Oct 24

Filed under:

Princeton publishes how-to guide for hacking Sequoia e-voting machines

If you’re American, it’s nearly time to do your civic duty and pick the lesser of two evils for the greater good… and then to wonder if that vote actually got counted. With Diebold admitting its own machines are utterly insecure, competitor Sequoia is now under the microscope and, after a little quality time with the company’s machines, Princeton researchers have filed a 158 page report on the ease of replacing their ROMs and winning yourself an election. Okay, we know what you’re thinking: “Hacking hardware isn’t exactly easy when the computer is in a locked box.” Amazingly, it is. A researcher was able to bypass the physical security mechanisms in 13 seconds, despite never having picked a lock before. Now you’re thinking: “But you’d need to do that on hundreds of them!” Not so; once infected that malicious code can spread itself to others, and, with no paper trail and an easily bypassed internal audit system, you’re well on your way to whatever dark corner of Washington, D.C. you care to occupy!

[Via Ars Technica]

Read | Permalink | Email this | Comments

Source: Tim Stevens

written by

Oct 10

Filed under:

We find it hard to believe that we won’t see one of these being used somewhere in the upcoming 007 film, but even if not, you can definitely put one to use in your everyday life — if you can get ahold of one of the ten being made, that is. Srulirecht’s DÆmdur is a Kevlar-based handkerchief which can keep your schnoz squeaky clean and (in theory, at least) keep your chest free from bullets. Granted, even the manufacturer makes clear that it takes no responsibility for “schmucks and wooden-heads who feel compelled to test the endurance or resistance of the textile in any way,” but it sure beats those cotton ones you buy ten to a pack.

[Via OhGizmo]

Read | Permalink | Email this | Comments

Source: Darren Murph

written by

Oct 10

Filed under:

Call us devilish, but we just can’t help but love these types of stories. Here we have yet another overly confident group of researchers grossly underestimating the collective power of the hacking underground, as gurus from all across Europe have joined together to announce “the first commercial communication network using unbreakable encryption based on quantum cryptography.” Interestingly enough, quantum cryptography has already been cracked in a kinda-sorta way, but that’s not stopping these folks from pushing this claim hard to government agencies, financial institutions and companies with distributed subsidiaries. We’ve no doubt this stuff is pretty secure, but the last time we heard someone utter a claim similar to this, we saw him uncomfortably chowing down on those very words merely months later.

[Via Physorg]

Read | Permalink | Email this | Comments

Source: Darren Murph

written by

Sep 21

Filed under:

If you had any urge whatsoever to try to your hand at drug trafficking over water while these “weird” economic times sort themselves out, uh, you may want to reevaluate your options. The ever-so-stealthy Stiletto has come to life after tracking down a remarkably quick drug-running boat near Florida; the bad guys were cruising at 42 knots, but that comic book-esque thing you’re undoubtedly peering at above can reach speeds of up to 60 knots. The double-M-shaped hull enables it to navigate in extraordinarily shallow waters without trouble, and a plethora of sensors and radars give it all the power it needs to track down goons. Oddly enough, it’s having a somewhat difficult time finding a government agency to truly call home, but if it continues to keep the coke out of our seas, we’d say it’ll win over some hearts soon enough.

[Thanks, Laz]

Read | Permalink | Email this | Comments

Source: Darren Murph

written by

Jul 29

Filed under:

Datto earned a round of golf claps with its Backup NAS by bringing comparatively affordable off-site storage to the small businesses of the world, but it’s giving itself a round of applause with the Z Series. Hailed as the “planet’s first on and off-site backup solution to use ZFS,” these units provide up to 1TB of local and off-site storage, optional RAID 1 local redundancy, twin gigabit Ethernet ports, OS X / Windows / Linux compatibility and the obligatory rock-solid stability that ZFS is known for. You’ll also get a rapid recovery promise, which enables you to sleep easy knowing that your data can be restored within 24 hours should disaster strike. The units range in capacity from 250GB ($499) to 1TB ($1,149), while the required service packages demand anywhere between $35 per month to $1,000 a year.

Read | Permalink | Email this | Comments

Source: Darren Murph

written by

Jul 01

Filed under:

Blizzard Authenticator

Nothing’s worse than when you log on to raid Onyxia only to find that some loser sold all your elite loot. Fear not, vulnerable World of Warcraft denizens, for Blizzard is here to sell you the $6.50 “Blizzard Authenticator” dongle. Reacting to an upswing in account theft incidents, Blizzard has released a security token that allows hardcore users to add another layer of protection to their high-level (and attractive) characters. The device is basically a SecurID token with a six-digit code that you’ll need to keep with you any time you want to get your groove on in Azeroth. By the way, we dare you to put this on your keychain and wear it with pride.

Read | Permalink | Email this | Comments

Source: Joshua Fruhlinger

written by

Mar 06

Filed under: ,

Oh yeah, we’ve seen GPS devices intended to sit secretively within the confines of a motorcar and beam back real-time tracking data to the powers that be, but typically, they’re fairly subtle about their purpose. Not so with the brashly named GPS Snitch, which makes no bones about its intentions of helping you catch that unfaithful SO or your rebellious teenager. As expected, this unit simply hides within one’s vehicle and can notify administrators via SMS / e-mail as soon as motion is detected or a pre-determined perimeter is exceeded. Additionally, you can track the vehicle’s progress through BlackLine’s website, and just in case the week of battery life isn’t enough, it can be hardwired to the car battery for logging extra long road trips. Ready to quell your suspicions? Grab one now for $399 plus applicable service plan fees.

 

Read | Permalink | Email this | Comments


Source: Darren Murph

written by

Mar 04

Filed under: ,

All of the sudden we’re starting to see more and more attacks take advantage of what’s stored on your computer’s RAM — the latest, from New Zealand’s Adam Boileau, allows an attacker to unlock Windows passwords in a just a few seconds using a Linux machine connected over Firewire. Unlike those disk encryption attacks we saw that required a reboot, Boileu’s attack works while the target computer is running, tricking Windows into allowing full write access to RAM and then corrupting the password protection code. That’s a little scary — but other researchers say that it’s not a traditional vulnerability, since direct memory access is a feature of Firewire. Still, we’re sealing up all of our ports with Silly Putty starting today, that ought to stop ‘em.

[Thanks, Drew]

 

Read | Permalink | Email this | Comments


Source: Nilay Patel

written by