Son of Blackbird: SR-72, Mach 6 Reconnaissance and Strike Drone
November 2nd, 2013I wonder if everyone in the U.S. will be on food stamps by the time this thing takes to the air:
Food banks across the country, stretched thin in the aftermath of the recession, are bracing for more people coming through their doors in the wake of cuts to the federal food stamp program.
Food stamp benefits to 47 million Americans were cut starting Friday as a temporary boost to the federal program comes to an end without new funding from a deadlocked Congress.
Via: Aviation Week:
Ever since Lockheed’s unsurpassed SR-71 Blackbird was retired from U.S. Air Force service almost two decades ago, the perennial question has been: Will it ever be succeeded by a new-generation, higher-speed aircraft and, if so, when?
That is, until now. After years of silence on the subject, Lockheed Martin’s Skunk Works has revealed exclusively to AW&ST details of long-running plans for what it describes as an affordable hypersonic intelligence, surveillance and reconnaissance (ISR) and strike platform that could enter development in demonstrator form as soon as 2018. Dubbed the SR-72, the twin-engine aircraft is designed for a Mach 6 cruise, around twice the speed of its forebear, and will have the optional capability to strike targets.
The One About BadBIOS
November 1st, 2013I’d make sure to consider skeptical views on this BadBIOS story:
Either it is an extremely limited piece of BIOS malware or it is occurring at the OS and escaping detection through previously unknown methods. Half the claims made regarding what it does (disabling registry editing, etc.) are so far from reasonable and possible with the BIOS it makes me facepalm. Point blank, these things are absolutely not possible, period. This is something going on at the OS level, the end.
Via: Arstechnica:
Three years ago, security consultant Dragos Ruiu was in his lab when he noticed something highly unusual: his MacBook Air, on which he had just installed a fresh copy of OS X, spontaneously updated the firmware that helps it boot. Stranger still, when Ruiu then tried to boot the machine off a CD ROM, it refused. He also found that the machine could delete data and undo configuration changes with no prompting. He didn’t know it then, but that odd firmware update would become a high-stakes malware mystery that would consume most of his waking hours.
In the following months, Ruiu observed more odd phenomena that seemed straight out of a science-fiction thriller. A computer running the Open BSD operating system also began to modify its settings and delete its data without explanation or prompting. His network transmitted data specific to the Internet’s next-generation IPv6 networking protocol, even from computers that were supposed to have IPv6 completely disabled. Strangest of all was the ability of infected machines to transmit small amounts of network data with other infected machines even when their power cords and Ethernet cables were unplugged and their Wi-Fi and Bluetooth cards were removed. Further investigation soon showed that the list of affected operating systems also included multiple variants of Windows and Linux.
“We were like, ‘Okay, we’re totally owned,'” Ruiu told Ars. “‘We have to erase all our systems and start from scratch,’ which we did. It was a very painful exercise. I’ve been suspicious of stuff around here ever since.”
In the intervening three years, Ruiu said, the infections have persisted, almost like a strain of bacteria that’s able to survive extreme antibiotic therapies. Within hours or weeks of wiping an infected computer clean, the odd behavior would return. The most visible sign of contamination is a machine’s inability to boot off a CD, but other, more subtle behaviors can be observed when using tools such as Process Monitor, which is designed for troubleshooting and forensic investigations.
Another intriguing characteristic: in addition to jumping “airgaps” designed to isolate infected or sensitive machines from all other networked computers, the malware seems to have self-healing capabilities.
“We had an air-gapped computer that just had its [firmware] BIOS reflashed, a fresh disk drive installed, and zero data on it, installed from a Windows system CD,” Ruiu said. “At one point, we were editing some of the components and our registry editor got disabled. It was like: wait a minute, how can that happen? How can the machine react and attack the software that we’re using to attack it? This is an air-gapped machine and all of a sudden the search function in the registry editor stopped working when we were using it to search for their keys.”
Over the past two weeks, Ruiu has taken to Twitter, Facebook, and Google Plus to document his investigative odyssey and share a theory that has captured the attention of some of the world’s foremost security experts. The malware, Ruiu believes, is transmitted though USB drives to infect the lowest levels of computer hardware. With the ability to target a computer’s Basic Input/Output System (BIOS), Unified Extensible Firmware Interface (UEFI), and possibly other firmware standards, the malware can attack a wide variety of platforms, escape common forms of detection, and survive most attempts to eradicate it.
But the story gets stranger still. In posts here, here, and here, Ruiu posited another theory that sounds like something from the screenplay of a post-apocalyptic movie: “badBIOS,” as Ruiu dubbed the malware, has the ability to use high-frequency transmissions passed between computer speakers and microphones to bridge airgaps.
Slow and Steady Progress Toward Lethal Autonomous Robots
October 31st, 2013This piece is a good summary of what’s happening in the field of military robotics. I’m pretty sure that all of the systems here have been covered separately on Cryptogon.
Via: Vocativ:
There are important differences between drones, landmines, and “killer robots” — the more serious term being “fully autonomous weapon,” or “lethal autonomous weapon” as the UN puts it.
Landmines are automatic rather than autonomous — laid as a trap, detonated by an unwary foot. Drones are remotely piloted by humans. But killer robots can both select their targets, and engage in violent force, completely outside of human control. Development and testing of these weapons are a precursor to a much different kind of warfare.
“So basically the machine is making a decision to kill, and that’s the problem we have with it,” Wareham said. “We don’t think that power should be given over to a machine. We want to see a human always in the loop.”
Related: Siri, Have Those People Killed
Research Credit: pookie
RBS Traders Suspended in Forex Probe
October 31st, 2013Via: BBC:
Royal Bank of Scotland (RBS) has suspended two traders in connection to a growing investigation into the possible manipulation of foreign exchange rates.
The news follows reports that London-based executives at three other major banks have been placed on leave.
Regulators in the UK, US and Switzerland are looking into whether banks colluded to set exchange rates.
The global foreign exchange market is worth more than £3tn a day.
London is the most important centre for the market, accounting for about 40% of all foreign exchange trading.
The reports are that executives at Citigroup, JP Morgan and Standard Chartered have agreed to be placed on leave, but none has been accused of any wrongdoing.
$30,000 Prosthetic Hand vs. One Made with a 3D Printer for $5
October 31st, 2013Via: Mish:
What do you do when you cannot afford a $30,000 prosthetic hand that your son needs?
Two years ago, Paul McCarthy began searching for an inexpensive yet functional prosthetic hand for his son Leon, who was born without fingers on one of his hands.
McCarthy came across a video online with detailed instruction on how to use a 3-D printer to make a prosthetic hand for his son. McCarthy made a prosthetic hand for his son for a cost of $5 and free time on a 3D printer.
Research Credit: alvinroasting
MIT Thermoelectric Bracelet: “Personalized, Dynamic Climate Control”
October 31st, 2013Via: Wired:
Wristify, as they call their device, is a thermoelectric bracelet that regulates the temperature of the person wearing it by subjecting their skin to alternating pulses of hot or cold, depending on what’s needed.
Cryptogon Readers Send Contributions in October
October 31st, 2013Thank you.
Eileen $104
KL $25
TM $15
MW $25
iWholeSale NZ$5
SSL Added and Removed Here! :)
October 30th, 2013And if they rely on SSL, well, that’s ok for buying a book online, but no tinfoiler in his right mind would bet his life on SSL.
—The Ugly Truth About Online Anonymity
What’s the difference between Paranoid Conspiracy Theorist and I told You So?
About six years.
Via: Washington Post:
The National Security Agency has secretly broken into the main communications links that connect Yahoo and Google data centers around the world, according to documents obtained from former NSA contractor Edward Snowden and interviews with knowledgeable officials.
By tapping those links, the agency has positioned itself to collect at will from hundreds of millions of user accounts, many of them belonging to Americans. The NSA does not keep everything it collects, but it keeps a lot.
According to a top-secret accounting dated Jan. 9, 2013, the NSA’s acquisitions directorate sends millions of records every day from Yahoo and Google internal networks to data warehouses at the agency’s headquarters at Fort Meade, Md. In the preceding 30 days, the report said, field collectors had processed and sent back 181,280,466 new records — including “metadata,” which would indicate who sent or received e-mails and when, as well as content such as text, audio and video.
The NSA’s principal tool to exploit the data links is a project called MUSCULAR, operated jointly with the agency’s British counterpart, the Government Communications Headquarters . From undisclosed interception points, the NSA and the GCHQ are copying entire data flows across fiber-optic cables that carry information between the data centers of the Silicon Valley giants.
The infiltration is especially striking because the NSA, under a separate program known as PRISM, has front-door access to Google and Yahoo user accounts through a court-approved process.
The MUSCULAR project appears to be an unusually aggressive use of NSA tradecraft against flagship American companies. The agency is built for high-tech spying, with a wide range of digital tools, but it has not been known to use them routinely against U.S. companies.
…
In an NSA presentation slide on “Google Cloud Exploitation,” however, a sketch shows where the “Public Internet” meets the internal “Google Cloud” where their data reside. In hand-printed letters, the drawing notes that encryption is “added and removed here!” The artist adds a smiley face, a cheeky celebration of victory over Google security.
Two engineers with close ties to Google exploded in profanity when they saw the drawing. “I hope you publish this,” one of them said.
…
For the MUSCULAR project, the GCHQ directs all intake into a “buffer” that can hold three to five days of traffic before recycling storage space. From the buffer, custom-built NSA tools unpack and decode the special data formats that the two companies use inside their clouds. Then the data are sent through a series of filters to “select” information the NSA wants and “defeat” what it does not.
Northrop Grumman, Lockheed Martin to Develop Pod-Mounted Aircraft and UAV Laser Defenses
October 30th, 2013Via: Military and Aerospace Electronics:
U.S. military researchers are hiring two defense companies to develop technology for pod-mounted laser weapons to protect manned aircraft and unmanned aerial vehicles (UAVs) from electro-optical and infrared (EO/IR)-guided surface-to-air missiles.
Officials of the U.S. Defense Advanced Research Projects Agency are choosing the Northrop Grumman Corp. Aerospace Systems segment in Redondo Beach, Calif., and the Lockheed Martin Mission Systems and Training segment in Akron, Ohio, for Project Endurance to develop laser weapons to defend aircraft from missiles.
People Who Live Downwind of Alberta’s Oil and Tar Sands Operations Are Getting Blood Cancer
October 30th, 2013Via: Think Progress:
A new study has found that levels of air pollution downwind of the largest tar sands, oil and gas producing region in Canada rival levels found in the world’s most polluted cities. And that pollution isn’t just dirtying the air — it also could be tied increased incidence of blood cancers in men that live in the area.
The study, published last week by researchers from University of California Irvine and the University of Michigan, found levels of carcinogenic air pollutants 1,3-butadiene and benzene spiked in the Fort Saskatchewan area, which is downwind of the oil and tar sands-rich “Industrial Heartland” of Alberta. Airborne levels of 1,3-butadiene were 322 times greater downwind of the Industrial Heartland — which houses more than 40 major chemical, petrochemical and oil and gas facilities — than upwind, while downwind levels of benzene were 51 times greater. Levels of some volatile organic compounds — which, depending on the compound, have been linked to liver, kidney and central nervous system damage as well as cancer — were 6,000 times higher than normal. The area saw concentrations of some chemicals that were higher than levels in Mexico City during the 1990s, when it was the most polluted city on the planet.


