Web’s Random Numbers Are Too Weak, Researchers Warn

August 9th, 2015

Low entropy.

Via: BBC:

The data scrambling systems used by millions of web servers could be much weaker than they ought to be, say researchers.

A study found shortcomings in the generation of the random numbers used to scramble or encrypt data.

The hard-to-guess numbers are vital to many security measures that prevent data theft.

But the sources of data that some computers call on to generate these numbers often run dry.

This, they warned, could mean random numbers are more susceptible to well-known attacks that leave personal data vulnerable.

“This seemed like just an interesting problem when we got started but as we went on it got scary,” said security analyst Bruce Potter who, along with researcher Sasha Moore, carried out the study that was presented at the Black Hat security event in Las Vegas.


Brazil: Radio Journalist Critical of Government Killed During Live Broadcast

August 9th, 2015

Via: Fox Latino:

A well-known radio journalist in Brazil who repeatedly denounced political corruption was gunned down Thursday in the middle of one of his broadcasts.

Gleydson Carvalho was a dogged journalist who had received death threats on Facebook.

Carvalho, police said, was in the middle of his broadcast in Camocim, in the state of Ceará, when two men showed up at the building to buy advertising space, according to the show’s technical operator, Ricardo Farias.

The ad inquiry, police say, was a ruse. Once the men were allowed into the building, one of them forced his way into the Carvalho’s booth and ambushed him.


Secret Sanctions Revealed Against University Hosting $1.25 Billion Bio Lab

August 8th, 2015

Via: USA Today:

Kansas State University — where a controversial $1.25 billion biosecurity lab facility is under construction — secretly faced federal sanctions last year after repeatedly violating safety regulations during its research with bioterror pathogens, records obtained by USA TODAY show.

Kansas State’s “history of non-compliance” during four consecutive inspections over two years shows a “systemic problem” and has “raised serious concerns” about the university’s ability to put safeguards in place to ensure safety and containment of dangerous pathogens, according to a March 2014 letter to the university from federal lab regulators.

University officials said Tuesday they were surprised by the letter’s harsh tone and language because nearly all of the violations involved administrative paperwork issues that posed no safety or security threat. Yet in the letter, regulators threatened to suspend or revoke the university’s permits to do research with bioterror pathogens if it didn’t agree to enter a federal performance improvement program.

The regulatory action against Kansas State is of particular importance because the university’s campus in Manhattan is the site of the federal government’s new National Bio and Agro-Defense Facility (NBAF), which held a groundbreaking ceremony in May. Construction of the 570,000-square-foot facility has faced years of delays and controversy because of concerns about whether research on some of the world’s most dangerous agricultural diseases can be done safely in farm country and near herds of livestock.

Although the NBAF will be an independently run Department of Homeland Security facility when it opens around 2022, the university has publicized on its website that Kansas State’s labs already are being used to “jump-start” research that “will eventually transition” to the new federal facility. Transition research underway includes studies of Rift Valley fever, a mosquito-borne disease that can cause abortions in livestock and fatal infections in people; Japanese encephalitis, another mosquito-borne disease that can cause reproductive problems in pigs and serious and sometimes fatal brain infections in people; and Classical swine fever, a potentially deadly pig disease.


Windows 10 Is Possibly the Worst Spyware Ever Made

August 8th, 2015

Via: Network World:

The usual bumps of an OS launch are understandable and forgivable, but some of the terms of the end user service agreement for Windows 10 put the NSA to shame.

Microsoft is already getting heat after it was found that Windows 10 was being auto-downloaded to user PCs without warning, and more seriously, that it was using the Internet connections of Windows 10 users to deliver Windows 10 and updates to others.

But there are worse offenders. Microsoft’s service agreement is a monstrous 12,000 words in length, about the size of a novella. And who reads those, right? Well, here’s one excerpt from Microsoft’s terms of use that you might want to read:

We will access, disclose and preserve personal data, including your content (such as the content of your emails, other private communications or files in private folders), when we have a good faith belief that doing so is necessary to.

EFF, where are you?

The good news is you can opt out of that feature, but the bad news is it defaults to on. You have to go to the Settings and then open the Privacy applet, where you are greeted with 13 different screens to weed through. Most of the offenders are on the General tab, but you really should go through all tabs, such as what types of data each app on your system can access.

Related: Tweaks to Windows 10 Settings for Privacy (Get comfortable, this is going to take awhile…)


The No Download List

August 8th, 2015

Via: The Register:

Software export controls are being applied to blacklisted people as well as countries: and these controls apply to routine security packages such as freebie antivirus scanning software, as well as more sensitive technologies, El Reg has concluded.

We’ve come to this way of thinking after investigating why Reg reader Hasan Ali was blocked from downloading Sophos AV for Mac. A screenshot of the “computer says no” message can be seen below.

Ali brought the issue to our attention, complaining that Sophos had applied an “anti-Muslim name filter” that places hurdles in the way of his attempts to download the security software firm’s freebie Mac malware detection tool.

In response, Sophos said the filter was based on the International Denied Persons List and its use was routine procedure that it needed to follow in order to comply with various international export laws.


Typhoon Soudelor Kills 6 in Taiwan and Leaves Millions Without Power

August 8th, 2015

Via: New York Times:

A powerful typhoon pummeled Taiwan on Saturday, dumping rain, toppling trees and leaving millions without electricity as strong winds ripped across the island.

At least six people were killed, Taiwan’s Interior Ministry said, including in its count people who had died Thursday and Friday as the storm approached. Five people were reported missing, and more than 60 were injured, many by blowing debris, the ministry said.


NZ Milk Price Gapdown: Fonterra Slashes Farmgate Milk Price to $3.85

August 6th, 2015

Break even price for many farmers: $5.70.

Via: NZ Herald:

Fonterra – New Zealand’s biggest exporter – has lowered its farmgate milk price for 2015/6 to $3.85 a kg of milksolids, down from a previous forecast of $5.25 a kg.

The co-op said its forecast total payout for the 2015/6 season would be $4.25-$4.35 a kg, comprising the revised farmgate milk price and earnings per share of 40 to 50 cents, down from the previous year’s record payout of $8.50 a kg.

The lower farmgate milk price follows sharp falls in whole milk powder prices, which have plummeted by 51.4 per cent on Fotnerra’s GlobalDairyTrade platform since March this year.

Agriculture information provider, AgriHQ, estimates that a $1/kg drop in the milk price equates to about $2 billion less income for dairy farmers.

A price around $5.70 is regarded as breakeven for many farmers. Those with high debt from converting other farms to dairy are more vulnerable but banks have said they are working closely with them to avoid problems.


Electronic Frontier Foundation: Privacy Badger

August 6th, 2015

Looks good.

Via: EFF:

How is Privacy Badger different to Disconnect, Adblock Plus, Ghostery, and other blocking extensions?

Privacy Badger was born out of our desire to be able to recommend a single extension that would automatically analyze and block any tracker or ad that violated the principle of user consent; which could function well without any settings, knowledge, or configuration by the user; which is produced by an organization that is unambiguously working for its users rather than for advertisers; and which uses algorithmic methods to decide what is and isn’t tracking.

Although we like Disconnect, Adblock Plus, Ghostery and similar products (in fact Privacy Badger is based on the ABP code!), none of them are exactly what we were looking for. In our testing, all of them required some custom configuration to block non-consensual trackers. Several of these extensions have business models that we weren’t entirely comfortable with. And EFF hopes that by developing rigorous algorithmic and policy methods for detecting and preventing non-consensual tracking, we’ll produce a codebase that could in fact be adopted by those other extensions, or by mainstream browsers, to give users maximal control over who does and doesn’t get to know what they do online.


Idaho Sheriff Guarding U.S. Navy Veteran Against Federal Gun Confiscation

August 6th, 2015

Via: AP:

A group of residents in northern Idaho have lined outside a U.S. Navy veteran’s house to protest claims that federal officials are planning on confiscating the man’s weapons.

Idaho Republican state Rep. Heather Scott says the Veteran Affairs office has sent a letter to John Arnold of Priest River warning him that he cannot possess or purchase firearms.

Bonner County Sheriff Daryl Wheeler says he and his deputies will stand guard against any federal attempts to remove Arnold’s guns.


Britain: Police Investigate Child Sex Abuse Claims Against Former Prime Minister

August 6th, 2015

Via: CNN:

At least four UK police forces are independently investigating claims that include child sexual abuse involving the late British Prime Minister Edward Heath.

The allegations about Heath, who led a Conservative government from 1970 to 1974 and only left Parliament in 2001, have dominated UK newspaper headlines this week.

They come at a time when Britain has been rocked by a series of revelations involving the sexual abuse of children by public figures — including UK entertainer Jimmy Savile — and allegations that the British establishment may have sought to cover up historic abuse claims involving some former senior politicians.

Heath, the most senior figure to be investigated for child sex abuse allegations dating back decades, died in 2005 at age 89.

Police forces in Kent, Wiltshire, Hampshire and Jersey, an island in the English Channel, have now confirmed they are looking into claims involving the former Prime Minister.

A UK police watchdog, the Independent Police Complaints Commission, is also examining how Wiltshire Police handled an alleged claim of child sex abuse made in the 1990s.


« Previous PageNext Page »