Forgot your password?
typodupeerror
Security

DARPA Open Source Security Helped FreeBSD, Junos, Mac OS X, iOS 22

An anonymous reader writes "In a February 2013 ACM Queue / Communications of the ACM article, A decade of OS access-control extensibility, Robert Watson at the University of Cambridge credits 2000s-era DARPA security research, distributed via FreeBSD, for the success of sandboxing in desktop, mobile, and embedded systems such as Mac OS X, iOS, and Juniper's Junos router OS. His blog post about the article argues that OS security extensibility is just as important as more traditional file system (VFS) and device driver extensibility features in kernels — especially in embedded environments where UNIX multi-user security makes little sense, and where tradeoffs between performance, power use, functionality, and security are very different. This seems to fly in the face of NSA's recent argument argument that one-size-fits-all SELinux-style Type Enforcement is the solution for Android security problems. He also suggests that military and academic security researchers overlooked the importance of app-store style security models, in which signed application identity is just as important as 'end users' in access control."
Networking

Remote Linksys 0-Day Root Exploit Uncovered 133

Orome1 writes "DefenseCode researchers have uncovered a remote root access vulnerability in the default installation of Linksys routers. They contacted Cisco and shared a detailed vulnerability description along with the PoC exploit for the vulnerability. Cisco claimed that the vulnerability was already fixed in the latest firmware release, which turned out to be incorrect. The latest Linksys firmware (4.30.14) and all previous versions are still vulnerable."
Security

Submission + - Firesheep author reflects on wild week (networkworld.com)

alphadogg writes: Firesheep, the Mozilla Firefox add-on released about a week ago that lets you spot users on open networks visiting unsecured websites, has given creator Eric Butler more than his 15 minutes of fame.

More than 542,000 downloads later, Firesheep has thrown Butler into the middle of heated discussions regarding everything from the ethics of releasing the code to the legality of using it to the need for website vendors to clean up their security acts.

Butler, who describes himself as a freelance Web application and software developer, reflects on the past week's happenings in a new blog post http://codebutler.com/firesheep-a-week-later-ethics-and-legality that features lots of bold wording for emphasis and reads in part:

"I've received hundreds of messages from people who are extremely happy that the issue of website security is receiving attention. Some, however, have questioned if Firesheep is legal to use. I'd like to be clear about this: It is nobody's business telling you what software you can or cannot run on your own computer. Like any tool, Firesheep can be used for many things. In addition to raising awareness, it has already proven very useful for people who want to test their own security as well as the security of their (consenting) friends. A much more appropriate question is: ‘Is it legal to access someone else's accounts without their permission'."

Television

US Switch To DTV Countdown Begins 293

s31523 writes "In February lawmakers postponed the switch from analog to digital TV. Now, the new June 12th deadline is upon us with no sign of another delay. CNET is reporting that the President himself has stated, '... I want to be clear: there will not be another delay.' So it looks like it is going to happen, for real this time. Even with the delay, there are still estimated to be millions of unprepared viewers. Local stations may participate in the voluntary 'Analog nightlight' services in which TV stations agree to keep an analog signal turned on in addition to their digital signals to provide information about the DTV transition and to notify unprepared TV viewers of emergencies, such as hurricanes."
Google

Google Releases Chrome V2.0 381

RadiusK writes "Google has released the second major version of the Chrome browser. This version features more speed improvements thanks to a newer version of V8 JavaScript engine and WebKit. JavaScript-heavy web pages will now run about 30% faster. Other new features include form autofill, fullscreen mode, and improved New Tab page. If you're already using Google Chrome, you'll be automatically updated with these new features soon. If you haven't downloaded Google Chrome, you can get the latest version at google.com/chrome." A version for Linux or OS X would be nice.
Portables

Lenovo On the Future of the Netbook 400

thefickler touts an interview in tech.blorge with Lenovo's Worldwide Competitive Analyst, Matt Kohut, who spoke about his vision of the future of netbooks, which involves Windows 7, bigger screens, built-in 3G, touch integration, and lower prices. Linux fans will be disappointed to hear that Kohut thinks Windows 7 will dominate future generations of netbooks because it offers a better, more familiar solution, with the benefits of touch. Quoting Kohut: "The other challenge has been, in order to keep the price points down, a lot of people thought that Linux would be the savior of all of these netbooks. You know, there were a lot of netbooks loaded with Linux, which saves $50 or $100 or whatever it happens to be, based on Microsoft's pricing and, again, from an industry standpoint, there were a lot of returns because people didn't know what to do with it. Linux, even if you've got a great distribution and you can argue which one is better or not, still requires a lot more hands-on than somebody who is using Windows. So, we've seen overwhelmingly people wanting to stay with Windows because it just makes more sense: you just take it out of the box and it's ready to go."
Windows

Windows 7 To Include "Windows XP Mode" 364

Z80xxc! writes "Paul Thurrott's WinSuperSite reports that Windows 7 will include a built-in virtual machine with a fully licensed copy of Windows XP Professional SP3. The VM runs in a modified version of Virtual PC, and applications running in the VM can interact directly with the host operating system as if they were running on the Windows 7 installation itself. While details are scarce for now, it looks as if this feature will only be available as a (free) addon for Professional, Enterprise and Ultimate editions of Windows 7. Also, a processor supporting hardware virtualization will be required, indicating that this is perhaps aimed more at power users and corporate users, rather than consumers. Microsoft confirmed the feature last night."
The Internet

Yahoo Pulls the Plug On GeoCities 427

Mike writes "It's official: Yahoo is pulling the plug, and GeoCities is dead. GeoCities had suffered a long and drawn-out battle with its health over the past decade. An antiquated service model and outdated technology are widely blamed for the struggle. An official cause of death, however, has yet to be determined. Awful, eye-punishing graphics, lack of relevancy, and 'lowest-common-denominator design' are believed to have contributed to its demise. GeoCities was 15 years old." There is doubtless a lot of funny and informative stuff on there that's worth saving (not just Jesux, which pudge has now migrated). If some of it belongs to you, perhaps you should move it sometime in the next few months. Update: 04/24 18:10 GMT by T : And if you know some GeoCities page owners who aren't especially computer savvy, you could point out to them how easy it is to slurp down their pages for re-hosting elsewhere.
Image

South Park Creators Given Signed Photo of Saddam Hussein 1297

Matt Stone and Trey Parker, the creators of South Park, were given a very special gift by US marines: a signed photo of Saddam Hussein. During his captivity, the marines forced Saddam to repeatedly watch the movie South Park: Bigger, Longer And Uncut, which shows him as the boyfriend of Satan. Stone said, "We're very proud of our signed Saddam picture and what it means. It's one of our biggest highlights."
Privacy

New CyberSecurity Bill Raises Privacy Questions 319

Nicolas Dawson points out coverage in Mother Jones of the early stages of a new cybersecurity bill that conveys sweeping powers on the President. Quoting: "The Cybersecurity Act of 2009 (PDF) gives the president the ability to 'declare a cybersecurity emergency' and shut down or limit Internet traffic in any 'critical' information network 'in the interest of national security.' The bill does not define a critical information network or a cybersecurity emergency. That definition would be left to the president. The bill ... also grants the Secretary of Commerce 'access to all relevant data concerning [critical] networks without regard to any provision of law, regulation, rule, or policy restricting such access.' This means he or she can monitor or access any data on private or public networks without regard to privacy laws."

Look Out, Firefox 3 — IE8 Is Back On Top For Now 662

CWmike writes "Internet Explorer 8 has shipped in its final version and is ready to take on its rivals. Preston Gralla reviewed it and says the latest version of Microsoft's browser leapfrogs its closest competition, Firefox 3, for basic browsing and productivity features — it has better tab handling, a niftier search bar, a more useful address bar, and new tools that deliver information directly from other Web pages and services. IE8 has also been tweaked for security and includes a so-called 'porn mode,' new anti-malware protection, and better ways to protect your privacy. The most noticeable new features? Accelerators and Web Slices. Think of an Accelerator as a mini-mashup that delivers information from another Web site directly to your current browser page. Web Slices deliver changing information from a Web page you're not actively visiting directly to IE8. There's one big problem for many, though. No add-ins, and there doesn't appear to be such an ecosystem on the horizon. So if you're a fan of add-ins and customizing the browser itself, writes Gralla, Firefox is superior. But for the actual browsing experience, IE8 has the upper hand — for now."

Slashdot Top Deals

"Falling in love makes smoking pot all day look like the ultimate in restraint." -- Dave Sim, author of Cerebrus.

Working...