30GB Zunes Failing Everywhere, All At Once
December 31st, 2008Cylons attack?
Probably not.
Anyway, there’s an object lesson in critical infrastructure here, even though this situation involves digital music players.
Via: Ars:
Around midnight Pacific time last night, 30GB Zunes began restarting and locking up at their boot screens. Reports have swamped official forums and fan sites, and Microsoft has yet to officially comment on the reason for this pre-New-Year’s Zune apocalypse.
As reported by hundreds of owners in forum threads at Zune.net and other sites, one of which already has over 1,000 replies, the 30GB model of Microsoft’s Zune digital media player—and apparently only the 30GB model—entered a coma last night. Whether a Zune was sitting idle or was in the middle of playing a song, users report that the device either shut itself off or restarted and then locked up at its boot screen.
Car Market Total Collapse
December 31st, 2008Apologies, I wasn’t able to determine the source of this.
Scott found the source: BBC: California’s Car Crisis:
Scott also sent: Fly over UK’s biggest car park. Chilling. Must see.
The $775,000-a-Year GI
December 31st, 2008Via: CounterPunch:
Kosiak estimates that by 2018, the total spending on the wars in Iraq and Afghanistan, along with related spending on veterans’ health care and other matters, could reach $1.7 trillion. The 88-page report, which includes 182 footnotes, provides an exhaustive look at the cost of Bush’s foreign adventures. It also provides a more modest estimate of the cost of those adventures than that provided by Joseph Stiglitz and Linda Bilmes, who have famously estimated the costs of the war on terrorism at over $3 trillion.
But the truly astounding number in Kosiak’s report comes on page 38, where he estimates that the total cost of sending a single soldier to fight in Iraq or Afghanistan is about $775,000 per year. Kosiak came up with that number by using data published in March by the Congressional Budget Office. He writes that the $775,000 per year figure “is some three times more than CBO projected in 2002, based on the cost of recent past wars, and about 70 percent more than its estimate from 2005.” Kosiak says that the soaring cost of keeping soldiers in the war zones is due to inflation, changes in force levels, and the increases in funding requested by the Department of Defense.
Kosiak’s estimate of the daily cost of deployment is particularly important given Obama’s plans to send an additional 20,000 U.S. soldiers to Afghanistan, a move that could bolster the U.S. presence there to about 52,000. And some analysts are projecting that the U.S. could need more than 100,000 troops to stabilize the vast country.
But at a cost of more than $2,100 per day per soldier, a military expansion of that magnitude will be incredibly costly. And it’s not at all clear that the U.S. can afford such an increase at a time when the U.S. treasury – and the U.S. economy – are in such parlous condition. Further, it’s essential to remember how quickly the costs of Bush’s “global war on terrorism” are increasing. In 2005, the Congressional Research Service put the cost of keeping one U.S. soldier in Afghanistan at about $275,000 per year. By early 2006, the cost of keeping one soldier on the ground in Iraq or Afghanistan had jumped to about $400,000 per year. Now Kosiak is estimating that actual cost of keeping a soldier deployed is nearly twice the estimate that the CRS published just two years ago.
A surge in inflation (which is almost certainly coming, thanks to the U.S. government’s huge fiscal deficit and the plans for yet-bigger deficits) will likely send Kosiak’s $775,000-per-year estimate even higher. Thus, by 2011 or so, the cost of keeping a soldier deployed in a war zone might top $1 million per year.
Research Credit: ltcolonelnemo
Several Cryptogon Readers Send Contributions
December 31st, 2008Thank you.
MW2 $60
SH $125
TW $50
BS $25
UO €10
AS £15
IL AU$100
Judge Rejects Class-Action Status in FEMA Trailer Suits
December 31st, 2008Imagine my shock.
The children who spent time in these trailers have been murdered, they just aren’t dead yet.
See:
Children in Katrina Trailers May Face Lifelong Ailments
FEMA Trailer Manufacturers Knew About Formaldehyde, Findings Went Undisclosed
Via: AP:
A federal judge on Monday refused to grant class-action status to lawsuits claiming that thousands of Gulf Coast hurricane victims were exposed to potentially toxic fumes while living in government-issued trailers.
U.S. District Judge Kurt Engelhardt ruled that a batch of lawsuits on behalf of hundreds of plaintiffs against the federal government and several trailer manufacturers can’t be handled as a class action because each person’s claim is unique and must be examined individually.
Government tests found elevated levels of formaldehyde in many of the trailers that housed victims of Katrina and Rita after those powerful hurricanes clobbered the Gulf Coast in 2005. Formaldehyde is a preservative that can cause breathing problems and is classified as a carcinogen.
Lawyers for the storm victims accuse trailer makers of using shoddy materials and building methods in a rush to meet the government’s demand for emergency housing for the displaced. The attorneys had argued that a class-action lawsuit would efficiently resolve all the cases from Louisiana, Texas, Mississippi and Alabama that Engelhardt is presiding over in New Orleans.
But the judge said the cases involve hundreds of trailer models made by dozens of companies and occupied by people with varying medical histories and symptoms.
“Each plaintiffs’ claims and alleged injuries will require an examination of individual evidence,” Engelhardt wrote in a 50-page ruling.
Tony Buzbee, one of the lead lawyers for plaintiffs, said he respects the judge’s decision but hasn’t ruled out an appeal.
“What it means is that we will try each of these cases individually,” he said. “We’re very excited about moving past this phase and getting some of this evidence before a jury.”
A Justice Department spokesman said he couldn’t comment on Engelhardt’s ruling because it involves ongoing litigation.
A lawyer for trailer makers didn’t immediately return a call for comment Monday.
The Federal Emergency Management Agency provided trailers or mobile homes to more than 144,000 families displaced by the 2005 hurricanes.
About a year ago, the U.S. Centers for Disease Control and Prevention tested the air quality in hundreds of occupied trailers and found formaldehyde levels that were, on average, about five times higher than what people are exposed to in most modern homes.
The symptoms reported by trailer dwellers include nausea, vomiting, difficulty breathing, skin rashes and ear infections.
Research Credit: ltcolonelnemo
SSL CERTIFICATES SIGNED WITH MD5 AUTHORITATIVELY BROKEN
December 31st, 2008“…no tinfoiler in his right mind would bet his life on SSL.”
—The Ugly Truth About Online Anonymity
* Chortling sounds *
Via: CNET:
BERLIN–A key piece of Internet technology that banks, e-commerce sites, and financial institutions rely on to keep transactions safe suffers from a serious security vulnerability, an international team of researchers announced on Tuesday.
They demonstrated how to forge security certificates used by secure Web sites, a process that would allow a sufficiently sophisticated criminal to fool the built-in verification methods used by all modern Web browsers–without the user being alerted that anything was amiss.
The problem is unlikely to affect most Internet users in the near future because taking advantage of the vulnerability requires discovering some techniques that are not expected to be made public as well as overcoming engineering hurdles: performing the initial digital forgery consumed approximately two weeks of computing time on a cluster of 200 PlayStation 3 consoles. In addition, a criminal needs to find a way to reroute traffic from a legitimate Web site to his own, perhaps through techniques that have become well-known in the last few years.
Yet if one group can do it today, others eventually will. “We have a proof-of-concept that allows us to impersonate any supposedly secure Web site on the Internet,” said David Molnar, a doctoral student in computer science at the University of California at Berkeley.
Molnar and six other researchers presented their findings during an afternoon session of the Chaos Computer Club’s annual conference here on Tuesday. Other team members include Jacob Appelbaum and Alexander Sotirov.
Their work has focused on finding vulnerabilities in a technology known as Secure Sockets Layer, or SSL, which was designed to provide Internet users with two guarantees: first, that the Web site they’re connecting to isn’t being spoofed, and second, that the connection is encrypted and is proof against eavesdropping. SSL is used whenever a user navigates to an address beginning with “https://”. SSL certificates essentially stand for the claim that, for instance, etrade.com actually belongs to E-Trade Inc., and is not being operated by a thief hoping to steal account passwords.
Most browsers indicate that SSL is active by displaying a small padlock icon. An attack using a forged authentication certificate–which is what the researchers say they have done–is insidious because the browser can’t detect it and the padlock icon would still appear.
Unlike most security issues, this problem cannot be fixed with a simple software update. “The bug is not in anyone’s software,” Sotirov said. “It’s not the browser that’s at fault. The browser does exactly what it’s supposed to do… The problem is that what it’s supposed to do is wrong.”
The attack exploits a mathematical vulnerability in the MD5 algorithm, one of the standard cryptographic functions used to check that SSL certificates (and thus the corresponding Web sites) are valid. This function has been publicly known to be weak since 2004, but until now no one had figured out how to turn this theoretical weakness into a practical attack.
An SSL certificate is a small file that ties a real-world corporate identity to a Web site address and a corresponding public encryption key. This is presented to a private certificate authority firm, which is supposed to verify the link between identity and domain name and then cryptographically “sign” the certificate to vouch for it.
The problem arises when someone else is able to forge the same signature.
VeriSign, which operates the largest certificate authority in the world, learned of the vulnerability early on Tuesday and acted quickly to close the hole in its certificates, according to Tim Callan, vice president of product marketing at the company.
“We went into our systems and removed the MD5 algorith and replaced it with SHA-1 (Secure Hashing Algorith),” he said. “You can not get an SSL certificate from VeriSign now that is subject to this attack.” More information from VeriSign is available on Callan’s SSL blog.
VeriSign was in the process of phasing out MD5 before the issue came up and is now on track to have it entirely out of commission in January, Callan said. “On balance, public key infrastructure works extraordinarily well,” he said when asked if the vulnerability illustrated a need to change the trust model.
Microsoft, while noting that the issue wasn’t a vulnerability with one of its products, tried to downplay the threat to users in a security advisory Monday.
“This new disclosure does not increase risk to customers significantly, as the researchers have not published the cryptographic background to the attack, and the attack is not repeatable without this information,” the advisory said.
A 1991-era protocol, but modern problems
When MIT professor Ron Rivest developed MD5 in 1991, it was considered sufficiently secure. But starting in 1996, a series of increasingly serious flaws started calling the continued viability of MD5 into question.
As CNET News reported in 2004, flaws discovered at that time “could eventually make it easier for intruders to insert undetectable back doors into computer code or to forge an electronic signature–unless a different, more secure algorithm is used.” Then, in 2007, Arjen Lenstra of Bell Laboratories Switzerland, with Marc Stevens and Benne de Weger of TU Eindhoven, demonstrated a technique to construct two new certificates with different content but the same fingerprint.
Although security researchers had been worrying, and recommending that other alternatives be considered, nobody had yet demonstrated how to exploit this theoretical flaw in a practical attack.
Molnar, Appelbaum, and Sotirov joined forces with the European MD5 research team in mid-2008, along with Swiss cryptographer Dag Arne Osvik. They realized that the co-construction technique could be used to simultaneously generate one normal SSL certificate and one forged certificate, which could be used to sign and vouch for any other. They purchased a signature for the legitimate certificate from an established company that was still using MD5 for signing, and then applied the legitimate signature to the forged certificate. Because the legitimate and forged certificates had the same MD5 value, the legitimate signature also marked the forged one as acceptable.
The process amounted to transferring a photograph from a real ID to a fake by carefully matching the holographic security markers.
The rogue certificate can then be used to sign any other certificate of the attacker’s choosing–such as one which assures Web browsers that a malicious phishing site is actually the legitimate etrade.com or bankofamerica.com.
After three unsuccessful attempts, each of which required approximately three days of compute time on a cluster of 200 PlayStation 3s, the researchers obtained a forged certificate authority in early November, at which time they notified browser developers and certificate authorities, or CAs, about the security flaw. Molnar estimates that the same processing time could be purchased from Amazon for about $1,500.
The team decided to disclose the vulnerability at the Berlin conference in hopes that the news will encourage everyone involved to fix the problem quickly. “The main message here is to stop issuing MD5 certificates, now,” said Molnar. He believes that MD5 is so weak it no longer should be used for any applications: “More secure, freely available alternatives exist.” (In November 2005, the U.S. government announced plans to find successors to MD5 and SHA-1, an official federal standard with its own problems. The new federal standard will be called SHA-3.)
By itself, the MD5-certificate-forging vulnerability wouldn’t be too worrisome. That’s because it relies on criminals being able to capture Web traffic to display a fraudulent Web site. But setting up a fake wireless access point to lure unsuspecting neighbors or business travelers is trivial, and a program released earlier this year to attack the domain name system (DNS) provides another way to direct Internet traffic for malicious purposes.
While only a few CAs currently sign certificates with MD5, Appelbaum estimates that 30 percent to 35 percent of all SSL certificates currently in use have an MD5 signature somewhere in their authentication chain. “The CAs should contact every customer that currently uses an MD5-signed certificate and offer a free replacement.”
In an interview on Tuesday morning, cryptography expert Bruce Schneier praised the research but downplayed the real-world consequences of the findings.
“SSL protects data in transit but the problem isn’t eavesdropping on the transmission. Someone can steal the credit card on some server somewhere. The real risk is data in storage. SSL protects against the wrong problem,” he said.
“This is good work, great cryptography. I love the research, but this doesn’t matter a whit,” Schneier added. “There are half a dozen ways to forge certificates and nobody checks them anyway.”
Paul Kocher, president of Cryptography Research and an architect of the SSL 3.0 protocol, said the exploit highlights the need for a new universal hash function “that everyone is comfortable with.”
“The paper is not a surprise, but at the same time it’s the crispest demonstration for why it’s necessary to remove this broken algorithm everywhere it is being used,” he said, before adding “there are bigger things to worry about, like browser bugs and operating security bugs.”
The researchers have created a Web site signed with a forged certificate which can be viewed here. The forged certificate was backdated so that it could not be used maliciously even if stolen from researchers, so you have to reset your system clock to August 2004 to view it.
Even though their work may be controversial, the researchers view their efforts as fundamental to creating a more secure Internet. “I don’t want to be hit by this type of attack either,” Sotirov said. “I use the Internet too.”
NFL Encourages Fans to Send Text Messages to Security Staff to Report Troublemakers
December 30th, 2008Via: USA Today:
Count Washington Redskins season-ticket holder Rick Cable as a big supporter of the NFL’s new Fan Code of Conduct.
During the Redskins’ 23-6 loss to the Pittsburgh Steelers on Nov. 3 at FedEx Field just outside Washington, Cable says, an obnoxious Steelers fan kept waving a “Terrible Towel” in the 47-year-old Cable’s face and screaming “Redskins suck!” Rather than escalate the confrontation, the Lusby, Md., resident quietly sent a text message to the stadium’s security command center. Security people responded quickly. When the Steelers fan gave them a hard time, he was ejected.
“It worked great,” Cable says.
It also reflected how fans are embracing new text-messaging systems that allow fans in NFL stadiums to inconspicuously report drunk or disorderly neighbors without confronting them, a provocative tactic many of the league’s 32 teams are using to enforce the conduct code announced by NFL commissioner Roger Goodell on Aug. 5.
Goodell’s rules — the result of rising concern that fan misconduct was driving some people from games — say that patrons who are drunk or disruptive, who use foul language or make obscene gestures or who verbally or physically harass other fans can be refused admission to games, or kicked out of them without refunds. Such fans also can be stripped of their season tickets.
The sweeping attempt to decrease misbehavior in stadiums and parking lots is a “work in progress,” says Milt Ahlerich, the NFL’s vice president of security. But the initiative, he says, “absolutely is working.”
As part of the program, teams are asking the 22.2 million patrons they predict will attend 333 preseason, regular season and playoff games this season to help identify bad apples in the stands.
Fans still are urged to complain to an usher or call a security hotline in the stadium to report unruly behavior. But text-messaging lines — typically advertised on stadium scoreboards and on signs where fans gather — are aimed at allowing tipsters to surreptitiously alert security personnel via cellphone without getting involved with rowdies or missing part of a game.
Research Credit: Bernard Marx
New Zealand Airline Flies Jetliner Partly on Biofuel
December 30th, 2008Via: AP:
A passenger jet powered in part by vegetable oil successfully completed a two-hour flight Tuesday to test a biofuel that could lower airplane emissions and cut costs, Air New Zealand said.
One engine of a Boeing 747-400 airplane was powered by a 50-50 blend of oil from jatropha plants and standard A1 jet fuel.
This year has seen an unprecedented push for alternative fuels by airlines, which were slammed by skyrocketing oil prices earlier in 2008 and are now bracing for a falloff in air travel in the face of a global economic slowdown.
While Air New Zealand couldn’t say whether the blend would be cheaper than standard jet fuel since jatropha is not yet produced on a commercial scale, the company expects the blend to be “cost competitive,” according to company spokeswoman Tracy Mills.
Biofuels were once regarded as impractical for aviation because most freeze at the low temperatures encountered at cruising altitudes. But tests show jatropha, whose seeds yield an oil already used to produce fuels like biodiesel, has an even lower freezing point than jet fuel.
Air New Zealand Chief Executive Rob Fyfe called the flight “a milestone for the airline and commercial aviation.”
“Today we stand at the earliest stages of sustainable fuel development and an important moment in aviation history,” he said shortly after the flight. The company’s goal is to become the world’s most environmentally sustainable airline.
The flight was the first to use jatropha as part of a biofuel mix.
In February, Boeing and Virgin Atlantic carried out a similar test flight that included a biofuel mixture of palm and coconut oil — but was dismissed as a publicity stunt by environmentalists who said the fuel could not be produced in the quantities needed for commercial aviation use.
Biofuels emit as much carbon as kerosene-based jet fuel, but jatropha — a Mexican plant that grows in warm climates — absorbs about half the carbon that jatropha-based fuels release. Air New Zealand’s proposed blend, for example, would mean a one-quarter reduction in the carbon footprint of standard jet fuel.
Many biofuels — like ethanol, which is produced from corn — have been blamed for raising the price of food by diverting it from kitchen tables to engines. While the link between biofuels and grain prices is debatable, Mills said that jatropha plants would not compete with food or other commercial crops since it can grow on land that would make poor farmland and needs little water.
“Ethanol is a first generation biofuel; jatropha a second generation biofuel that doesn’t compete for land with food production,” Mills said.
The test flight out of Auckland International Airport included a full-power takeoff and cruising to 35,000 feet (10,600 meters), where the crew manually set all four engine controls to check for identical performance readings among the biofuel-powered engine and those using jet fuel. Pilots also switched off the fuel pump for the biofuel engine at 25,000 feet (7,600 meters) “to test the lubricity of the fuel,” ensuring its friction in the pipe did not slow its flow to the engine.
Capt. David Morgan, the airline’s chief pilot who was on board the airplane, said results from the flight tests will provide the company and its partners with invaluable data to help jatropha become a certified aviation fuel.
The checks were “designed to test the biofuel to the fullest extent,” Morgan said.
While the airline heralded the flight as successful, Air New Zealand Group Manager Ed Sims cautioned that it will be at least 2013 before the company can ensure easy access to the large quantities of jatropha it would need to use the biofuel on all of its flights.
“Clearly we are a long, long way from being able to source commercially quantifiable amounts of the fuel and then be able to move that amount of fuel around the world to be able to power the world’s airlines is still some years off,” Sims told New Zealand’s National Radio.
The company bought the seeds from plantations in East Africa and India that total 309,000 acres (125,000 hectares).
The company hopes that by 2013, 10 percent of its flights will be powered, at least in part, by biofuels, Mills said. Most of those using the blend would be short haul domestic services.
Simon Boxer, of environmental group Greenpeace New Zealand, said it was inevitable that airlines would show greater interest in sustainable biofuels as travelers become more aware of the harm that air travel causes the environment.
But he said it wasn’t clear whether jatropha was really sustainable. He questioned what the environmental impact would be if jatropha grew popular and more land and resources were needed to produce it on a commercial scale.
The flight was a joint venture by Air New Zealand, airplane maker Boeing, engine maker Rolls Royce and biofuel specialist, UOP Llc, a unit of Honeywell International.
The flight, initially scheduled for earlier this month, was postponed after an Air New Zealand A320 Airbus crashed off Perpignan on the south coast of France on Nov. 27, killing all seven on board.
UK: CCTV Cameras and Microphones Spy on Children as Young as Four
December 30th, 2008Via: Telegraph:
The surveillance equipment is in use in around 85 primary and secondary schools and colleges across the country.
Classwatch, the company behind the system, says it is being used as a way to monitor children who are disrupting lessons.
The firm said the equipment, which is sold with evidence bags approved by the Crown Prosecution Service to store material for court cases, can be used to compile “proof” of wrongdoing.
The system includes ceiling-mounted microphones and cameras and a hard drive recorder housed in a secure cabinet.
They cost around £3,000 to install in each classroom or can be leased for about £50 a month for each classroom.
Data protection watchdog the Information Commissioner has warned the surveillance may be illegal and demanded to know why schools are using it.
Classwatch said the devices act as “impartial witnesses” which can provide evidence in disputes and curb bullying and unruly behaviour.
They can also be used to protect teachers against false allegations of abuse and provide evidence acceptable in court, it said.
Andrew Jenkins, the firm’s director, said: “The system can be turned on and turned off as they wish.
“It is a bit like a video at home. This is not Big Brother. The system is under the control of the teacher.”
A Schools Department spokesman said: “We do not prescribe what schools must do to tackle security.”
Which Texan Was Going to Buy a Young Girl for Three Hundred Thousand Dollars?
December 30th, 2008I used to think that I could mentally handle any subject matter, no matter how horrible. What could be worse than what happened to Native Americans? The Soviet Union under Stalin and then what the Russians went through during World War II (estimates of the number of dead vary by millions)? The extermination programs of the Third Reich? Rwandan genocide… On and on. I was able to put these subjects in a sort of manageable, academic box. I could write papers about these things, discuss foreign policy failures, etc. blah blah without too much difficulty. Some might call it clinical detachment. Objectivity. Whatever.
Later on, however, as I started to research trauma induced mind control, I also started to stumble over stories related to human trafficking and crimes against children.
You may or may not have noticed that I don’t post much about human trafficking and crimes against children. It’s not that I’m not aware of these stories (I am). For the first time, with these topics, I found myself wanting to un-read what I was reading, and I couldn’t.
There is palpable, opaque, murmuring evil in the world, and this shit, in my opinion, offers a crystal clear view of it.
So, I’m warning you, in the strongest possible terms: If this topic is new to you, and you proceed, know that you run the risk of not being able to go back. You never know how or when this stuff will haunt you, but it almost certainly will haunt you.
With the long preface/disclaimer/warning out of the way, I have just one question:
Which Texan was going to buy a young girl for three hundred thousand dollars?
This is what happened to Shauna Newell:
MSNBC: Teen recounts horror of abduction into sex slavery
Independent News: Shauna’s Story of Slavery: Panhandle top place in Florida for human trafficking


