Forgot your password?
typodupeerror

Submission Summary: 0 pending, 35 declined, 4 accepted (39 total, 10.26% accepted)

+ - Will Schneier Help Save Us From The NSA?->

Submitted by al0ha
al0ha (1262684) writes "Schneier briefs members of Congress on the NSA in a closed door meeting. According to Bruce, "Surreal part of setting up this meeting: I suggested that we hold this meeting in a SCIF, because they wanted me to talk about top secret documents that had not been made public. So we had to have the meeting in a regular room."

I am so very happy to hear a rational expert, that is almost uniquely able to explain complex subjects and their potential ramifications to those of us possessing less than brilliant minds in this world, has been briefing Congress on the NSA."

Link to Original Source
Hardware

+ - The Memristor - It may transform computer hardware->

Submitted by al0ha
al0ha (1262684) writes "The first new passive circuit element since the 1830s might transform computer hardware.

In a thriving transistor monoculture where more transistors are created than grains of rice grown world wide; can a new circuit element find a place to take root and grow? That’s the question posed by the memristor, a device first discussed theoretically 40 years ago and finally implemented in hardware in 2008. The name is a contraction of “memory resistor,” which offers a good clue to how it works."

Link to Original Source

+ - Why Is Slashdot Session Management Insecure->

Submitted by al0ha
al0ha (1262684) writes "Why is it that Slashdot session management is insecure? If you force HTTPS during login, then session cookies are set for encrypted sessions only, so for the rest of the site you are not logged in. If you login over insecure HTTP, then the session cookies are set for any connection.

This is totally lame and makes session hijacking via FireSheep simple, as well as credential sniffing on the wire and wireless.

How Geeky can Geeknet be if they can't even handle session management appropriately?

The password change page and login pages should be protected by HTTPS. Then session cookies appropriate for general content, or privileged content (like changing account information) should be set where privileged content always runs over HTTPS."

Link to Original Source
Privacy

+ - Worry About Little Brother->

Submitted by al0ha
al0ha (1262684) writes "To paraphrase the article: "These days, the main enemy of privacy is not Big Brother, but a whole bunch of Little Brothers. I grant you that long experience teaches us that the government itself must be watched. However, if you think that it is the main threat to your privacy these days, I humbly suggest that you think again.""
Link to Original Source

+ - Dissecting the neural circuitry of fear->

Submitted by al0ha
al0ha (1262684) writes "In this week's issue of the journal Nature, a research team led by scientists at the California Institute of Technology (Caltech) has taken an important step toward understanding just how this kickoff occurs by beginning to dissect the neural circuitry of fear. In their paper, these scientists—led by David J. Anderson, the Benzer Professor of Biology at Caltech and a Howard Hughes Medical Institute investigator—describe a microcircuit in the amygdala that controls, or "gates," the outflow of fear from that region of the brain.

Read the Paper if you have No Fear; of real science. :-)"

Link to Original Source
Security

+ - Zeus Trojan 2p0wn 2 Factor Auth->

Submitted by al0ha
al0ha (1262684) writes "The attack begins as it usually does — the Trojan steals the username and password as it is inserted by the user. Then, a rogue form pops up and demands of him to share his mobile phone vendor, model and phone number:

A while back Schneier pointed out the failure of 2 factor auth: http://www.schneier.com/blog/archives/2005/03/the_failure_of.html"

Link to Original Source
Security

+ - Browser Security Courtesy of the American Taxpayer->

Submitted by al0ha
al0ha (1262684) writes "Invincea, a security firm originally funded by the Defense Advanced Research Projects Agency (DARPA) to build a prototype virtualized browser, today rolled out a Windows application that places Internet Explorer (IE) into a virtual environment in order to protect the underlying system from Web-based attacks.

While the product is an interesting idea and may be useful, I totally object to the pricing as an American taxpayer. I have already helped pay for the development of this product; the CEO must be related to Bush/Cheney somehow. What a scam."

Link to Original Source
Security

+ - Active Govt. SSL MITM Spying->

Submitted by al0ha
al0ha (1262684) writes "From the article, "A paper published today by Chris Soghoian and Sid Stamm [pdf] suggests that the threat may be far more practical than previously thought. They found turnkey surveillance products, marketed and sold to law enforcement and intelligence agencies in the US and foreign countries, designed to collect encrypted SSL traffic based on forged 'look-alike' certificates obtained from cooperative certificate authorities."

There is protection via an FF add-on..."

Link to Original Source
Linux

+ - Darl, please go away now like a good boy->

Submitted by al0ha
al0ha (1262684) writes "Today, the jury in the District Court of Utah trial between SCO Group and Novell issued a verdict.

Novell is very pleased with the jury’s decision confirming Novell’s ownership of the Unix copyrights, which SCO had asserted to own in its attack on Linux. Novell remains committed to promoting Linux, including by defending Linux on the intellectual property front.

This decision is good news for Novell, for Linux, and for the open source community.

Well as long as Larry never buys Novell that is!"

Link to Original Source

Man must shape his tools lest they shape him. -- Arthur R. Miller

Working...