Press "Enter" to skip to content

Posts published in “Security”

New Temp Patent Head, Amnesty for Snowden & More…

FOSS Week in Review

Credit card breach at Target affects over 40 million

Merry Christmas. Your bank account has been drained.

This week’s holiday cheer was marred for millions as they learned that their banking information might be in the hands of hackers.

Target has announced that over 40 million customer credit card transactions have been hijacked since Black Friday. The data was stolen from transactions at the retailer’s brick and mortar stores. Online transactions are evidently not affected. All information contained in a credit card’s magnetic stripe has been compromised, enough information to make counterfeit cards.

The story was originally made public on Wednesday by security expert Brian Krebs on his site KrebsonSecurity. This afternoon, Krebs wrote in an update that information pilfered from Target was making its way to the black market.

Android On Nokia, SCOTUS On Patents & More…

FOSS Week in Review

FreeBSD rethinks encryption after Snowden leaks

Only three months after the Snowden leaks on NSA snooping began, we learn from Ars Technica that the developers at FreeBSD have decided to rethink the way they access random numbers to generate cryptographic keys. Starting with version 10.0, users of the operating system will no longer be relying solely on random numbers generated by Intel and Via Technologies processors. This comes as a response to reports that government spooks can successfully open some encryption schemes.

Linux Worm, Bad Patent Good & More…

FOSS Week in Review

Good news & bad on the patent front

This week we received some good news and bad on the continuing patent wars.

First the bad news.

Down in the northeast Texas town of Marshall, an eight person jury has found that online retailer Newegg infringed on a patent held by TQP Development because they mixed the use of SSL and RC4 on their websites. The jury awarded $2.3 million, less than half of the $5.1 million that TQP’s damage expert had thought due.

Even though Newegg had a strong case, it’s not that much of a surprise that they lost, not in Marshall, where juries are infamous for siding with the plaintiffs on patent cases. Often these judgments are overturned on appeal. Make no mistake about it, Newegg’s attorney Lee Cheng plans to appeal. He made that very plain to Joe Mullin who covered the trial for Ars Technica:

Hacked by the NSA

The Internet has become a neighborhood infested with cockroaches.

On Saturday, the Dutch newspaper NRC reported that the NSA has infected over 50,000 computer networks with malware designed to steal sensitive data. The allegation arises from examination of documents supplied by Edward Snowden and “seen by” NRC reporters.

“The malware can be controlled remotely and be turned on and off at will. The ‘implants’ act as digital ‘sleeper cells’ that can be activated with a single push of a button. According to the Washington Post, the NSA has been carrying out this type of cyber operation since 1998.”

Christine Hall

Christine Hall has been a journalist since 1971. In 2001, she began writing a weekly consumer computer column and started covering Linux and FOSS in 2002 after making the switch to GNU/Linux. Follow her on Twitter: @BrideOfLinux

Google Pays States, Newegg Tackles Troll & More…

FOSS Week in Review

FBI claims U.S. computers breached by Anonymous

In an exclusive story published Saturday by Reuters, the FBI has claimed Anonymous has managed to hack into U.S. government computers and steal sensitive data. What’s more, they believe these intrusions have been going on for at least a year.

“The hackers exploited a flaw in Adobe Systems Inc’s software to launch a rash of electronic break-ins that began last December, then left “back doors” to return to many of the machines as recently as last month, the Federal Bureau of Investigation said in a memo seen by Reuters.

“The memo, distributed on Thursday, described the attacks as ‘a widespread problem that should be addressed.’ It said the breach affected the U.S. Army, Department of Energy, Department of Health and Human Services, and perhaps many more agencies.

“Investigators are still gathering information on the scope of the cyber campaign, which the authorities believe is continuing. The FBI document tells system administrators what to look for to determine if their systems are compromised.”

Chrome Clamps Down, Bitcoin Vulnerability & More…

FOSS Week in Review

Swiss cloud with, presumably, no holes

Back when the Edward Snowden brouhaha first began, we said that this was going to have serious repercussions on the tech sector here in the United States, especially after it became evident that Microsoft was actively working with the spooks by allegedly designing back doors into their operating system and keeping federal intelligence agents informed about unpatched security holes that could be used against foreign governments and “terrorist,” which now days seems to be everyone who doesn’t work for the NSA, FBI or CIA.

Swisscom logoBrazil is already spending big bucks in an effort to make sure that no Internet cable entering their country goes anywhere near the US of A and is working to pass laws to make sure all Brazilian businesses use only servers located in-country. Similar efforts are underway in Europe, most notably in France and Germany.

Now the frugal Swiss are jumping on board, and they rightfully intend to profit from our stupidity by taking advantage of their strong privacy laws.

WordPress Becomes Big Brother & More…

FOSS Week in Review

Is Netflix coming soon to a Linux near you?

Saurav Modak at Muktware was observant enough to note last week that Netflix is now offering-up programming with a choice heretofore unavailable. For the time being they’re still pretty much married to Microsoft’s dead or dying Silverlight, but they’ve taken HTML5 on as a lover. This gives users of the popular movie outlet a choice that, at the very least, should make things easier for Linux users who insist on using the Netflix service:

“Although hackers have already made a workaround to stream Netflix videos in Linux machines, performance is generally low and video playback is not hassle free. Some workarounds include running the entire browser in Wine, or running a Silverlight plugin in Wine and make it compatible with the browser. But all of them come at a cost of performance. Switching to HTML5 from Silverlight will greatly reduce all these hassles, as all you will need is a latest standard compatible browser to stream movies and TV shows. This will also allow support for mobile devices and tablets which are adopting more HTML5 standards day by day.”

PHP Attacked, the Shuttleworth Tea Party & More…

FOSS Week in Review

NSA: Locking the barn door after the horse is stolen

On Monday, Reuters reported in an exclusive story that the NSA had failed to install some super duper software meant specifically to protect the agency from inside threats at the site in Hawaii where Eric Snowden downloaded thousands of classified documents. In other words, after spending who knows how much taxpayer money developing internal security software, made by Raytheon by the way, and getting it installed and tweaked at NSA installations everywhere, little Eric Snowden was shuffled off to one of the only, if not the only, locations where internal security wasn’t in place. In hindsight, this made the NSA akin to two lengths of case hardened steel chain being bound together by a link made from a paper clip.

All Things Open: On Vendor Mistrust, Containerization & Profiting From Open Source

The first ever All Things Open conference in Raleigh, North Carolina is now history–but it’s history that will repeat itself. At the sendoff after the last workshops had finished, Conference Chair Todd Lewis announced that the event had been a bigger success than expected, with something like 800 in attendance, and that the event would definitely be returning to the Old North State’s capital city in 2014.

The three presentations I was able to attend at the afternoon session started with “Open Source Communities in a For Profit World” led by John Mertic, a Solutions Architect for SugarCRM. Although Mr. Mertic is a personable enough person and his presentation was well thought out, his ideas were a bit disturbing to this dyed-in-the-wool open sourcer. I’ll save the whys and wherefores for next week’s in depth look at this workshop. Suffice it to say, right now I’m hoping that when I review his presentation I’ll find I misunderstood some of his ideas.

Christine Hall

Christine Hall has been a journalist since 1971. In 2001, she began writing a weekly consumer computer column and started covering Linux and FOSS in 2002 after making the switch to GNU/Linux. Follow her on Twitter: @BrideOfLinux

Windows Becomes Freeware, Adobe Cracked & More…

FOSS Week in Review

Adobe hacked

We’ve known for years that Adobe doesn’t seem to have a knack for keeping their products secure. New vulnerabilities are found almost daily in Reader and Flash, so much so that Windows users grow used to the constant updates required of them by the fine folks at Adobe. Now it appears as if the San Jose based company can’t keep their servers secure either.

Last Friday, The Australian reported that black hats had managed to steal source code and sensitive customer information:

Torvald’s Diplomacy, Elop’s Riches & More…

FOSS Week in Review

Redmond Ups the Ante on Its Buyback Program

No sooner had we told you last Friday of Microsoft’s offer to buy certain “gently used” iPads for up to $200 in credit vouchers, good at your friendly neighborhood Microsoft store, than they went and upped the ante. What they’ve done is something of a reverse interpretation of a line from the old Proctor and Bergman comedy album from the early 70’s, TV or Not TV. To paraphrase, “What was once two hundred is now three hundred fifty.”

Yup. You heard us right. On Friday your old iPad was worth two hundred smackers to the Microsoft folk–which had to be taken in store credit. By Sunday morning, it was three fifty as cash loaded on a Visa card. Talk about inflation. Not only that, Redmond’s buyback offer now extends beyond a limited range of iPads to include many more devices. Now they’ll take Android devices, both phones and tablets, from Samsung, Lenovo and others, as well as iPhones and iPads. We understand they’re even offering to buyback BlackBerrys.

Latest Articles