force
Source: http://gizmodo.com/5883585/google-wallets-pin-system-has-been-cracked-but-dont-panic-just-yet
The security PIN system that Google Wallet users have to enter to verify transactions has been compromised. Thankfully, the chances of your wallet being used against you is relatively low—assuming you haven’t rooted your phone, that is.
Since Wallet saves your PIN in an encrypted file on the phone itself, rather than the secured NFC chip, if your phone falls into the wrong hands, that person could lift your PIN file from the phone and simply crack it using brute force. From there, he’d have access to—and use of—your Wallet account.
Security firm, Zvelo, discovered and reported the issue to Google, but because Wallet’s security architecture, the change will require a fundamental rejiggering of the security protocols. Man, talk about an oversight. According to Zvelo,
The lynch-pin, however, was that within the PIN information section was a long integer “salt” and a SHA256 hex encoded string “hash”. Knowing that the PIN can only be a 4-digit numeric value, it dawned on us that a brute-force attack would only require calculating, at most, 10,000 SHA256 hashes…This completely negates all of the security of this mobile phone payment system.
So, if you are rooted, be sure to take some additional security steps to protect yourself like activating the lock screen, disabling the USB debugging option in settings, and enabling full-disk encryption. Or maybe not losing your phone in the first place. [Zvelo via Android Central via The Verge]
Source: http://gizmodo.com/5883585/google-wallets-pin-system-has-been-cracked-but-dont-panic-just-yet
The security PIN system that Google Wallet users have to enter to verify transactions has been compromised. Thankfully, the chances of your wallet being used against you is relatively low—assuming you haven’t rooted your phone, that is.
Since Wallet saves your PIN in an encrypted file on the phone itself, rather than the secured NFC chip, if your phone falls into the wrong hands, that person could lift your PIN file from the phone and simply crack it using brute force. From there, he’d have access to—and use of—your Wallet account.
Security firm, Zvelo, discovered and reported the issue to Google, but because Wallet’s security architecture, the change will require a fundamental rejiggering of the security protocols. Man, talk about an oversight. According to Zvelo,
The lynch-pin, however, was that within the PIN information section was a long integer “salt” and a SHA256 hex encoded string “hash”. Knowing that the PIN can only be a 4-digit numeric value, it dawned on us that a brute-force attack would only require calculating, at most, 10,000 SHA256 hashes…This completely negates all of the security of this mobile phone payment system.
So, if you are rooted, be sure to take some additional security steps to protect yourself like activating the lock screen, disabling the USB debugging option in settings, and enabling full-disk encryption. Or maybe not losing your phone in the first place. [Zvelo via Android Central via The Verge]
Source: http://gizmodo.com/5882546/us-military-to-get-secure-android-handsets
In a war zone, a standard mobile phone, with its countless possible security flaws, is no use — which is why the military doesn’t rely on them. But now that’s changing, as the US military is investing in secure Android handsets.
It’s not the first time we’ve heard about the army handing out smart phones — hell, they even run competitions to develop apps. But CNN is reporting that the US military is, after two years of testing, intending to “install its custom software on commercially available phones.” It’s starting out with a custom modification of Android’s kernel. The ideas is to give fine-grained control over data, applications and information transmission, as well as providing officials with detailed usage feedback.
Interestingly, this looks set not just to be limited to the military, as CNN reports that “each version of the Android OS [will] be certified once for all federal agencies”, suggesting that these new secure Android handsets may become standard issue across the whole of the US government. That would be bad news for BlackBerry, because RIM currently provides most federal phones — even Obama’s. The new secure handsets are to be shipped out to soldiers by March for testing. [CNN; Image: U.S. Air Force]
Here’s A Sneak Peek At Netflix’s First Big Bet On Original Programming (NFLX)
Source: http://www.businessinsider.com/netflix-original-series-lilyhammer-2012-1
Netflix has been talking up their new original programming quite a bit, and now they’ve actually released some footage.
“Lilyhammer” tells the story of an East Coast mobster, played by “The Sopranos” actor Steven Van Zandt, who’s relocated to a small town in Norway as part of the witness protection program.
Unlike most TV shows, you’ll be able to see all eight episodes of “Lilyhammer” at once — Netflix is putting the whole series online February 6.
This seems to be a risky strategy: shows often build buzz over the course of the season, especially with a new series, and if “Lilyhammer” doesn’t catch on immediately it could have a hard time building viewership.
Netflix might be counting on a viral audience, with subscribers passing it between each other and telling their friends they need to see it. If that’s the case, it better be good.
Please follow SAI: Media on Twitter and Facebook.
Join the conversation about this story »
See Also:
- This Could Be Part Of The Reason Iran Is So Darn Defensive
- PRESENTING: The Invisible Force That’s Saving The US Economy
- Oregon’s Rose Bowl Helmet Is Even More Sparkly Than We Feared
—
drag2share – drag and drop RSS news items on your email contacts to share (click SEE DEMO)
Another predictable failure — the .xxx top-level domain
Despite the creation of the .xxx top-level domain (TLD), no one will use it. Porn purveyors will not use it for sure because they want to avoid parental control software which can easily block the entire TLD. And regular citizens won’t know to type it in or will simply add a .com after it because of force of habit. This is a perfect example of a lot of work that went into creating something that no one will use.
Source: http://lifehacker.com/5572900/icann-approves-xxx-porn-domain
A new top-level porn domain, XXX (e.g., http://pornexample.xxx), was approved today by ICANN, the non-profit organization responsible for managing the assignment of domain names and approval of new top-level domains like .com, .org, and so on. This doesn’t mean that all porn sites will leave their current cushy URLs for XXX, but it’ll be an easy block for concerned parents. [PC World]
1024-bit RSA encryption cracked by carefully starving CPU of electricity
Source: http://www.engadget.com/2010/03/09/1024-bit-rsa-encryption-cracked-by-carefully-starving-cpu-of-ele/
Since 1977, RSA public-key encryption has protected privacy and verified authenticity when using computers, gadgets and web browsers around the globe, with only the most brutish of brute force efforts (and 1,500 years of processing time) felling its 768-bit variety earlier this year. Now, three eggheads (or Wolverines, as it were) at the University of Michigan claim they can break it simply by tweaking a device’s power supply. By fluctuating the voltage to the CPU such that it generated a single hardware error per clock cycle, they found that they could cause the server to flip single bits of the private key at a time, allowing them to slowly piece together the password. With a small cluster of 81 Pentium 4 chips and 104 hours of processing time, they were able to successfully hack 1024-bit encryption in OpenSSL on a SPARC-based system, without damaging the computer, leaving a single trace or ending human life as we know it. That’s why they’re presenting a paper at the Design, Automation and Test conference this week in Europe, and that’s why — until RSA hopefully fixes the flaw — you should keep a close eye on your server room’s power supply.
1024-bit RSA encryption cracked by carefully starving CPU of electricity originally appeared on Engadget on Tue, 09 Mar 2010 02:47:00 EST. Please see our terms for use of feeds.
Permalink
p://www.theregister.co.uk/2010/03/04/severe_openssl_vulnerability/“>The Register, TechWorld |
University of Michigan | Email this | Comments
Another day, another story about some cheap, plastic Wii motion control accessory finding an application outside of gaming. In this case, it’s the balance board, and not only is this device helping stroke victims recover, it’s saving them money, too.
In fact, doctors at the University of Melbourne found that the balance board, normally used for pseudo Yoga or navigating Mii’s down a virtual ski slope, was so sensitive it could very well replace traditional laboratory-grade “force platforms” doctors use to assess a patient’s balance.
When doctors disassembled the board, they found the accelerometers and strain gauges to be of “excellent” quality. “I was shocked given the price: it was an extremely impressive strain gauge set-up,” said lead researcher Ross Clark, in an interview with New Scientist.
Even better, Clark’s team has already published a paper that verifies the Wii balance board is “clinically comparable” to the nearly $18,000 lab force platform. That’s great news for many smaller physio clinics that would otherwise be unable to afford the traditional rig. [New Scientist]
Digital Consigliere
Tags
Popular Posts
- Netflix vs Blockbuster - Perfect example of an industry replaced by a more efficient version of itself
- Coke vs Pepsi vs Dr Pepper
- Marketing Costs Normalized to CPM Basis for Comparison
- 3G calling, no registration, and totally free
- AOL's Plan To Steal TV Ad Dollars Is Totally Working
- The Top Endorsement Earners In Each Sport
- drag2share: The Most Pinned Brand On Pinterest Doesn't Even Use A Pinterest Account [THE BRIEF]
- Groupon launches Breadcrumb iPad app, vows to not be a typical POS
- HP Mini 311 Nvidia ION Netbook Hackintosh'ed
Published Articles by Dr. Augustine Fou
- #SESNY: Toward a Performance Mindset for All Advertising
- Tips for Marketers Selecting a Digital Agency
- Context Is Not King or Queen; It's Just Necessary
- 2013 New Year's Digital Marketing Resolutions
- The Good, Bad, and Ugly of Online Campaign Ratings and eGRPs
- Why You Should Banish the Net Promoter Score Immediately
- Digital Strategy To-MAY-to vs. To-MAH-to
- The Agency-Client Relationship is Forever Changed
- Targeting vs. Privacy - Who Will Win?
- Digital + Traditional = Unified Marketing
Pages
Archives
- May 2013 (64)
- April 2013 (70)
- March 2013 (114)
- February 2013 (89)
- January 2013 (136)
- December 2012 (96)
- November 2012 (130)
- October 2012 (147)
- September 2012 (94)
- August 2012 (92)
- July 2012 (112)
- June 2012 (71)
- May 2012 (82)
- April 2012 (80)
- March 2012 (122)
- February 2012 (114)
- January 2012 (129)
- December 2011 (60)
- November 2011 (54)
- October 2011 (29)
- September 2011 (17)
- August 2011 (30)
- July 2011 (18)
- June 2011 (19)
- May 2011 (23)
- April 2011 (23)
- March 2011 (52)
- February 2011 (69)
- January 2011 (108)
- December 2010 (82)
- November 2010 (67)
- October 2010 (68)
- September 2010 (44)
- August 2010 (101)
- July 2010 (61)
- June 2010 (28)
- May 2010 (28)
- April 2010 (26)
- March 2010 (33)
- February 2010 (21)
- January 2010 (12)
- December 2009 (4)
- November 2009 (2)
- October 2009 (14)
- September 2009 (6)
- August 2009 (19)
- July 2009 (34)
- June 2009 (11)
- May 2009 (4)
- April 2009 (6)
- March 2009 (13)
- February 2009 (32)
- January 2009 (25)
- December 2008 (1)
- October 2008 (1)
- June 2008 (1)
- November 2007 (1)
Prototype Web Services
- drag2share – quickly share news items by drag and drop on email addresses
- LivePhotoFrame – upload and remotely manage a digital photo frame via unique URL
- MedleyTuner – create a continuous listening experience by uploading mp3s
- MusicSamplr – discover new artists and music, listen to samples
- SharedMost – what links on ANY webpage are shared most?
- Signatory – sign and date a document and verify it hasn't been altered since that exact time.
- WebTeleprompter – just what it says it is

