Russian Wheat Harvest Down Sharply Due to Drought and Fires
August 4th, 2010Via: Kansas City Star:
Drought and raging wildfires have destroyed one-fifth of the wheat crop in Russia and sent wheat prices soaring around the world.
The fear that Russia, a major wheat producer, will have to cut exports by at least 30 percent is good news for U.S. farmers, who now are getting more money to go along with a bumper crop this year.
That big harvest, analysts point out, should spare U.S. consumers much increase in the prices of bread and other wheat-based foods despite the problems in Russia.
Any price increases will hit consumers hardest in wheat-deficient areas such as the Middle East, Africa and parts of Asia.
The severe drought in Russia is thought to be the country’s worst in 130 years. Most of the damage to the wheat crop has been caused by the drought, but now wildfires are sweeping farmlands in western Russia.
The Associated Press reported that the director of a small state farm outside Moscow said fire destroyed its entire wheat crop one night before the harvest.
“The fruits of the year’s labor of the farm went up in smoke. This is very painful,” Pavel Grudinin, director of Lenin State Farm, said on Russian television.
The drought is also affecting harvests in Ukraine and Kazakhstan, Russia’s neighboring wheat-producing countries.
Troubles with wheat crops aren’t confined to that part of the world. Heavy rains during the planting season destroyed much of Canada’s crop. The Canadian Wheat Board, the marketing agency for the country’s farmers, is forecasting a 35 percent drop in the harvest.
The crop disasters have fed an unyielding price rally. In July alone, prices at the Chicago Board of Trade surged 42 percent, the biggest monthly gain in half a century.
In Chicago, wheat prices breached $7 a bushel Tuesday for the first time since September 2008.
At the Kansas City Board of Trade, the leading exchange for hard red winter wheat, prices are at a 13-month high, closing Tuesday at $6.85 a bushel.
Hacker Spoofs Cell Phone Tower to Intercept Calls
August 4th, 2010Via: Wired:
A security researcher created a cell phone base station that tricks cell phones into routing their outbound calls through his device, allowing someone to intercept even encrypted calls in the clear.
The device tricks the phones into disabling encryption and records call details and content before they’re routed on their proper way through voice-over-IP.
The low-cost, home-brewed device, developed by researcher Chris Paget, mimics more expensive devices already used by intelligence and law enforcement agencies – called IMSI catchers – that can capture phone ID data and content. The devices essentially spoof a legitimate GSM tower and entice cell phones to send them data by emitting a signal that’s stronger than legitimate towers in the area.
“If you have the ability to deliver a reasonably strong signal, then those around are owned,” Paget said.
Paget’s system costs only about $1,500, as opposed to several hundreds of thousands for professional products. Most of the price is for the laptop he used to operate the system.
Doing this kind of interception “used to be a million dollars, now you can do it with a thousand times less cost,” Paget said during a press conference after his attack. “If it’s $1,500, it’s just beyond the range that people can start buying them for themselves and listening in on their neighbors.”
Paget’s device captures only 2G GSM calls, making AT&T and T-Mobile calls, which use GSM, vulnerable to interception. Paget’s aim was to highlight vulnerabilities in the GSM standard that allows a rogue station to capture calls. GSM is a second-generation technology that is not as secure as 3G technology.
Encrypted calls are not protected from interception because the rogue tower can simply turn it off. Although the GSM specifications say that a phone should pop up a warning when it connects to a station that does not have encryption, SIM cards disable that setting so that alerts are not displayed.
“Even though the GSM spec requires it, this is a deliberate choice on the cell phone makers,” Paget said.
The system captures only outbound calls. Inbound calls would go directly to voicemail during the period that someone’s phone is connected to Paget’s tower.
The device could be used by corporate spies, criminals, or private investigators to intercept private calls of targets.
“Any information that goes across a cell phone you can now intercept,” he said, except data. Professional grade IMSI catchers do capture data transfers, but Paget’s system doesn’t currently do this.
And Now… A Vaccine Against Stress
August 4th, 2010Oh sure.
Via: CBS News:
Stressed out? There’s no app for that, but soon enough there might be a vaccine.
Dr Robert Sapolsky, a neuroscience professor at Stanford, says after 30 years of studying stress, his team might be on the verge of a novel cure.
“To be honest, I’m still amazed that it works,” Sapolsky told Wired in an August profile.
Sapolsky has long theorized that, unlike some animals, humans are unable to turn off stress chemicals used for the fight-or-flight mechanism. A class of hormone called glucocorticoids are one of the chief offenders, according to Sapolsky.
So his team has pioneered a way to bootstrap a “herpes virus to carry engineered ‘neuroprotective’ genes deep into the brain to neutralize the rogue hormones before they can cause damage,” according to the Daily Mail.
Sounds properly science fiction, but will it work?
So far, rat studies have gone well, according to the British paper. Human trials are still years away.
Until then, don’t give up your yoga mat.
Web Attack Uses Google Geolocation Database to Identify Address of Routers
August 4th, 2010First of all, as usual with stories like this, I have to refer back to my old essay that deals with the Ugly Truth About Online Anonymity.
Second, this hack isn’t new. See the Skyhook Wireless antics, circa 2008.
Third, the article below doesn’t make it clear, but this will only reveal your exact location if you’re using a wi-fi router that is in Google’s location services database.
So, yes, “Privacy is dead, people,” like the man says, but it’s not because of this. This is just another blunt blow of the rubber hose on the lifeless body of privacy.
Via: BBC:
One visit to a booby-trapped website could direct attackers to a person’s home, a security expert has shown.
The attack, thought up by hacker Samy Kamkar, exploits shortcomings in many routers to find out a key identification number.
It uses this number and widely available net tools to find out where a router is located.
Demonstrating the attack, Mr Kamkar located one router to within nine metres of its real world position.
‘Creepy’ attack
Many people go online via a router and typically only the computer directly connected to the device can interrogate it for ID information.
However, Mr Kamkar found a way to booby-trap a webpage via a browser so the request for the ID information looks like it is coming from the PC on which that page is being viewed.
He then coupled the ID information, known as a MAC address, with a geo-location feature of the Firefox web browser. This interrogates a Google database created when its cars were carrying out surveys for its Street View service.
This database links Mac addresses of routers with GPS co-ordinates to help locate them. During the demonstration, Mr Kamkar showed how straightforward it was to use the attack to identify someone’s location to within a few metres.
“This is geo-location gone terrible,” said Mr Kamkar during his presentation. “Privacy is dead, people. I’m sorry.”
Research Credit: GP
China: Garbage Islands Threaten Three Gorges Dam
August 3rd, 2010Via: Reuters:
Thousands of tons of garbage washed down by recent torrential rain are threatening to jam the locks of China’s massive Three Gorges Dam, and is in places so thick people can stand on it, state media said on Monday.
Chen Lei, a senior official at the China Three Gorges Corporation, told the China Daily that 3,000 tons of rubbish was being collected at the dam every day, but there was still not enough manpower to clean it all up.
“The large amount of waste in the dam area could jam the miter gate of the Three Gorges Dam,” Chen said, referring to the gates of the locks which allow shipping to pass through the Yangtze River.
The river is a crucial commercial artery for the upstream city of Chongqing and other areas in China’s less-developed western interior provinces.
Pictures showed a huge swathe of the waters by the dam crammed full of debris, with cranes brought in to fish out a tangled mess, including shoes, bottles, branches and Styrofoam.
Some 50,000 square meters of water (more than half a million square feet) had been covered by trash washed down since the start of the rainy season in July, the report said. The trash is around 60 centimeters (two feet) deep, and in some parts so compacted people can walk on it, the Hubei Daily added.
Related: Clean Energy and Turning What’s Left Into Trash
Rockefeller Foundation: Scenarios for the Future of Technology and International Development
August 3rd, 2010This Rockefeller Foundation report lays out four possible scenarios for the near future. I’ll just clip a few passages from each of the four. You’ll love this.
Via: Rockefeller Foundation:
LOCK STEP – A world of tighter top-down government control and more authoritarian leadership, with limited innovation and growing citizen pushback
In 2012, the pandemic that the world had been anticipating for years finally hit. Unlike 2009’s H1N1, this new influenza strain — originating from wild geese — was extremely virulent and deadly. Even the most pandemic-prepared nations were quickly overwhelmed when the virus streaked around the world, infecting nearly 20 percent of the global population and killing 8 million in just seven months, the majority of them healthy young adults. The pandemic also had a deadly effect on economies: international mobility of both people and goods screeched to a halt, debilitating industries like tourism and breaking global supply chains. Even locally, normally bustling shops and office buildings sat empty for months, devoid of both employees and customers.
…
At first, the notion of a more controlled world gained wide acceptance and approval. Citizens willingly gave up some of their sovereignty — and their privacy — to more paternalistic states in exchange for greater safety and stability.
Citizens were more tolerant, and even eager, for top-down direction and oversight, and national leaders had more latitude to impose order in the ways they saw fit. In developed countries, this heightened oversight took many forms: biometric IDs for all citizens, for example, and tighter regulation of key industries whose stability was deemed vital to national interests. In many developed countries, enforced cooperation with a suite of new regulations and agreements slowly but steadily restored both order and, importantly, economic growth.
CLEVER TOGETHER – A world in which highly coordinated and successful strategies emerge for addressing both urgent and entrenched worldwide issues
The recession of 2008-10 did not turn into the decades-long global economic slide that many had feared. In fact, quite the opposite: strong global growth returned in force, with the world headed once again toward the demographic and economic projections forecasted before the downturn.
India and China were on track to see their middle classes explode to 1 billion by 2020. Mega-cities like Sao Paulo and Jakarta expanded at a blistering pace as millions poured in from rural areas. Countries raced to industrialize by whatever means necessary; the global marketplace bustled.
But two big problems loomed. First, not all people and places benefited equally from this return to globalized growth: all boats were rising, but some were clearly rising more. Second, those hell-bent on development and expansion largely ignored the very real environmental consequences of their unrestricted growth. Undeniably, the planet’s climate was becoming increasingly unstable.
Sea levels were rising fast, even as countries continued to build-out coastal mega-cities. In 2014, the Hudson River overflowed into New York City during a storm surge, turning the World Trade Center site into a three-foot-deep lake. The image of motorboats navigating through lower Manhattan jarred the world’s most powerful nations into realizing that climate change was not just a developing-world problem.
That same year, new measurements showing that atmospheric carbon dioxide levels were climbing precipitously created new urgency and pressure for governments (really, for everyone) to do something fast.
…
A functioning global cap and trade system was also established. Worldwide, the pressure to reduce waste and increase efficiency in planet-friendly ways was enormous. New globally coordinated systems for monitoring energy use capacity — including smart grids and bottom-up pattern recognition technologies — were rolled out.
HACK ATTACK – An economically unstable and shock-prone world in which governments weaken, criminals thrive, and dangerous innovations emerge
Devastating shocks like September 11, the Southeast Asian tsunami of 2004, and the 2010 Haiti earthquake had certainly primed the world for sudden disasters. But no one was prepared for a world in which large-scale catastrophes would occur with such breathtaking frequency. The years 2010 to 2020 were dubbed the “doom decade” for good reason: the 2012 Olympic bombing, which killed 13,000, was followed closely by an earthquake in Indonesia killing 40,000, a tsunami that almost wiped out Nicaragua, and the onset of the West China Famine, caused by a once-in a-millennium drought linked to climate change.
Not surprisingly, this opening series of deadly asynchronous catastrophes (there were more) put enormous pressure on an already overstressed global economy that had entered the decade still in recession. Massive humanitarian relief efforts cost vast sums of money, but the primary sources — from aid agencies to developed-world governments — had run out of funds to offer. Most nation-states could no longer afford their locked-in costs, let alone respond to increased citizen demands for more security, more healthcare coverage, more social programs and services, and more infrastructure repair. In 2014, when mudslides in Lima buried thousands, only minimal help trickled in, prompting the Economist headline: “Is the Planet Finally Bankrupt?”
These dire circumstances forced tough tradeoffs. In 2015, the U.S. reallocated a large share of its defense spending to domestic concerns, pulling out of Afghanistan — where the resurgent Taliban seized power once again. In Europe, Asia, South America, and Africa, more and more nationstates lost control of their public finances, along with the capacity to help their citizens and retain stability and order. Resource scarcities and trade disputes, together with severe economic and climate stresses, pushed many alliances and partnerships to the breaking point; they also sparked proxy wars and low-level conflict in resource-rich parts of the developing world. Nations raised trade barriers in order to protect their domestic sectors against imports and — in the face of global food and resource shortages — to reduce exports of agricultural produce and other commodities. By 2016, the global coordination and interconnectedness that had marked the post-Berlin Wall world was tenuous at best.
With government power weakened, order rapidly disintegrating, and safety nets evaporating, violence and crime grew more rampant. Countries with ethnic, religious, or class divisions saw especially sharp spikes in hostility: Naxalite separatists dramatically expanded their guerrilla campaign in East India; Israeli- Palestinian bloodshed escalated; and across Africa, fights over resources erupted along ethnic or tribal lines. Meanwhile, overtaxed militaries and police forces could do little to stop growing communities of criminals and terrorists from gaining power. Technology-enabled gangs and networked criminal enterprises exploited both the weakness of states and the desperation of individuals. With increasing ease, these “global guerillas” moved illicit products through underground channels from poor producer countries to markets in the developed world. Using retired 727s and other rogue aircraft, they crisscrossed the Atlantic, from South America to Africa, transporting cocaine, weapons, and operatives. Drug and gun money became a common recruiting tool for the desperately poor.
SMART SCRAMBLE – An economically depressed world in which individuals and communities develop localized, makeshift solutions to a growing set of problems
The global recession that started in 2008 did not trail off in 2010 but dragged onward. Vigorous attempts to jumpstart markets and economies didn’t work, or at least not fast enough to reverse the steady downward pull. The combined private and public debt burden hanging over the developed world continued to depress economic activity, both there and in developing countries with economies dependent on exporting to (formerly) rich markets. Without the ability to boost economic activity, many countries saw their debts deepen and civil unrest and crime rates climb.
The United States, too, lost much of its presence and credibility on the international stage due to deepening debt, debilitated markets, and a distracted government. This, in turn, led to the fracturing or decoupling of many international collaborations started by or reliant on the U.S.’s continued strength.
…
Makeshift, “good enough” technology solutions — addressing everything from water purification and harnessing energy to improved crop yield and disease control — emerged to fill the gaps. Communities grew tighter. Micro-manufacturing, communal gardens, and patchwork energy grids were created at the local level for local purposes. Many communities took on the aura of co-ops, some even launching currencies designed to boost local trade and bring communities closer together. Nowhere was this more true than in India, where localized experiments proliferated, and succeeded or failed, with little connection to or impact on other parts of the country — or the world.
The Aftermath of the Global Housing Bubble Chokes the World Banking System
August 3rd, 2010The U.S. housing bubble was tame compared with several other ones around the world over the same period.
Via: Housing Story:
What our leaders are doing is correcting a severe cyclical recession. What our reporters are doing is covering a severe cyclical recession. What sublime kabuki theater.
Back in the real world, the destruction of debt required to cure a credit bubble hasn’t been done. That means the reason for the new credit crisis is no different than during that past time of fear and failure – except that now we have new magnificent malignant clusters of sovereign debt serving as a sort of hand-held fan covering the unclothed emperor. Does that count as cover?
There is a prism I use to see the world. It is in houses. Look immediately above to see housing prices acting strangely in many advanced economies (the global housing bubble chart). Let me tell what I see when I look at this: We had one wicked housing bubble in the United States, but apparently we were the conservative party poopers. It looks like the funner countries are Ireland, Britain, Spain, Sweden, France, Norway, Denmark and Italy.
Research Credit: Pookie
Six Month Backlog of Americans Wanting to Renounce Citizenship in Britain
August 3rd, 2010Via: Financial Times:
At the US Embassy in London, there is a waiting list that none of the officials likes to discuss. On the list are Americans hoping to give up their citizenship, as they seek shelter from the Internal Revenue Service.
…
The backlog at the US Embassy, where no appointments are available until February, stems from a rise in the number of American expatriates living in the UK who have been seeking to escape paying US tax on their worldwide income and capital gains since the simplification of US tax laws in 2008.
Six Cities Training Mail Carriers to Dispense “Anti-Terror Drugs”
August 2nd, 2010Via: USA Today:
The Postal Service is ready to deliver lifesaving drugs to about a quarter of the residents of Minneapolis-St. Paul, the only metropolitan area in the nation where letter carriers have been trained to dispense medication after a large-scale terrorist attack involving biological weapons.
Six years after the government began exploring the idea of using postal workers as rapid-response medicine dispensers and eight months after President Obama ordered government agencies to develop a plan to do so, efforts are underway in six cities to train workers to deliver the drugs needed to counter anthrax or other potentially deadly agents, the White House says.
The White House won’t name the six cities, and Department of Homeland Security spokeswoman Amy Kudwa says she can’t talk about whether more cities are interested in the voluntary program.
Cities are not required to adopt the plan, and most have separate plans in place to set up distribution centers in schools, community health centers and other government buildings where people can go to pick up drugs in the event of an attack. The White House, however, says using the Postal Service is a cost-effective and efficient way to create a reliable system for drug distribution in a crisis because postal workers can get drugs to the elderly and others who can’t get out easily or wait in long lines.
“We need the capability” to get lifesaving drugs to people in a hurry because in the case of an anthrax attack, in particular, “what we know is: hours matter,” White House spokesman Nick Shapiro says.
He says “many cities have expressed interest” in the program, especially now that there is a successful model to follow in Minneapolis.
Adrian Lamo Is a “Volunteer” for Project Vigilant, a Private Internet Surveillance Company Closely Linked to U.S. Intelligence
August 2nd, 2010Via: Forbes:
A semi-secret government contractor that calls itself Project Vigilant surfaced at the Defcon security conference Sunday with a series of revelations: that it monitors the traffic of 12 regional Internet service providers, hands much of that information to federal agencies, and encouraged one of its “volunteers”, researcher Adrian Lamo, to inform the federal government about the alleged source of a controversial video of civilian deaths in Iraq leaked to whistle-blower site Wikileaks in April.
Chet Uber, the director of Fort Pierce, Fl.-based Project Vigilant, says that he personally asked Lamo to meet with federal authorities to out the source of a video published by Wikileaks showing a U.S. Apache helicopter killing several civilians and two journalists in a suburb of Baghdad, a clip that Wikileaks labelled “Collateral Murder.” Lamo, who Uber said worked as an “Adversary Characterization” analyst for Project Vigilant, had struck up an online friendship with Bradley Manning, a former U.S. Army intelligence analyst who currently faces charges of releasing the classified video.
In June, Uber said he learned from Lamo’s father that the young researcher had identified Manning as the video’s source, and pressured him to meet with federal agencies to name Manning as Wikileaks’ source. He then arranged a meeting with employees of “three letter” agencies and Lamo, who Uber said had mixed feelings about informing on Manning.
“I’m the one who called the U.S. government,” Uber said. “All the people who say that Adrian is a narc, he did a patriotic thing. He sees all kinds of hacks, and he was seriously worried about people dying.”
Uber says that Lamo later called him from the meeting, regretting his decision to inform on Manning. “I’m in a meeting with five guys and I don’t want to do this,” Uber says Lamo told him at the time. Uber says he responded, “You don’t have any choice, you’ve got to do this.”
“I said, ‘They’re not going to throw you in jail,'” Uber said. “‘Give them everything you have.'”
…
According to Uber, one of Project Vigilant’s manifold methods for gathering intelligence includes collecting information from a dozen regional U.S. Internet service providers. (ISPs) Uber declined to name those ISPs, but said that because the companies included a provision allowing them to share users’ Internet activities with third parties in their end user license agreements (EULAs), Vigilant was able to legally able to gather data from the Internet carriers and use it to craft reports for federal agencies. A Vigilant press release says that the organization tracks more than 250 million IP addresses a day and can “develop portfolios on any name, screen name or IP address.”
“We don’t do anything illegal,” says Uber. “If an ISP has a EULA to let us monitor traffic, we can work with them. If they don’t, we can’t.”
And whether that massive data gathering violates privacy? The organization says it never looks at personally identifying information, though just how it defines that information isn’t clear, nor is how it scrubs its data mining for sensitive details.
ISP monitoring is just one form of intelligence that Vigilant employs, says Uber. It also gathers variety of open source intelligence and numerous agents around the world. In Iran, for instance, Uber says Vigilant created an anonymous Internet proxy service that allowed it to receive information from local dissidents prior to last year’s election, including early information indicating that the re-election of Mahmoud Ahmadinejad was skewed by fraud.
Uber, who formerly founded a private sector group called Infragard that worked closely with the FBI, compares the organization’s techniques with Ghostnet, the Chinese cyber espionage campaign revealed last year that planted spyware on computers of many governments and NGOs. “We’ve developed a network for obfuscation that allows us to view bad actors,” he says.
Uber says he’s speaking publicly about Vigilant because he wants to recruit the conference’s breed of young, skilled hackers. By July 2011, the organization hopes to have more than 1,300 new employees.
The organization already has a few big names. According to a San Francisco Examiner article last month, it employs former NSA official Ira Winkler and Suzanne Gorman, former security chief for the New York Stock Exchange.
—
Elite U.S. Cyber Team Courts Hackers to Fight Terror
Via: AFP:
An elite US cyber team that has stealthily tracked Internet villains for more than a decade pulled back its cloak of secrecy to recruit hackers at a DefCon gathering.
Vigilant was described by its chief Chet Uber as a sort of cyber “A-Team” taking on terrorists, drug cartels, mobsters and other enemies on the Internet.
“We do things the government can’t,” Uber said on Sunday. “This was never supposed to have been a public thing.”
Vigilant is an alliance of slightly more than 600 volunteers and its secret ranks reportedly include chiefs of technology at top firms and former high-ranking US cyber spies.
The group scours Internet traffic for clues about online attacks, terrorists, cartels and other targets rated as priorities by members of the democratically run private organization.
Vigilant also claimed to have “collection officers” in 22 countries that gather intelligence or coordinate networks in person.
“We go into bars, look for lists of bad actors, get tips from people…” Uber said.
“But, a significant amount of our intelligence comes from our monitoring the Internet. We are looking at everything on websites, and websites are public.”
He was adamant that Vigilant stays within US law while being more technologically nimble than government agencies weighed down by bureaucracy and internal rivalries.
“Intelligence is a by-product of what our research is,” Uber said. “Our research is into attacks, why they happen and how we can prevent them.”
Vigilant shares seemingly significant findings with US spy agencies, and is so respected by leading members of the hacker community that Uber was invited to DefCon to recruit new talent.
Uber said that Vigilant came up from underground after 14 years of operation in a drive to be at “full capacity” by adding 1,750 “vetted volunteers” by the year 2012.
“We are good people not out to hurt anybody,” Uber said. “Our one oath is to defend the US Constitution against all enemies foreign and domestic.”
Anything that can be looked at legally on the Internet is fair game for Vigilant, with email and encrypted transactions such as online shopping off limits.
The holy grail for Vigilant is finding out who is behind cyber attacks. Inability to figure out who launches online assaults routinely leaves companies or governments without targets to fire back at.
“This is a completely unsolved problem,” Uber said. “We’ve probably been working on it as long as the government has.”
Vigilant has developed its own “obfuscation” network to view “bad actors” on the Internet without being noticed.
He told of uncovering evidence of fraud in the latest presidential election in Iran while testing a way for people to slip information out of countries with oppressive regimes.
The information obtained was given to US officials.
“They expected fraud but they didn’t expect the wholesale fraud that we passed along,” Uber said.
Vigilant’s network claimed a role relaying Twitter messages sent by Iranian protestors in the aftermath of the election.
The group is bent on gathering intelligence by any legal means and then putting the pieces together to see bigger pictures.
“The wholesale tapping of the Internet around the world can’t be done,” Uber said. “We are looking at what people write, how people attack, how attacks happen…we don’t care who that person is.”
Uber is working on a mathematical model to spot when terrorist organizations are recruiting teenagers online. The group has 100 projects in the works.
“Our end goal is to provide software as a service to government agencies so we can get out of the business of intelligence,” Uber said.
Along with technology savants, Vigilant is recruiting sociologists, psychologists, and people with other specialties.
The wall between “feds” and hackers has been crumbling at DefCon, which has become a forum for alliances between government crime fighters and civilians considered digital-age “ninjas.”


