Unauthorized Drone Activity Over Paris

February 25th, 2015

Via: BBC:

Drones have appeared over landmarks in central Paris for the second night running and police are no closer to knowing who is operating them.

There were five sightings between 23:00 on Tuesday and 02:00 (01:00 GMT) on Wednesday, French media report.

Up to three drones were seen near the Invalides military museum, Place de la Concorde and two of the old city gates.

Flying drones over Paris at night is illegal and daytime flights require authorisation from the city.

Five drones were seen the previous night in similar areas, including the Eiffel Tower and above the US embassy, close to Place de la Concorde.

However, some of the latest drone flights have been captured on film and will be analysed by a 10-strong team of investigators set up after the first incidents.

The security threat from these drones is minimal.

Related? Secret Service Conducting Drone Exercises in U.S. Capital Region


Komodia’s Founder, “Was Once a Programmer in Israel’s IDF’s Intelligence Core”

February 24th, 2015

It’s for the children.

Via: Forbes:

In a brief email conversation with Barak Weichselbaum, Komodia’s founder who was once a programmer in Israel’s IDF’s Intelligence Core, he said the company was not hiding behind DDoS claims and that the attack was real.

Why is Komodia now getting so much attention anyway? Because its hugely intrusive and poorly protected technology is found in many places on the web, according to Marc Rogers, principal security researcher at content delivery network CloudFlare. The technology can be found in various parental control software, including those made by Qustodio and the Israeli firm’s own “Keep My Family Secure” product, and in web filter products across the world. On Weichselbaum’s LinkedIn page, he says: “My biggest vision is to create a world where children can surf the internet safely, and I’m working to see this vision realized.”

Worryingly, it’s very easy to extract and use the encryption key run by Komodia, largely because the password to access all different versions of the certificate is “komodia”. That means malicious hackers can craft their own SSL certificates, which are supposed to guarantee trust, with the Komodia key. They can then intercept people’s internet connections, create fake versions of certain websites and steal their data, as long as targets’ computers trust the Komodia certificates.

“This means that those dodgy certificates aren’t limited to Lenovo laptops sold over a specific date range. It means that anyone who has come into contact with a Komodia product, or who has had some sort of Parental Control software installed on their computer should probably check to see if they are affected,” said Rogers.

“This problem is much bigger than we thought it was.”

Research Credit: Martin Luther


Plea Deals Rather Than Talking About StingRay

February 23rd, 2015

Via: Washington Post:

McKenzie’s case is emblematic of the growing, but hidden, use by local law enforcement of a sophisticated surveillance technology borrowed from the national security world. It shows how a gag order imposed by the FBI — on grounds that discussing the device’s operation would compromise its effectiveness — has left judges, the public and criminal defendants in the dark on how the tool works.

But how did he know that the phone was in the house at 6 in the morning? The phone was a “burner” — one not registered under McKenzie’s name.

“We do have specific equipment that allows us to .?.?. direction-find on the handset, if necessary,” Corbitt said.

“What is that, and how does that work?” McMullen asked.

“I can’t go into that,” he said. “Due to [a] nondisclosure agreement with the FBI, we’re not able to get into the details of how the equipment operates.”


Why Does Apple Include Government Certificate Authorities on the Mac?

February 23rd, 2015

Via: Zit Seng’s Blog:

The Certificate Authorities are usually trustworthy. Usually. Except, when you look into the list Certificate Authorities trusted by the Mac. There are the usual big name Certificate Authorities like Verisign, GeoTrust, Symantec and Thawte. But how about these ones:

Subject: C=US, O=U.S. Government, OU=FPKI, CN=Federal Common Policy CA
Subject: C=US, O=U.S. Government, OU=DoD, OU=PKI, CN=DoD Root CA 2
Subject: C=JP, O=Japanese Government, OU=ApplicationCA
Subject: C=CN, O=China Internet Network Information Center, CN=China Internet Network Information Center EV Certificates Root

But governments are the good people right? Erm, I don’t know. There are people who don’t trust their own government. For example, U.S. citizens may be concerned about their NSA (or FBI) spying activities. They are afraid about the NSA being able to break encryption codes.

Well, it turns out that NSA’s job is a lot easier. There are no codes to break. They just intercept your communication, carry out a man-in-the-middle attack, and what else do they need? You think your HTTPS connection is securely encrypted, but wait, couldn’t the U.S. government generate a brand new fake certificate, give it to the NSA, and then serve that to you? Your web browser won’t raise any alarm bells. The SSL certificate is valid, and it is signed by a Certificate Authority that is trusted by your computer.

So, just to get this straight. Not only does the U.S. government have the privilege of intercepting any of your HTTPS connections and present valid, trusted, SSL certificates to you, the Japanese government and the Chinese government have the same privileges.


“Think of it as the food manufacturers’ equivalent of an arms fair”

February 22nd, 2015

Via: Guardian:

On a bright, cold day in late November 2013, I found myself in the dark, eerie, indoor expanses of Frankfurt’s Blade Runner-like Festhalle Messe. I was there undercover, to attend an annual trade show called Food Ingredients. This three-day exhibition hosts the world’s most important gathering of ingredients suppliers, distributors and buyers. In 2011, when it was held in Paris, more than 23,000 visitors attended from 154 countries, collectively representing a buying power of €4bn (£2.97bn). Think of it as the food manufacturers’ equivalent of an arms fair. It is not open to the public. Anyone who tries to register has to show that they work in food manufacturing; I used a fake ID.

Tired after hours of walking round the fair, and, uncharacteristically, not feeling hungry, I sought refuge at a stand displaying cut-up fruits and vegetables; it felt good to see something natural, something instantly recognisable as food. But why did the fruit have dates, several weeks past, beside them? A salesman for Agricoat told me that they had been dipped in one of its solutions, NatureSeal, which, because it contains citric acid along with other unnamed ingredients, adds 21 days to their shelf life. Treated in this way, carrots don’t develop that telltale white that makes them look old, cut apples don’t turn brown, pears don’t become translucent, melons don’t ooze and kiwis don’t collapse into a jellied mush; a dip in NatureSeal leaves salads “appearing fresh and natural”.

For the salesman, this preparation was a technical triumph, a boon to caterers who would otherwise waste unsold food. There was a further benefit: NatureSeal is classed as a processing aid, not an ingredient, so there’s no need to declare it on the label, no obligation to tell consumers that their “fresh” fruit salad is weeks old.

Over the past few years, the food industry has embarked on an operation it dubs “clean label”, with the goal of removing the most glaring industrial ingredients and additives, replacing them with substitutes that sound altogether more benign. Some companies have reformulated their products in a genuine, wholehearted way, replacing ingredients with substitutes that are less problematic. Others, unconvinced that they can pass the cost on to retailers and consumers, have turned to a novel range of cheaper substances that allow them to present a scrubbed and rosy face to the public.


U.S. to Begin Widespread Sales of Killer Drones to Allies

February 22nd, 2015

Via: Washington Post:

The Obama administration will permit the widespread export of armed drones for the first time, a step toward providing allied nations with weapons that have become a cornerstone of U.S. counterterrorism strategy but whose remotely controlled power to kill is intensely controversial.

The new policy, announced Tuesday after a long internal review, is a significant step for U.S. arms policy as allied nations from Italy to Turkey to the Persian Gulf region clamor for the aircraft. It also is a nod to U.S. defense firms scrambling to secure a greater share of a growing global drone market.


Feds Changing Absurd Cholesterol Guidelines

February 20th, 2015

How many people were killed or permanently injured by statins because of the decades long cholesterol quackery?!?

Via: Los Angeles Times:

Go ahead and make that omelet. A new draft of the federal government’s healthy eating guidelines is poised to scramble some long-standing advice on cholesterol-rich foods.

Nutrition and public health experts advising the federal government recommended Thursday that cholesterol no longer be labeled a “nutrient of concern” — a designation that for decades has prompted health-conscious Americans to avoid eggs and other foods that are high in the fat-like substance.

The new advice appeared in the fine print of a scientific report prepared for the secretaries of Agriculture and Health and Human Services. It is widely expected to be adopted by the panel that will update the government’s Dietary Guidelines for Americans later this year.


Apple Wants to Start Producing Cars as Soon as 2020

February 20th, 2015

Via: Bloomberg:

Apple Inc., which has been working secretly on a car, is pushing its team to begin production of an electric vehicle as early as 2020, people with knowledge of the matter said.

The timeframe — automakers typically spend five to seven years developing a car — underscores the project’s aggressive goals and could set the stage for a battle for customers with Tesla Motors Inc. and General Motors Co. Both automakers are targeting a 2017 release of an electric vehicle that can go more than 200 miles on a single charge and cost less than $40,000.

“That’s the inflection point — the proving ground — that brings on the electric age,” Steve LeVine, author of “The Powerhouse,” a book about the automotive battery industry, said on Bloomberg TV Thursday. “Now you have Apple coming in and this is critical mass. Was GM really going to be able to match Tesla? Apple can.”


Jeb Bush’s Foreign Policy Team Is Eerily Familiar, in One Venn Diagram

February 20th, 2015

Wolfowitz. Wow.

Hayden. Chertoff.

Why not roll Cheney out for one last slaughter with the Legion of Doom?

Via: Washington Post:

Former Florida governor Jeb Bush will announce his foreign policy vision in a speech Wednesday in Chicago. Accompanying that speech is a rollout of a slate of experts who will help guide the candidate on foreign policy issues.

If Bush’s goal is to present himself as his “own man,” that list of advisers undermines the point somewhat: 19 of the 21 people on it worked in the administrations of his father or brother. We’ve identified the roles each played in the past three Republican administrations, divvying them up as needed in the following Venn diagram.


The Great SIM Heist

February 19th, 2015

Via: First Look:

AMERICAN AND BRITISH spies hacked into the internal computer network of the largest manufacturer of SIM cards in the world, stealing encryption keys used to protect the privacy of cellphone communications across the globe, according to top-secret documents provided to The Intercept by National Security Agency whistleblower Edward Snowden.

The hack was perpetrated by a joint unit consisting of operatives from the NSA and its British counterpart Government Communications Headquarters, or GCHQ. The breach, detailed in a secret 2010 GCHQ document, gave the surveillance agencies the potential to secretly monitor a large portion of the world’s cellular communications, including both voice and data.

The company targeted by the intelligence agencies, Gemalto, is a multinational firm incorporated in the Netherlands that makes the chips used in mobile phones and next-generation credit cards. Among its clients are AT&T, T-Mobile, Verizon, Sprint and some 450 wireless network providers around the world. The company operates in 85 countries and has more than 40 manufacturing facilities. One of its three global headquarters is in Austin, Texas and it has a large factory in Pennsylvania.

In all, Gemalto produces some 2 billion SIM cards a year. Its motto is “Security to be Free.”


« Previous PageNext Page »