attack
It’s An Attack On Microsoft’s Last Line Of Defense (GOOG)

Google announced yesterday that it is going to start charging all businesses that want to use Google Apps – Google’s online version of Microsoft Windows.
Previously, Google Apps had been free to use for businesses smaller than 10 people.
This news might mean that Google is sick of flushing money down rat hole and finally wants to cover its cost, despite the reduction in usage this will cause.
But it also might mean Google is about to take Apps development a whole lot more seriously. It might Google is going to start trying to make Google Apps something that all businessess find worth paying for.
If that’s the case, it has to make Microsoft nervous.
Microsoft is in a very precarious place at the moment.
It’s just released a new operating system that’s very different from its old one.
The new operating system forces enterprises and consumers around into a choice: what kind of new OS do they adopt?
In years past, there was really only one choice: Microsoft.
But now, consumers are bringing their iOS devices and Android devices to work. They’re used to them. They love them. Meanwhile, consumers are not rushing out to buy Microsoft’s new tablet, Surface.
So now, enterprises have three choices: Microsoft, Google, or Apple.
The big advantage! Microso ft has had for years now is that its software suite for doing business, Microsoft Office, is far superior to anything Google or Apple had to offer.
But if Google is going to charge all clients for its Office clone, that might mean it is about to take Apps development a whole lot more seriously.
Maybe Google will finally build a real rival to Microsoft office’s crown jewel, Excel.
Please follow SAI: Enterprise on Twitter and Facebook.
Join the conversation about this story »
The security PIN system that Google Wallet users have to enter to verify transactions has been compromised. Thankfully, the chances of your wallet being used against you is relatively low—assuming you haven’t rooted your phone, that is.
Since Wallet saves your PIN in an encrypted file on the phone itself, rather than the secured NFC chip, if your phone falls into the wrong hands, that person could lift your PIN file from the phone and simply crack it using brute force. From there, he’d have access to—and use of—your Wallet account.
Security firm, Zvelo, discovered and reported the issue to Google, but because Wallet’s security architecture, the change will require a fundamental rejiggering of the security protocols. Man, talk about an oversight. According to Zvelo,
The lynch-pin, however, was that within the PIN information section was a long integer “salt” and a SHA256 hex encoded string “hash”. Knowing that the PIN can only be a 4-digit numeric value, it dawned on us that a brute-force attack would only require calculating, at most, 10,000 SHA256 hashes…This completely negates all of the security of this mobile phone payment system.
So, if you are rooted, be sure to take some additional security steps to protect yourself like activating the lock screen, disabling the USB debugging option in settings, and enabling full-disk encryption. Or maybe not losing your phone in the first place. [Zvelo via Android Central via The Verge]
Source: http://gizmodo.com/5883585/google-wallets-pin-system-has-been-cracked-but-dont-panic-just-yet
The security PIN system that Google Wallet users have to enter to verify transactions has been compromised. Thankfully, the chances of your wallet being used against you is relatively low—assuming you haven’t rooted your phone, that is.
Since Wallet saves your PIN in an encrypted file on the phone itself, rather than the secured NFC chip, if your phone falls into the wrong hands, that person could lift your PIN file from the phone and simply crack it using brute force. From there, he’d have access to—and use of—your Wallet account.
Security firm, Zvelo, discovered and reported the issue to Google, but because Wallet’s security architecture, the change will require a fundamental rejiggering of the security protocols. Man, talk about an oversight. According to Zvelo,
The lynch-pin, however, was that within the PIN information section was a long integer “salt” and a SHA256 hex encoded string “hash”. Knowing that the PIN can only be a 4-digit numeric value, it dawned on us that a brute-force attack would only require calculating, at most, 10,000 SHA256 hashes…This completely negates all of the security of this mobile phone payment system.
So, if you are rooted, be sure to take some additional security steps to protect yourself like activating the lock screen, disabling the USB debugging option in settings, and enabling full-disk encryption. Or maybe not losing your phone in the first place. [Zvelo via Android Central via The Verge]
DoJ, RIAA, MPAA, and Universal Music All Offline [Hackers]
Source: http://gizmodo.com/5877679/anonymous-kills-department-of-justice-site-in-megaupload-revenge-strike
Anonymous has sure been quiet lately, but today’s federal bust of Megaupload riled ‘em up good: a retaliatory strike against DoJ.gov (and plenty of other foes) leaving them completely dead.
DownForEveryoneOrJustMe.com is reporting the department’s site as universally nuked, and an Anonymous-affiliated Twitter account is boasting success. This is almost certainly the result of a quickly-assembled DDoS attack—and easily the widest in scope and ferocity we’ve seen in some time. If you had any doubts Anonymous is still a hacker wrecking ball, doubt no more.
The combination of the hacking nebula’s SOPA animosity—they’ve been a vocal opponent of the bill since its inception—combined with today’s sudden Megaupload news has made the group bubble over: hundreds upon hundreds of Anon operatives are in a plotting frenzy, chatting about which site will go down next. In Anon’s eyes, the government and media interests are responsible for the undue destruction of Megaupload (and the arrest of four of its operators), so it’ll be exactly those entities that’re feeling the pain right now. Pretty much every company that makes movies, TV, or music, along with the entirety of the federal government, is in Anonymous’ crosshairs.
Update: Anonymous says they’ve also knocked off the RIAA’s site—looks down for us at the moment as well.
Update 2: Universal Music Group has also fallen off an e-cliff.
Update 3: Goodbye for now, MPAA.org.
Update 4: Affected sites are bouncing in and out of life, and are at the very least super slow to load. Anon agents are currently trying to coordinate their DDoS attacks in the same direction via IRC.
Update 5: The US Copyright Office joins the list.
Update 6: This Anon sums up the mood in their “official” chat room at the moment:
Danzu: STOP EVERYTHING, who are we DoSing right now?
Update 7: Russian news service RT claims this is the largest coordinated attack in Anonymous’ history—over 5,600 DDoS zealots blasting at once.
Update 8: the Anonymous DDoS planning committee is chittering so quickly, it’s making my laptop fan spin.
Update 9: Major record label EMI is down for the count.
Update 10: La résistance est international—French copyright authority HADOPI bites the dust under Anon pressure.
Update 11: The Federal Bureau of Investigation has fallen and can’t get up.
Update 12: Anonymous has released a statement about today’s attacks.
—
drag2share – drag and drop RSS news items on your email contacts to share (click SEE DEMO)
#whentwitterwasdown – Twitter crippled by massive #ddos (distributed denial of service) attack
As many of you may have noticed, Twitter was down for many hours starting Thursday morning August 6 and remained intermittent even when it was brought back up. The theory is that this was caused by a massive DDOS attack on their servers including the services that other web applications depended on — that means that outside services (twitter applications) were also taken down.
For an explanation of denial-of-service attack or distributed-denial-of-service, this is the wikipedia entry. It basically is an attacker using a large number of “zombie” computers to “hit” the victim’s site at the same time, thus overloading it, and causing it to not be able to respond to legitimate traffic.

Full Coverage of the Social Media DDoS (Source: Mashable)
–Is Cyber Warfare to Blame for Twitter Meltdown?
–Denial of Service Attacks Being Investigated by Google, Twitter, Facebook
–Facebook Problems Also the Result of DDoS Attack
–Twitter Outage Explained: What’s a Distributed Denial of Service Attack (DDoS)?
–Twitter Down Due to Denial of Service Attack (DDoS)
Digital Consigliere
Tags
Popular Posts
- Netflix vs Blockbuster - Perfect example of an industry replaced by a more efficient version of itself
- Coke vs Pepsi vs Dr Pepper
- Marketing Costs Normalized to CPM Basis for Comparison
- 3G calling, no registration, and totally free
- The Top Endorsement Earners In Each Sport
- AOL's Plan To Steal TV Ad Dollars Is Totally Working
- drag2share: The Most Pinned Brand On Pinterest Doesn't Even Use A Pinterest Account [THE BRIEF]
- Groupon launches Breadcrumb iPad app, vows to not be a typical POS
- HP Mini 311 Nvidia ION Netbook Hackintosh'ed
Published Articles by Dr. Augustine Fou
- #SESNY: Toward a Performance Mindset for All Advertising
- Tips for Marketers Selecting a Digital Agency
- Context Is Not King or Queen; It's Just Necessary
- 2013 New Year's Digital Marketing Resolutions
- The Good, Bad, and Ugly of Online Campaign Ratings and eGRPs
- Why You Should Banish the Net Promoter Score Immediately
- Digital Strategy To-MAY-to vs. To-MAH-to
- The Agency-Client Relationship is Forever Changed
- Targeting vs. Privacy - Who Will Win?
- Digital + Traditional = Unified Marketing
Pages
Archives
- May 2013 (66)
- April 2013 (70)
- March 2013 (114)
- February 2013 (89)
- January 2013 (136)
- December 2012 (96)
- November 2012 (130)
- October 2012 (147)
- September 2012 (94)
- August 2012 (92)
- July 2012 (112)
- June 2012 (71)
- May 2012 (82)
- April 2012 (80)
- March 2012 (122)
- February 2012 (114)
- January 2012 (129)
- December 2011 (60)
- November 2011 (54)
- October 2011 (29)
- September 2011 (17)
- August 2011 (30)
- July 2011 (18)
- June 2011 (19)
- May 2011 (23)
- April 2011 (23)
- March 2011 (52)
- February 2011 (69)
- January 2011 (108)
- December 2010 (82)
- November 2010 (67)
- October 2010 (68)
- September 2010 (44)
- August 2010 (101)
- July 2010 (61)
- June 2010 (28)
- May 2010 (28)
- April 2010 (26)
- March 2010 (33)
- February 2010 (21)
- January 2010 (12)
- December 2009 (4)
- November 2009 (2)
- October 2009 (14)
- September 2009 (6)
- August 2009 (19)
- July 2009 (34)
- June 2009 (11)
- May 2009 (4)
- April 2009 (6)
- March 2009 (13)
- February 2009 (32)
- January 2009 (25)
- December 2008 (1)
- October 2008 (1)
- June 2008 (1)
- November 2007 (1)
Prototype Web Services
- drag2share – quickly share news items by drag and drop on email addresses
- LivePhotoFrame – upload and remotely manage a digital photo frame via unique URL
- MedleyTuner – create a continuous listening experience by uploading mp3s
- MusicSamplr – discover new artists and music, listen to samples
- SharedMost – what links on ANY webpage are shared most?
- Signatory – sign and date a document and verify it hasn't been altered since that exact time.
- WebTeleprompter – just what it says it is

