Showing posts with label security. Show all posts
Showing posts with label security. Show all posts

Tuesday, November 27, 2012

GPU Energy video games as well as Breaking security passwords




Scientists in the Atlanta Technology Investigation Start, going through Rich Boyd, exposed which off-the-shelf GPU(the exact same energy from the images greeting card inside your computer) tend to be much better from breaking security passwords compared to formerly believed, based on BBC statement.



Character GPU need they had been within in a position to procedure huge levels of information concurrently. This particular technologies is actually usually accustomed to supply high-resolution three dimensional images within video games, however offers additional, much more frightening outcomes.



The majority of the GPU producers possess opened up their own systems make it possible for the actual supply doesn't to create programs to operate upon stronger cores, as well as among the findings associated with less-than-legal ideal with regard to this kind of technologies is really a brute-force breaking. Brute-force breaking demands screening just about all feasible combos associated with figures that may help to make the actual pass word, rather than taking a look at a summary of feasible phrases, referred to as AOS, assault book, au.



Contemporary GPUs tend to be powerful sufficient which actually pass word Boyd phone calls 7 figures, hopelessly inadequate UA from the possible from the GPU or even several GPUs employed in parallel. Obviously, including much more figures for that pass word may tremendously more difficult as well as hard in order to split utilizing brute-force. Boyd shows that a minimum of 12 characters(mixing amounts, characters or even symbols) that the information is actually secure.. right now.



There are several superb open up supply methods to produce as well as shop safe security passwords. The most popular is actually KeePass, that is obtainable free of charge upon numerous platforms(including Home windows, MacOS, Google android because KeePassDroid as well as IOS because MyKeePass ). KeePass may produce the arbitrary, safe security passwords as well as shop all of them within an encrypted data source.



[ BBC News by Engadget ]



Exactly what? You may even appreciate IOS four. 0. two, 3. two. two improvements Kill JailbreakMe Luka Dual- Mobile phones primary coming iFixit Droid two Teardown discloses the actual greatest, darkest secrets and techniques



Adhere to GeekTech upon Tweets or even Myspace, or even sign up for the



RSS OR ATOM.



Twitter







By way of: GPU: Energy video games as well as Breaking security passwords



Associated Publishing Research Outcome: h2>







Difficulty Antivirus, backup as well as Hacking Kinect



My personal close friend, Keith, that explains themself because "a recuperating physicist", authored a fascinating placement in order to weblog capital t...





Lenovo IdeaPad U260: Netbook computer Pounds, Energy associated with Laptop computer



Lenovo ultraportable Mon launched the actual pounds as well as energy netbook computer laptop computer. Lenovo IdeaPad U260 sports activities a lavish...


Monday, December 26, 2011

Merry Hackmas (not really)

While most technologists were busy yesterday drinking eggnog and trying out their new gadgets, others were busy hacking Stratfor, an intelligence news organization.  All the news outlets reported it was 'Anonymous', but now people are saying it was (apparently) Sabu from LulzSec.

(Frankly, I can't blame the news outlets for the error - I can't keep up with the drama of who's who any more. It's like a soap opera, really.)

Anyway, whomever it was, they hack into Stratfor, steal a bunch of credit card numbers of people who subscribe to the company's intelligence briefings, then a) post them on the internet and b) use the credit cards to make donations to charitable organizations.

I'm not really sure what the point of this is. Any of these donations will be returned, and all the credit card numbers will be canceled. Really this will just cost the credit card companies lots of money, which will just result in the average Joe/Joann having to pay higher fees. Exactly what people need in this economy.

I wish these hackers would do something useful with their time. Solve some problems on challenge.gov. Teach math and computer science to children. Help local governments have more up to date computer systems in order to help empower communities.

Anything, really. This is just a sad waste of tech brains.

Wednesday, July 6, 2011

Burn after reading

I received an unencrypted email yesterday which had in the title "CONFIDENTIAL AND PRIVATE". It also had instructions that if I were to print out its PDF attachment, I must shred it immediately after reading it.

Clearly we Computer Scientists are doing a bad job with public outreach here. So, hey, chance to educate.

Email is hardly ever secure. I say 'hardly ever' because it is possible to encrypt email, and it is also possible to send email on secure, closed networks, free from the pull of the internet sea.

But most of the average email your average person is sending is being sent in the clear, unencrypted. This is a lot like walking down the street holding a big sign with the contents of your email. Which is recorded by a camera. And a lot of people can watch the video at any point in the future. Also, the video is archived in a library 4ever*.

The metaphor of a paper postal letter may have made sense about 15-20 years ago, but it's no longer valid. A letter sent by physical mail is much harder for lots and lots of people to read, unless someone tampers with the mail, makes a photocopy, etc. It also had ephemerality - you really could burn it after reading.

I pretty much operate under the assumption that any determined person can read my email and all unencrypted files on my computer. I also assume any emails I send could end up being forwarded to others, printed out, or posted on some blog somewhere.  Err on the side of caution, and all.

--------
(*) Ok, except a library is a bad metaphor because it's not necessarily easy for people to find this video. (aka. "security through obscurity"). Nor is it necessarily around for ever, but it could be.

Monday, June 13, 2011

Secure your networks, this time with feeling!

I know I've said that my research area is not security, but you'd think I was lying with all my recent posts on these topics.

The IMF has now been hacked. (Apparently by a foreign government). I read this in the NY Times article -
Because the fund has been at the center of economic bailout programs for Portugal, Greece and Ireland — and possesses sensitive data on other countries that may be on the brink of crisis — its database contains potentially market-moving information. It also includes communications with national leaders as they negotiate, often behind the scenes, on the terms of international bailouts. Those agreements are, in the words of one fund official, “political dynamite in many countries.” It was unclear what information the attackers were able to access.
- and had two immediate thoughts:

1) How could it be unclear what information the attackers were able to access? Don't they have logs? And if the logs were vaporized, don't they have clever digital forensics experts who can figure out what happened?  This is the IMF for pete's sake.

2) All the data stored in these databases was encrypted with strong encryption, right? Oh, and all the traffic from client computers to the database was encrypted, right? And they keep a tight access control list, right? Right?

If you follow good practice to begin with, you don't have to worry quite as much when you're hacked. But so few organizations do, which is really depressing.

I used to bemoan the lack of good practice to friends who do work in this field, and they would chuckle and said, "Look, FCS, if you want to protect your data, write it on a slip of paper, burn the paper, dig a hole 10 feet deep, and put the ashes in the hole. Or better yet, don't write it down in the first place."

Yeah.

Friday, June 3, 2011

Female Computer Scientists FTW

In other security news this week, Google is claiming China orchestrated some major attacks against gmail users. No shock, but what I found interesting is that they were discovered by blogger and fellow female computer scientist Mila Parkour.

Kudos, Mila!

And this just in - apparently Sony! Soni! Soné! has been hacked again. With script kiddie SQL injection attacks. The PC World article says, "Sony seems to ignore compliance requirements and basic security best practices".

For shame, Soné, for shame. You should totally hire Mila to fix you up. After China I suspect a gaming network will be child's play.

Monday, May 30, 2011

And so it begins*

Remember I blogged a few months ago about RSA getting hacked? We are now seeing the first major repercussions of this - Lockheed Martin's attack last week is assumed to be due to this.

According to AP, "Lockheed Martin said in a statement that it detected the May 21 attack 'almost immediately' and took countermeasures. As a result, 'our systems remain secure; no customer, program or employee personal data has been compromised.'"

Color me unconvinced.

To be honest, I'm really shocked RSA didn't do a massive recall of all its fobs after it was attacked. It was negligent not to.

(*) There's your B5 reference, Scott!

Wednesday, April 27, 2011

Sony! Soni! Soné!

I am very disappointed in you.

You get hacked, have 77 million credit and debit card numbers stolen but wait one week before telling your customers. And now you face a class action lawsuit, a senator demanding answers, and possibly lots of "angry mums". (Watch out for those angry mums! Like Bob! Or is he a daisy?)

And, given your track record on security (i.e., installing rootkits on customer's machines), you're not really in a good place right now.

The right thing to have done would have been come clean initially. Be honest with your customers from the start - "We stored information we shouldn't have, we didn't encrypt your data, and it's all been stolen. Call your bank and change your debit and credit card numbers."

Other companies, please take note. Only store the data you need to. Tighten your existing controls.  Do not think yourself invulnerable, or something's gonna getcha, little Walter.

Friday, March 18, 2011

RSA hack - Trouble with a capital T

It seems RSA was hacked today. This means, if you use one of those nice little SecureID fobs to connect to your corporate server or bank, it may have been compromised.

This is a big deal. Using two-factor authentication is an industry gold standard, and RSA is one of the most prolific manufacturers of such fobs.

Securious has a nice write up of the fact vs. fiction surrounding the attack, including a note that this was an APT attack, not some random script kiddie in Germany.

I'm not trying to stir up panic here, but if you work with sensitive data, this might be a good time to add another layer of encryption on it*. There are lots of free solutions, like True Crypt, or if you're on a Mac the easiest thing to do is create a password protected disk image. Remember not to use the same password for your encrypted disk partition that you use for anything else (logging in, email, etc.). But also don't lose this password - if you do then your data is "irrevocably lost". Whee!

* Obviously all the "check with your (IT) doctor" disclaimers apply here.