Slashdot is powered by your submissions, so send in your scoop

 



Forgot your password?
typodupeerror
×

Comment Re:Fail: crackable in just two days w desktop PC (Score 1) 154

I think you may have misinterpreted how the device works.

Certainly with the FIPS device I use, there are 6 factory programmed 256 bit encryption keys stored in the device. All the pin code does is unlock the factory code that is currently in use in the encryption hardware. The encryption keys are not derived in any way from the pin code.

If you get the pin wrong 10 times then one of the encryption keys is erased and you move onto the next one. Once 6 have been erased, the device is permanently useless. This all happens well before any attempt to access the data via sata or any other means.
Android

Submission + - Android phone 'wipeout' security flaw exposed (bbc.co.uk)

carvell writes: A weakness that can cause all the data stored on Android smartphone handsets to be erased has been found.

Websites tricked users into activating malicious code by clicking on-screen phone numbers, Ravi Borgaonkar, from the Technical University Berlin, said.

No Android could tell the difference between actual phone numbers and USSD codes recognised by handsets as instructions to re-set or wipe its memory card, he wrote in a blog post.

Android maker Google has issued a fix.

Mr Borgaonkar is urging Android phone owners to ensure they have the latest updates.

Comment Re:perhaps they want to examine packet logs? (Score 1) 107

Why do people think this is anything other than a publicity stunt to generate internet-chatter and pimp their name about a bit?

The details of the challenge are almost certainly irrelevant - anyone can apply for GCHQ jobs directly with them, without having to complete a challenge.

The more their name is banded around forums and sites like slashdot the better, as they'll get more people applying for their jobs, which can only be good for them.

Comment Linux build is available (Score 3, Informative) 229

A linux build is available here. It's an firefox addon file (xpi). I have it up and running on Ubuntu fine. You'll need libpcap installed obviously.

You need to make sure you run firesheep-backend --fix-permissions as root manually before it'll work. You'll find this in Firefox's plugins directory.

All info taken from here.

Submission + - Man jailed over computer password refusal (bbc.co.uk) 1

carvell writes: A teenager has been jailed for 16 weeks after he refused to give police the password to his computer.

Oliver Drage, 19, of Liverpool, was arrested in May 2009 by police tackling child sexual exploitation.

Police seized his computer but could not access material on it as it had a 50-character encryption password.

Image

Thieves Use Vacuum To Siphon Cash From Safes Screenshot-sm 173

Tootech writes "A gang of thieves armed with a powerful vacuum cleaner that sucks cash from supermarket safes has struck for the fifteenth time in France. The burglars broke into their latest store near Paris and drilled a hole in the pneumatic tube that siphons money from the checkout to the strong-room. They then sucked rolls of cash totaling £60,000 from the safe without even having to break its lock. Police said the gang — dubbed the Vacuum Burglars — always raid Monoprix supermarkets and have hit 15 of the stores branches around Paris in the past four years. A spokesman added: 'They spotted a weakness in the company's security system and have been exploiting it ever since.'"

Comment Re:Quaint system... (Score 1) 334

They don't check anything. I'm constantly requesting copies of birth certificates (genealogy) and I've never been asked anything. Just find the person whose certificate you're after, look them up in the BMD indexes and bingo bango, one officially approved birth certificate arrives in the post a week or so later.

Slashdot Top Deals

Top Ten Things Overheard At The ANSI C Draft Committee Meetings: (5) All right, who's the wiseguy who stuck this trigraph stuff in here?

Working...