Press "Enter" to skip to content

Posts tagged as “security”

Google Beats Troll, Ellison’s Oracle ‘Unbreakable’ & More…

FOSS Week in Review

NSA involved in industrial espionage

Another big non-surprise this week in the continuing saga of the NSA. It appears that our beloved spy agency has been using their secret powers for the purpose of uncovering industrial secrets from foreign companies. So much for the separation of business and state. Reuters reported that in a television interview with a German TV network, Edward Snowden said the agency doesn’t confine its intelligence gathering to items of national security.

“‘If there’s information at Siemens that’s beneficial to U.S. national interests – even if it doesn’t have anything to do with national security – then they’ll take that information nevertheless,’ Snowden said…”

Even the Republicans are jumping on the stop-the-NSA bandwagon, which is rather surprising.

Chrome Eavesdropping, Balkanized Internet & More…

FOSS Week in Review

Sixteen-year-old wrote the code for Target breach

TargetMiamiThe press calls him a “nearly seventeen-year-old” and he’s reported to be one of the people behind the malware used to compromise credit card data at Target and other locations. By our way of counting, “nearly seventeen” means he is sixteen or, like the show tune says, “sixteen going on seventeen.” He lives in Russia and is said to be the author of the BlackPOS malware that was used against Target and might have been used against Neiman Marcus.

This info comes from Los Angeles based cyber-intelligence firm IntelCrawler, which says it’s also traced six additional breaches to BlackPOS. As noted on MarketWatch, despite authoring the malware, the kid is just a small fry in this affair.

Blackberry Trolls, Coke in Patent Suit & More…

FOSS Week in Review

India drops deal with Google over spying fears

Since the Snowden leaks revealed that Microsoft has allegedly built back doors into Windows for the NSA, we’ve been saying that the spy agency’s actions are going to hurt the U.S. tech industry’s business abroad. Well, it’s started to happen. On Thursday, Reuters reported that India has decided to drop out of a planned partnership with Google designed to help voters access information.

“…the plan was opposed by the Indian Infosec Consortium, a government and private sector-backed alliance of cyber security experts, who feared Google would collaborate with “American agencies” for espionage purposes.”

cokeadThere’s even been more digital security news from the EU, where there’s been a scramble to address privacy and security issues since the NSA scandal began. On January 3, phoneArena.com reported that European phone makers have been coming out with pricey phones designed for the security conscious.

Mark our words. This is only the beginning.

2013 — That Was the Year That Was

Now that the celebrating is out of the way, I thought it might be time to take a look at some of the stories we covered on FOSS Force this year.

1. The NSA. The biggest story to come down the wire this year undoubtedly had to do with Edward Snowden’s revelations about the National Security Agency’s bag of dirty tricks. Even those of us who have long understood that the Internet isn’t necessarily a place to expect privacy were surprised at how deeply the NSA has managed to reach into the Internet. Odds are, if you’ve been using social networks, everything you’ve posted is now on file with the NSA. What’s worse, every email you’ve sent probably has a copy resting on a NSA server somewhere.

Christine Hall

Christine Hall has been a journalist since 1971. In 2001, she began writing a weekly consumer computer column and started covering Linux and FOSS in 2002 after making the switch to GNU/Linux. Follow her on Twitter: @BrideOfLinux

Target Breach Illustrates Internet Weakness

In October, 2000, when Microsoft was presumably working on what would become XP, they were hacked. Somebody broke into their systems and managed to at least look at source code for Windows and Office. The folks in Redmond dutifully called in the FBI, examined their code and found it hadn’t been compromised. Or so they said.

“It is clear that hackers did see some of our source code,” Ballmer announced to a group of reporters and programmers at a seminar he was attending in Stockholm. “I can assure you that we know that there has been no compromise of the integrity of the source code, that it has not been modified or tampered with in any way.”

Target POS
The point of sale locations at Target stores — ground zero for the latest data breach.
At the time, this was disturbing, more so than if it were it to happen today. It was also an eye opener.

Christine Hall

Christine Hall has been a journalist since 1971. In 2001, she began writing a weekly consumer computer column and started covering Linux and FOSS in 2002 after making the switch to GNU/Linux. Follow her on Twitter: @BrideOfLinux

New Temp Patent Head, Amnesty for Snowden & More…

FOSS Week in Review

Credit card breach at Target affects over 40 million

Merry Christmas. Your bank account has been drained.

This week’s holiday cheer was marred for millions as they learned that their banking information might be in the hands of hackers.

Target has announced that over 40 million customer credit card transactions have been hijacked since Black Friday. The data was stolen from transactions at the retailer’s brick and mortar stores. Online transactions are evidently not affected. All information contained in a credit card’s magnetic stripe has been compromised, enough information to make counterfeit cards.

The story was originally made public on Wednesday by security expert Brian Krebs on his site KrebsonSecurity. This afternoon, Krebs wrote in an update that information pilfered from Target was making its way to the black market.

Linux Worm, Bad Patent Good & More…

FOSS Week in Review

Good news & bad on the patent front

This week we received some good news and bad on the continuing patent wars.

First the bad news.

Down in the northeast Texas town of Marshall, an eight person jury has found that online retailer Newegg infringed on a patent held by TQP Development because they mixed the use of SSL and RC4 on their websites. The jury awarded $2.3 million, less than half of the $5.1 million that TQP’s damage expert had thought due.

Even though Newegg had a strong case, it’s not that much of a surprise that they lost, not in Marshall, where juries are infamous for siding with the plaintiffs on patent cases. Often these judgments are overturned on appeal. Make no mistake about it, Newegg’s attorney Lee Cheng plans to appeal. He made that very plain to Joe Mullin who covered the trial for Ars Technica:

Chrome Clamps Down, Bitcoin Vulnerability & More…

FOSS Week in Review

Swiss cloud with, presumably, no holes

Back when the Edward Snowden brouhaha first began, we said that this was going to have serious repercussions on the tech sector here in the United States, especially after it became evident that Microsoft was actively working with the spooks by allegedly designing back doors into their operating system and keeping federal intelligence agents informed about unpatched security holes that could be used against foreign governments and “terrorist,” which now days seems to be everyone who doesn’t work for the NSA, FBI or CIA.

Swisscom logoBrazil is already spending big bucks in an effort to make sure that no Internet cable entering their country goes anywhere near the US of A and is working to pass laws to make sure all Brazilian businesses use only servers located in-country. Similar efforts are underway in Europe, most notably in France and Germany.

Now the frugal Swiss are jumping on board, and they rightfully intend to profit from our stupidity by taking advantage of their strong privacy laws.

WordPress Becomes Big Brother & More…

FOSS Week in Review

Is Netflix coming soon to a Linux near you?

Saurav Modak at Muktware was observant enough to note last week that Netflix is now offering-up programming with a choice heretofore unavailable. For the time being they’re still pretty much married to Microsoft’s dead or dying Silverlight, but they’ve taken HTML5 on as a lover. This gives users of the popular movie outlet a choice that, at the very least, should make things easier for Linux users who insist on using the Netflix service:

“Although hackers have already made a workaround to stream Netflix videos in Linux machines, performance is generally low and video playback is not hassle free. Some workarounds include running the entire browser in Wine, or running a Silverlight plugin in Wine and make it compatible with the browser. But all of them come at a cost of performance. Switching to HTML5 from Silverlight will greatly reduce all these hassles, as all you will need is a latest standard compatible browser to stream movies and TV shows. This will also allow support for mobile devices and tablets which are adopting more HTML5 standards day by day.”

PHP Attacked, the Shuttleworth Tea Party & More…

FOSS Week in Review

NSA: Locking the barn door after the horse is stolen

On Monday, Reuters reported in an exclusive story that the NSA had failed to install some super duper software meant specifically to protect the agency from inside threats at the site in Hawaii where Eric Snowden downloaded thousands of classified documents. In other words, after spending who knows how much taxpayer money developing internal security software, made by Raytheon by the way, and getting it installed and tweaked at NSA installations everywhere, little Eric Snowden was shuffled off to one of the only, if not the only, locations where internal security wasn’t in place. In hindsight, this made the NSA akin to two lengths of case hardened steel chain being bound together by a link made from a paper clip.

Windows Becomes Freeware, Adobe Cracked & More…

FOSS Week in Review

Adobe hacked

We’ve known for years that Adobe doesn’t seem to have a knack for keeping their products secure. New vulnerabilities are found almost daily in Reader and Flash, so much so that Windows users grow used to the constant updates required of them by the fine folks at Adobe. Now it appears as if the San Jose based company can’t keep their servers secure either.

Last Friday, The Australian reported that black hats had managed to steal source code and sensitive customer information:

Latest Articles