want to maximize their earnings. Now, an article at Slate goes over some of the statistics demonstrating this trend. A map of geo-located Tweets show that in Manhattan, a generally affluent area, most of the Tweets come from iPhones. Meanwhile, in nearby Newark, which is a poorer area, most Tweets come from Android devices. In other tests, traffic data shows 87% of visits to e-commerce websites from tablets come from iPads, and the average value of an order from an iPad is $155, compared to $110 from Android tablets. (Android fairs a bit better on phones). Android shows a huge market share advantage in poorer countries, as well. Not all devs and business are just chasing the money, though. Twitter developer Cennydd Bowles said, 'I do hope, given tech's rhetoric about changing the world and disrupting outdated hierarchies, that we don't really think only those with revenue potential are worth our attention. A designer has a duty to be empathetic; to understand and embrace people not like him/herself. A group owning different devices to the design elite is not a valid reason to neglect their needs.'"

Comment Re:Short story: See to what Linus responds (Score 1) 641

Linus made this argument in a different forum yesterday (paraphrasing from memory): "Look, something has to be authoratitive when it comes to parameters. On a linux system, that's the kernel". Which is aribitrary, but not without merit.

No. This is the kernel command line we're talking about, after all. Its original intent is to be used to send options and information to the kernel and, by extension, kernel modules. The fact that user-space programs can read /proc/cmdline and get options passed in from the bootloader (e.g different menu entries) is frankly a hack. The least any user-space programmer should do is make sure their chosen strings don't clash with already-existing parameters. Re-using the "debug" flag is inappropriate, even if it didn't flood dmesg and hang the system.

Slashdot Top Deals

Math is like love -- a simple idea but it can get complicated. -- R. Drabek

Working...