Want to read Slashdot from your mobile device? Point it at m.slashdot.org and keep reading!

 



Forgot your password?
typodupeerror
×
Security

MIT Reveals "Hack-Proof" RFID Chip (thestack.com) 53

JustAnotherOldGuy writes: A group of researchers at MIT and Texas Instruments claim that they have developed a new radio frequency identification chip that may be impossible to hack. Traditional RFID chips are vulnerable to side-channel attacks, whereby a hacker can extract a cryptographic key from the chip. The new RFID chip runs a random-number generator that creates a new secret key after each transaction. The key can then be verified with a server to ensure that it is correct. The group at MIT also incorporated protection against a power-glitch attack, an attack that would normally leave a chip vulnerable to an interruption of the power source that would in turn halt the creation of a new secret key. Texas Instruments CTO Ahmad Bahai stated, "We believe this research is an important step toward the goal of a robust, lo-cost, low-power authentication protocol for the industrial internet." The question is, how long will it be before this "hack proof" chip is hacked?
Bug

IRS Computer Problems Shut Down Tax Return E-file System (foxnews.com) 176

Mr.Intel writes: The IRS stopped accepting electronically filed tax returns Wednesday because of problems with some of its computer systems. The outage could affect refunds, but the agency said it doesn't anticipate "major disruptions." A "hardware failure" forced the shutdown of several tax processing systems, including the e-file system, the IRS said in a statement. The IRS.gov website remains available, but "where's my refund" and other services are not working. Some systems will be out of service at least until Thursday, the agency said. "The IRS is currently in the process of making repairs and working to restore normal operations as soon as possible," the IRS said.
Data Storage

Storing Very Large Files On Amazon's Unlimited Cloud Photo Storage 229

AmiMoJo writes: Last year Amazon started offering unlimited cloud storage for photos to customers who subscribed to its "Prime" service. Japanese user YDKK has developed a tool to store arbitrary data inside a .bmp file, which can then be uploaded to Amazon's service. A 1.44GB test image containing an executable file uploaded at over 250Mb/sec, far faster than typical cloud storage services that are rate limited and don't allow extremely large files.

Submission + - Patent troll VirnetX awarded $626M in damages from Apple (arstechnica.com)

Tackhead writes: Having won a $200M judgement against Microsoft in 2010, lost a $258M appeal against Cisco in 2013, and having beaten Apple for $368M in 2012, only to see the verdict overturned in 2014, patent troll VirnetX is back in the news, having been awarded $626M in damages arising from the 2012 Facetime patent infringement case against Apple.
Cloud

New Hack Shrinks Docker Containers (www.iron.io) 131

destinyland writes: Promising "uber tiny Docker images for all the things," Iron.io has released a new library of base images for every major language optimized to be as small as possible by using only the required OS libraries and language dependencies. "By streamlining the cruft that is attached to the node images and installing only the essentials, they reduced the image from 644 MB to 29MB,"explains one technology reporter, noting this makes it quicker to download and distribute the image, and also more secure. "Less code/less programs in the container means less attack surface..." writes Travis Reeder, the co-founder of Iron.io, in a post on the company's blog. "Most people who start using Docker will use Docker's official repositories for their language of choice, but unfortunately if you use them, you'll end up with images the size of the Empire State Building..."
Government

MIT Inches Closer To ARC Reactor Despite Losing Federal Funding (computerworld.com) 182

Lucas123 writes: Experimenting with a fusion device over the past 20 years has edged MIT researchers to their final goal, creating a small and relatively inexpensive ARC reactor, three of which would produce enough energy to power a city the size of Boston. The lessons already learned from MIT's even current Alcator C-Mod fusion device — with a plasma radius of just 0.68 meters — have enabled researchers to publish a paper on a prototype ARC that would be the world's smallest fusion reactor but with the greatest magnetic force and energy output for its size. The ARC would require 50MW to run while putting out about 200MW of electricity to the grid. Key to MIT's ARC reactor would be the use of a "high-temperature" rare-earth barium copper oxide (REBCO) superconducting tape for its magnetic coils, which only need to be cooled to 100 Kelvin, which enables the use of abundant liquid nitrogen as a cooling agent. Other fusion reactors' superconducting coils must be cooled to 4 degrees Kelvin. While there remain hurdles to overcome, such as sustaining the fusion reaction long enough to achieve a net power return, building the ARC would only take 4 to 5 years and cost about $5 billion, compared to the International Thermonuclear Experimental Reactor (ITER), the world's largest tokamak fusion reactor due to go online and begin producing energy in 2027.
Communications

Receiving Real-Time Imagery From Russia's Meteor-M N2 Satellite 26

An anonymous reader writes: The Meteor-M N2 is a low orbit Russian weather satellite which broadcasts live weather satellite images, similar to the APT images produced by the NOAA satellites. But Meteor digital images are however much better as they are transmitted as a digital signal with an image resolution 12x greater than the aging analog NOAA APT signals. Radio enthusiasts are receiving images with hacked cheap digital TV dongles. There is even the AMIGOS project which stands for Amateur Meteor Images Global Observation System: users around the world can contribute Meteor images through the internet to create worldwide real-time coverage.
Businesses

Elon Musk Cancels Stewart Alsop's Tesla Order Over Complaints About Launch Event 339

New submitter umafuckit writes: Blogger Stewart Alsop wrote an open letter to Elon Musk following a supposedly badly run launch event for the Model X. Alsop complained that the event started almost 2 hours late and was unable to test drive the car (for which has put down a deposit). In response, Musk cancelled Alsop's pre-order saying "Must be a slow news day if denying service to a super rude customer gets this much attention." Alsop, who is known not just for his prolific blogging but for his role as a founding partner at VC firm Alsop Louie Partners, compares his treatment by Tesla to that of BMW, about which he's also said some unflattering things as a customer.
Microsoft

Microsoft To Acquire SwiftKey Predictive Keyboard Technology Company For $250M (hothardware.com) 118

MojoKid writes: SwiftKey has been one of the more popular predictive keyboard offerings in the mobile space since it was first released in beta form on the Android market back in 2010. What made SwiftKey so appealing was its intelligent predictive texting technology. SwiftKey isn't a simple keyboard replacement. Rather, the software uses a combination of artificial intelligence technologies that give it the ability to learn usage patterns and predict the next word the user most likely intends to type. SwiftKey refines its predictions, learning over time by analyzing data from SMS, Facebook, and Twitter messages, then offering predictions based on the text being entered at the time. It is estimated that SwiftKey is installed on upwards of 500 million mobile devices. According to reports, Microsoft is apparently buying the UK-based company for a cool $250 Million. What Microsoft intends to do with SwiftKey is not clear just yet, but the company has been purchasing mobile apps at a good clip as of late.

Submission + - Docker 1.10 Brings Linux SECCOMP Security to Containers (eweek.com)

darthcamaro writes: Starting this week, there is a new tool in the toolbox to secure Docker containers. In addition to SELinux (or AppArmor) and Namespaces — Docker 1.10 will now include a default SECCOMP profile. So what's the difference between SECCOMP and SELinux?

SELinux is the list of people you can talk to, while seccomp is the list of what words you can say, McCarty said. As an example, if a person could communicate with another person using only three or five words, it would very much limit what could be expressed and prevent most types of illicit activities, and applies in much the same way to Linux containers, he added.


Technology

Ask Slashdot: How Can We Improve Slashdot? 1839

Hi all. Most of you are already aware that Slashdot was sold by DHI Group last week, and I very much enjoyed answering questions and reading feedback in the comments of that announcement story. There's no doubt that the Slashdot community is one of the most thoughtful, intelligent, and prolific communities on the web.

I wanted to use this opportunity to get a discussion going on how we can improve Slashdot moving forward. I am not talking about a full re-design that will detract from the original spirit of Slashdot, but rather: user experience, bug fixes, and feature improvements that are requested from actual /. users. We appreciated many of your suggestions in the story announcing the sale, and I have taken note of those suggestions. This story will serve as a more master list for feature requests and improvement suggestions.

We welcome any and all suggestions. Some ideas mentioned in the sale story were, in no particular order: Unicode support, direct messaging, increased cap on comment scores, put more weight on firehose voting to determine which stories make the front page, reduced time required between comments, and many more. We'd love a chance to discuss these suggestions and feature improvements and pros and cons here before we bring them back to our team for implementation.
Games

Video Game Cheaters Outed By Logic Bombs 224

Lirodon writes: A Reddit user decided to tackle the issue of cheaters within Valve's multiplayer shooter Counter Strike: Global Offensive in their own unique way: by luring them towards fake "multihacks" that promised a motherlode of cheating tools, but in reality, were actually traps designed to cause the users who installed them to eventually receive bans. The first two were designed as time bombs, which activated functions designed to trigger bans after a specific time of day. The third, which was downloaded over 3,500 times, caused instantaneous bans.
Networking

Japanese Researchers Achieve Record 56Gbps Wireless Transmission 33

Mickeycaskill writes: Fujitsu and the Tokyo Institute of Technology have achieved a wireless transmission of 56Gbps over a 10cm distance using millimeter-wave (mmWave) frequencies located between 30-300GHz. While cellular capacity is improved in some areas through the addition of new mobile masts and small cells, the fibre networks used to link these sites to the wider network is either absent or not feasible to deploy in urban locations or on difficult terrain. This makes the wireless capacity of mobile masts even more important. To achieve the speed, researchers developed custom chips and interface technology to boost capacity of wireless signals without significant data loss.

It is claimed that by pairing the technology developed with a high-output amplifier, the same effect can be achieved outdoors and could be commercialised for mobile operators by 2020.
The Internet

How the Raspberry Pi Can Automatically Tweet Complaints About Your Slow Internet (ibtimes.co.uk) 154

An anonymous reader writes: Contacting your internet provider to complain about slow browsing speeds is a tiresome chore which none of us enjoy, but one man has found a solution. He has configured a Raspberry Pi computer to automatically tweet a complaint to Comcast when his internet falls below 50Mbps, well below the 150Mbps he pays for. Wouldn't it be nice if ISPs wrote a rebate check each month to reflect the percentage of their promised throughput that was actually available?
Security

Cisco Patches Authentication, Denial-of-Service, NTP Flaws In Many Products (csoonline.com) 33

itwbennett writes: Cisco Systems has released a new batch of security patches for flaws affecting a wide range of products, including for a critical vulnerability in its RV220W wireless network security firewalls. The RV220W vulnerability stems from insufficient input validation of HTTP requests sent to the firewall's Web-based management interface. This could allow remote unauthenticated attackers to send HTTP requests with SQL code in their headers that would bypass the authentication on the targeted devices and give attackers administrative privileges.

Slashdot Top Deals

Air pollution is really making us pay through the nose.

Working...