Google Search

Showing posts with label control. Show all posts
Showing posts with label control. Show all posts

Tuesday, June 10, 2014

Quantum dots provide complete control of photons

By emitting photons from a quantum dot at the top of a micropyramid, researchers at Link?ping University are creating a polarized light source for such things as energy-saving computer screens and wiretap-proof communications.

Polarized light -- where all the light waves oscillate on the same plane -- forms the foundation for technology such as LCD displays in computers and TV sets, and advanced quantum encryption. Normally, this is created by normal unpolarized light passing through a filter that blocks the unwanted light waves. At least half of the light emitted, and thereby an equal amount of energy, is lost in the process.

A better method is to emit light that is polarized right at the source. This can be achieved with quantum dots -- crystals of semiconductive material so small that they produce quantum mechanical phenomena. But until now, they have only achieved polarization that is either entirely too weak or hard to control.

A semiconductive materials research group led by Professor Per Olof Holtz is now presenting an alternative method where asymmetrical quantum dots of a nitride material with indium is formed at the top of microscopic six-sided pyramids. With these, they have succeeded in creating light with a high degree of linear polarization, on average 84%. The results are being published in the Nature periodical Light: Science & Applications.

"We're demonstrating a new way to generate polarized light directly, with a predetermined polarization vector and with a degree of polarization substantially higher than with the methods previously launched," Professor Holtz says.

In experiments, quantum dots were used that emit violet light with a wavelength of 415 nm, but the photons can in principle take on any colour at all within the visible spectrum through varying the amount of the metal indium.

"Our theoretical calculations point to the fact that an increased amount of indium in the quantum dots further improves the degree of polarization," says reader Fredrik Karlsson, one of the authors of the article.

The micropyramid is constructed through crystalline growth, atom layer by atom layer, of the semiconductive material gallium nitride. A couple of nanothin layers where the metal indium is also included are laid on top of this. From the asymmetrical quantum dot thus formed at the top, light particles are emitted with a well-defined wavelength.

The results of the research are opening up possibilities, for example for more energy-effective polarized light-emitting diodes in the light source for LCD screens. As the quantum dots can also emit one photon at a time, this is very promising technology for quantum encryption, a growing technology for wiretap-proof communications.


View the original article here

Friday, July 26, 2013

Apple updates Safari, gives better control over Java applets

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

Apple has pushed out a Safari update to go along with this week's Java Tuesday fix.

Apple's browser goes to version 6.0.4 on OS X 10.7 and 10.8 (Lion and Mountain Lion), and to 5.1.19 on Macs that are still running 10.6 (Snow Leopard).

The key change that the new version brings to the party is finer-grained control over Java applets in the browser.

At this point, you're probably asking yourself, "Why?"

After all, as regular Naked Security readers will know, we've been suggesting for nearly a year that you should turn Java off in your browser altogether, unless you are certain that you need it.

We even recorded a dedicated Techknow podcast entitled All about Java to help you make up your own mind on how to manage the risks.

Listen to the podcast, duration 16'19".

We weren't alone in proposing such a blunt-edged tool to deal with the threat from browser-based Java exploits.

Homeland Security's US-CERT team in the United States said something similar, and so did our chum Brian Krebs.

But our advice hasn't been universally popular.

Some readers and listeners hit back at us for being unworldly, pointing out that an all-or-nothing approach to Java in the browser just isn't practical in their world.

? One reader, a contractor to an aerospace company that relies on website Java for outsiders to upload their work, pointed out that for him it was a choice between getting paid and following our advice. Other readers told us that their financial institutions insist on browser-based Java for internet banking. And some sysadmins noted that they were required to support in-house applets that wouldn't work with the latest Java versions, forcing them not only to enable Java but also to leave it unpatched.

Even users who were keen to take our advice were stuck at the thorny question, "How do I know whether I need Java or not?"

So Apple has headed towards a middle ground in which Safari allows you to authorise some applets, blocks others outright, and asks you what you want to do with all the rest.

The feature appears in the Security tab in Safari's Preferences pane:

The Allow Java tick-box isn't an all-or-nothing option any more, sporting as it does a shiny new Manage Website Settings... button next to it.

When you first enable Java, all applets on all sites are in an "ask me" state, provoking a question like this when you come across them:

Annoying though this may seem, it's actually a good way of helping you answer that question, "What do I need Java for, if anything?"

Once you've encountered an applet-serving web page, you can click into the Manage Website Settings... window and choose one of four options for the future:

There's a subtle difference between Allow and Allow Always, and it's important to understand it.

The former option will run the relevant applet next time you visit the page, provided that you've kept your Java installation up-to-date; if you haven't, you'll get a handy warning:

The latter option, Allow Always, overrides the version check, and is obviously intended for use only in stubborn cases, such as legacy applets that require an older, insecure Java version.

As Apple advises:

This setting is only recommended for trusted websites that require the Java web plug-in, such as websites that are only accessible on your company's intranet.

For sysadmins who support OS X users on a corporate network, or for contractors like our aerospace worker above, this feature is a good starting point for a "have your cake and eat it" approach to Java in the browser.

But it is far from perfect, not least because there's no easy way to pre-populate the allowlist, and no way to lock down the blocklist.

So, even in an environment where users are keen to do the right thing, mistakes are not only possible, but likely, especially when it comes to the free-for-all Allow Always option.

Intrepid sysadmins, however, might be willing to knit their own scripts for pre-configuring the allowlist (for example, to pre-authorise a set of intranet applets) after taking a look Safari's plist file.

Use the plutil (property list utility) command to dump your Safari configuration in human-readable form:

If you've added any applets to the control list via Safari's warning dialogs, you'll see how they are recorded near the end of the XML data:

The four possible values of the Manage Website Settings options shown above are encoded into the PluginPolicy key as one of four strings:

The plist is usually in binary format, but if you convert it to XML and edit it, Safari itself will happily load the XML version next time you start it.

With that, a determined sysadmin should have enough information to write a script that automatically populates users' WhitelistedBlockedPlugins settings with an appropriate applet list.

And that, in a nutshell, is the new "control Java in your browser" feature in Safari, at least on OS X.

Windows users of Safari, assuming there are any left, are out of luck: as far as we can tell, Safari for Windows is still back on version 5.1.7, which came out last year.

Follow @duckblog


View the original article here

Sunday, February 3, 2013

Facebook privacy control overhaul will remove ability to limit who can find us

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

FacebookAre you suffering from CFF - Chronic Facebook Fatigue? The mental and bodily malaise that comes from constant tweaking of privacy options in the Land of the Face?

Fear not, for the most recent round of changes, announced today, carry some good privacy tidings, including privacy shortcuts from the main page drop-down menu, plus a new Request Removal tool for managing multiple photos in which you have been tagged.

The changes will begin rolling out at the end of the year.

Facebook is also adding in-context educational notices throughout its platform to help make it easier to understand how to control your sharing.

For example, a reminder may inform users how items hidden on their timelines can still appear in news feeds, in searches, and in other places.

Hidden Education

But lest we get all giddy, note that the new privacy changes are part good, part bad.

On the plus side is the privacy short-cut.

You'll be able to click on a lock icon, next to the Home button on the upper right of the drop-down menu, to quickly access settings for "Who can see my stuff?" "Who can contact me?" and "How do I stop someone from bothering me?"

privacy-shortcuts

You'll also be able to access Help Center content from the short-cut drop-down menu.

As Facebook product manager Sam Lessin notes in his writeup of the changes, this quick access replaces what used to be a bit of a maze.

Up until now, tweaking privacy and timeline controls required you to stop what you were doing and navigate through a separate set of pages.

In the best of all possible worlds, the ease of access to Facebook privacy controls would increase their use.

That's good. It's hard to imagine their use getting worse, at any rate.

As Consumer Reports reported in April, 13 million US Facebook users aren't using, or are oblivious to, privacy controls.

Facebook is arguing that another positive step is the upcoming ability to remove your name from multiple photos that you are tagged in.

We'll be able to go to the "Photos of You" tab, select multiple photos, and ask friends to take down the shots we don’t want to be tagged in. We'll also be able to append a message about why this is important.

The tool will enable you to take off your name from multiple photos. But bear in mind that while untagged photos don’t appear on your timeline, the photos can still appear in other places on Facebook, such as search, news feed, or your friends’ timelines.

request-removal-tool

It's sounds like it will be a convenient way to bemoan rampant tagging to the slap-happy taggers in your network, but it doesn't go far enough.

As Sophos's Graham Cluley noted when he wrote up the last big privacy setting revamp in August 2011, Facebook-using Naked Security readers list photo-tagging as one of the least popular elements of the site.

Rather than having to slog through a continual process of requesting that people untag them in photos, and that they please leave off the habit entirely in the future, and rather than simply blocking tagged photos from appearing on their timelines, many Facebook users want to simply block anyone from tagging them without having received express prior permission to do so.

Unfortunately, Facebook has failed to give us this blanket tag-blocking ability in these recent privacy changes.

Facebook magnifying glassAnother negative change is the removal of the ability to hide yourself from people searching for you by name.

Facebook is axing the setting called "Who can look up my timeline by name," which controlled whether someone could be found by typing their name into the Facebook search bar.

That setting was "very limited in scope," Lessin wrote, and didn't keep people from being found in "many other ways across the site."

He wrote:

"Because of the limited nature of the setting, we removed it for people who weren’t using it, and have built new, contextual tools, along with education about how to use them. In the coming weeks, we’ll be retiring this setting for the small percentage of people who still have it."

Again, it's the wrong direction. If the original setting was limited in scope and failed to do what it purported - e.g., choose who can find you - why not rework it so as to actually protect people's privacy and give them the right to not be found?

Why not patch those privacy leakage holes, those "many other ways across the site" that allow people to find those who don't want to be found?

Facebook deserves kudos for putting privacy controls in a quick short-cut where more people might access and use them, and the contextual education sounds like a win, but it all would be more comforting if the company weren't, at the same time, trashing the important privacy control of who can find us.

If you are on Facebook and want to keep yourself informed about the latest news from the world of internet security and privacy, join the Sophos Facebook page where more than 200,000 people regularly discuss these issues and best practice.

Follow @LisaVaas
Follow @NakedSecurity


View the original article here

Sunday, November 4, 2012

Chinese hackers linked to breach of control systems used in electric grids

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

electricity_170Attackers breached Telvent's network, the company has informed its customers in a letter. Telvent is the maker of an industrial control system that remotely controls smart grid networks used in portions of the electric grid.

Telvent told its customers that on Sept. 10, it learned that hackers had breached its internal firewall and security systems, implanted malicious software, and stolen project files.

According to
Chinese Hackers Blamed for Intrusion at Energy Industry Giant Telvent" href="http://krebsonsecurity.com/2012/09/chinese-hackers-blamed-for-intrusion-at-energy-industry-giant-telvent/" rel="nofollow">KrebsOnSecurity, which first reported the breach, the project files concerned Telvent's
Standardized, centralized SCADA solutions from Telvent" href="http://www.telvent.com/en/business_areas/smart_grid/solutions_overview/smart_grid/smart_operations/oasys-scada.cfm" rel="nofollow">OASyS SCADA product, which offers energy firms a bridge between older technology and advanced smart grid technologies.

Telvent, which is owned by Schneider Electric, told customers that the attack spans operations in the US, Canada and Spain.

Experts detected digital fingerprints implicating a Chinese hacking group that has been tied to cyber-espionage campaigns against Western interests.

Telvent_logo

KrebsOnSecurity cited Joe Stewart, director of malware research at Dell SecureWorks, who said that website and malware names mentioned in a more recent letter from Telvent can be traced to a Chinese hacking team known as the "Comment Group."

That group, often referred to as the Comment group, has been under investigation by US intelligence for years.

Researchers told Bloomberg that during two months of monitoring last year, targeted companies spanned a vast scale as data "bled from one victim to the next":

...from oilfield services leader Halliburton Co. (HAL) to Washington law firm Wiley Rein LLP; from a Canadian magistrate involved in a sensitive China extradition case to Kolkata-based tobacco and technology conglomerate ITC Ltd. (ITC)

A loose-knit group of some 30 North American private security researchers tracking the group have called the Comment Group one of the biggest and busiest hacking groups in China.

Bloomberg quoted Shawn Henry, former executive assistant director of the FBI in charge of the agency’s cyber division, who said that typical cybersecurity headlines about data breaches scarcely hint at the scope of the group's activities:

What the general public hears about — stolen credit card numbers, somebody hacked LinkedIn (LNKD) — that’s the tip of the iceberg, the unclassified stuff. … I’ve been circling the iceberg in a submarine. This is the biggest vacuuming up of U.S. proprietary data that we’ve ever seen. It’s a machine.

Evidence indicates that at least 20 organizations have been harvested for data, many of whose secrets could give China a leg up on its path to becoming the world’s largest economy.

Bloomberg cited unnamed security experts who said that the breaches have sprung data leaks in major oil companies, who've lost seismic maps charting oil reserves, while patent law firms have been squeezed for clients' trade secrets and investment banks have been targeted for market analysis regarding global ventures of state-owned companies.

Telvent said that investigations are still under way, but it's taken the precaution of severing data links between clients and the affected portions of its internal networks.

The company also said that it hasn't yet found evidence that the attackers had been able to compromise customers' systems:

Although we do not have any reason to believe that the intruder(s) acquired any information that would enable them to gain access to a customer system or that any of the compromised computers have been connected to a customer system, as a further precautionary measure, we indefinitely terminated any customer system access by Telvent.

Telvent gave me this statement:

Telvent is aware of a security breach of its corporate network that has affected some customer files. Customers have been informed and are taking recommended actions, with the support of Telvent teams. Telvent is actively working with law enforcement, security specialists and its affected customers to ensure the breach has been contained.

Meanwhile, the Obama adminstration and Congress have grown increasingly vocal about Chinese and Russian cyber espionage and attacks, with the White House close to completing the first draft of a cybersecurity executive order designed to bring about stronger cyber security around the nation's water, electrical and transportation systems.

It's a reasonable thing to call for stronger protection around vital infrastructure.

But as Reuters pointed out in a recent report on what one top US cybersecurity official called "reckless" cyber behavior from nation states, the US's right to complain about other nations' cyber warfare might be questionable, given what is by now a widespread belief that the US and Israel were behind Stuxnet.

Follow @LisaVaas
Follow @nakedsecurity

electricity images courtesy of Shutterstock


View the original article here

Wednesday, June 13, 2012

Stuxnet: How USA and Israel created anti-Iran virus, and then lost control of it

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

There is a simply fascinating report in today's New York Times describing how the Stuxnet virus was created by the USA to target an Iranian nuclear facility, but accidentally escaped into the wider world.

New York Times article

The report comes from David E. Sanger, the Chief Washington correspondent at The New York Times and author of the upcoming book "Confront and Conceal: Obama’s Secret Wars and Surprising Use of American Power".

Here is a quick summary of the claims made in the report:

David Sanger says his account of the American and Israeli attempt to undermine Iran's nuclear program with malware is based upon interviews with current and former officials who were involved in the operation. None of them have allowed their names to be published.

We've reported before on how US defence chiefs have squirmed when quizzed about whether America was responsible for writing Stuxnet, and according to Sanger the operation remains highly classified.

One thing seems certain. Stuxnet is old news. Even the recently discovered (and much hyped) Flame malware isn't an effective weapon today. There seems little doubt that state-sponsored cyberweapons (if that is indeed what Stuxnet was) continue to be developed - and chances are that it's not just the USA and Israel who are developing them but other developed countries.

Read the full story on the New York Times website. It certainly makes for fascinating reading.

http://twitter.com/gcluley

Tags: barack obama, Cyberwarfare, George W Bush, Iran, israel, Malware, Natanz, New York Times, Olympic Games, Stuxnet, usa


View the original article here

Monday, March 5, 2012

Report: Hackers Seized Control of Computers in NASA’s Jet Propulsion Lab

Illustration showing NASA's newest Martian rover, the Curiosity, which will look for past or current conditions favorable for life when it lands later this year. Photo: NASA/JPL

Hackers seized control of networks at NASA’s Jet Propulsion Laboratory last November, gaining the ability to install malware, delete or steal sensitive data, and hijack the accounts of users in order to gain their privileged access, according to a report from the National Aeronautics and Space Administration’s inspector general.

The breach, originating from Chinese-based IP addresses, allowed the intruders to compromise the accounts “of the most privileged JPL users,” giving them “full access to key JPL systems,” according to Inspector General Paul K. Martin in a report to Congress (.pdf).

The investigation of the breach is ongoing, but Martin says the intruders had the ability to modify sensitive files; modify or delete user accounts for mission-critical JPL systems; and alter system logs to conceal their actions.

“In other words, the attackers had full functional control over these networks,” Martin writes.

But this wasn’t the only breach NASA experienced. In 2010 and 2011, the agency had 5,408 computer security incidents that resulted in the installation of malicious software and the theft of export-controlled and otherwise sensitive data, with an estimated cost to NASA of more than $7 million. Some of the breaches “may have been sponsored by foreign intelligence services seeking to further their countries’ objectives,” Martin writes.

One March 2011 theft of an unencrypted NASA notebook computer resulted in the loss of algorithms used to command and control the International Space Station. In one of the most successful attacks, Martin notes, intruders stole user credentials for more than 150 NASA employees, which could have been used to gain unauthorized access to NASA systems.

NASA operates more than 550 information systems that control spacecraft, collect and process scientific data, and enable NASA personnel to collaborate with colleagues around the world, and spends about $58 million annually for IT security.

“Some NASA systems house sensitive information which, if lost or stolen, could result in significant financial loss, adversely affect national security, or significantly impair our Nation’s competitive technological advantage,” Martin writes.

But even more troubling, he said, skilled attackers “could choose to cause significant disruption to NASA operations, as IT networks are central to all aspects of NASA’s operations.”

Kim Zetter is a senior reporter at Wired covering cybercrime, privacy, security and civil liberties.
Follow @KimZetter and @ThreatLevel on Twitter.

View the original article here

Saturday, March 3, 2012

Could hackers seize control of your car?

A student at the Freie Universitaet Berlin steers a converted Dodge minivan remotely with an iPhone in November 2009.A student at the Freie Universitaet Berlin steers a converted Dodge minivan remotely with an iPhone in November 2009.Car manufacturers' appearance at mobile show heralds new automotive eraIncreased use of technology in cars has raised concerns over securityExperts warn computer hackers could access car systems and data

(CNN) -- When car companies begin exhibiting at mobile phone shows, it's a sign that the "connected" vehicle has truly arrived -- allowing us to take our digital lives with us as we hit the highway.

But while Ford's unveiling of its latest car at Mobile World Congress -- a major cell phone industry event -- this week may have heralded a new automotive age, it also heightens fears that our technology-crammed cars could be hijacked by hackers.

Just like our PCs and smartphones, the computerized components that have infiltrated almost every aspect of modern vehicles could potentially be broken into, experts say. Only, with a car, this could have far more dangerous consequences.

"We typically don't drive our smartphones at 80 miles an hour," said Brian Contos, security strategist at technology protection firm McAfee. "But safety concerns and privacy concerns all culminate when you talk about automobiles."

Ford isn't alone in integrating mobile phone technology into its cars.

var currExpandable="expand16";if(typeof CNN.expandableMap==='object'){CNN.expandableMap.push(currExpandable);}var mObj={};mObj.type='video';mObj.contentId='';mObj.source='tech/2012/02/27/boulden-ford-car-tech.cnn';mObj.lgImage="http://i2.cdn.turner.com/cnn/dam/assets/120227020819-boulden-ford-car-tech-00005630-story-body.jpg";mObj.lgImageX=300;mObj.lgImageY=169;mObj.origImageX="214";mObj.origImageY="120";mObj.contentType='video';CNN.expElements.expand16Store=mObj;var currExpandable="expand26";if(typeof CNN.expandableMap==='object'){CNN.expandableMap.push(currExpandable);}var mObj={};mObj.type='video';mObj.contentId='';mObj.source='business/2012/02/28/boulden-intv-blackberry-rory-oneill.cnn';mObj.lgImage="http://i2.cdn.turner.com/cnn/dam/assets/120228090123-boulden-intv-blackberry-rory-o-neill-00014607-story-body.jpg";mObj.lgImageX=300;mObj.lgImageY=169;mObj.origImageX="214";mObj.origImageY="120";mObj.contentType='video';CNN.expElements.expand26Store=mObj;if (typeof cnnArticleGallery == "undefined") {var cnnArticleGallery = {};}if(typeof cnnArticleGallery.currentImageList =="undefined"){cnnArticleGallery.currentImageList = [];}var expGallery63=new ArticleExpandableGallery();expGallery63.setImageCount(20);//cnn_adbptrackpgalimg("Latest gadgets on display in Barcelona", 1);Latest gadgets on display in BarcelonaLatest gadgets on display in BarcelonaLatest gadgets on display in BarcelonaLatest gadgets on display in BarcelonaLatest gadgets on display in BarcelonaLatest gadgets on display in BarcelonaLatest gadgets on display in BarcelonaLatest gadgets on display in BarcelonaLatest gadgets on display in BarcelonaLatest gadgets on display in BarcelonaLatest gadgets on display in BarcelonaLatest gadgets on display in BarcelonaLatest gadgets on display in BarcelonaLatest gadgets on display in BarcelonaLatest gadgets on display in BarcelonaLatest gadgets on display in BarcelonaLatest gadgets on display in BarcelonaLatest gadgets on display in BarcelonaLatest gadgets on display in BarcelonaMobile World Congress Mobile World Congress Event.observe(window, 'load', function() {//report the first gallery image to ADBPif(typeof(cnn_adbptrackpgalimg) == 'function' && typeof(cnnArticleGallery) != 'undefined') {cnn_adbptrackpgalimg(cnnArticleGallery.currentImageList[0].image, "");}});

While its networked B-Max compact and its prototype Evos were big hits at the Mobile World Congress in Barcelona, also on display was a BlackBerry-embedded Porsche 911 and a Toyota with an integrated Samsung phone application.

Read more about Ford's tecnhology-filled car

Almost every vehicle manufactured in the past few years is hardwired with computer circuitry in some way, from simple entertainment units to sophisticated safety systems that can control braking and acceleration.

And technology continues to advance. Google is working on a driverless car project that, in allowing complete control of the vehicle to be handled by computers, could reshape the future of motoring.

With onboard systems capable of preventing crashes or summoning help after accidents, vehicles have arguably never been safer.

But in-built links to cell phones, Bluetooth or even low-range radio transmitters serve only to heighten the possibility that this technology can be turned against us.

So far, such attacks have been largely academic. Last year computer scientists at the University of California, San Diego and University of Washington reported they were able to gain remote access to the safety systems of a "moderately priced sedan" using an audio CD infected with a virus.

"Modern automobiles are pervasively computerized, and hence potentially vulnerable to attack," they argued in a report to the U.S. National Academy of Sciences. They warned of "financially-motivated scenarios" under which an attacker might exploit these weaknesses.

There have been a few real-life examples, such as the disgruntled ex-employee of a firm providing web-based vehicle-immobilization systems who reportedly managed to disable 100 cars in Austin Texas in 2010.

"The nightmare scenario is 100 cars on a bridge and 50% of them hit their brakes and 50% hit their accelerators," added Contos. "Just the amount of collision that something like that would cause with a remote attack, that's pretty scary stuff."

Safety concerns and privacy concerns all culminate when you talk about automobiles.
Brian Contos, McAfee securty strategist

Another possibility envisaged by Contos is hackers using radio waves to trigger a tire pressure warning. "And then what happens? The logical person would pull over and check their tires, and what a great way to carjack somebody."

Contos, whose company has compiled a report highlighting vehicle cyber security issues, also suggests that the most likely motive for such an attack would be financial, but could simply be the work of hackers trying to wreak havoc for the sake of it. Terrorism could also be a factor.

"A lot people say there's no such thing as cyber terrorism because it doesn't have the shock and awe value of blowing up a car or something of that nature. Well something like (causing a major collision) would have that."

Then there are the concerns over privacy. In downloading personal information into our cars we may help them navigate to our favorite coffee shops or check our diaries, but we also make them targets for data thieves.

For many in the auto industry, the question is currently one of balance: whether the benefits of technology outweigh the problems with security.

Read more about mobiles and medicine

"I don't think this is a situation that's unique to the car industry," said motoring journalist Carlton Boyce. He suggests that handing more computerized autonomy to our vehicles is inevitable in an increasingly traffic-clogged world. This, he says, is something consumers are happy with, and will benefit from in the long run.

"The risks are probably smaller than putting everyone in charge of two tons of metal and letting them drive at 80 miles an hour," he said.

Vehicle manufacturers themselves are not blind to the problem. Bill Ford, great grandson of Model-T creator Henry Ford and now the auto giant's executive chairman, says he traveled to Barcelona this week partly to address security concerns.

"That's one of the issues we're going to have to work out as we go along and that's why we're here, to talk to the mobile providers because they're already facing many of those security issues," he said. "For now, what we're working with is opt-in; you can opt-in with how much you're comfortable with."

He added: "Your car can know where you are at any moment and that's great for safety reasons, but the downside of that potential is someone knows where you are every second, and that's something we're going to have to work through."

This won't be easy, says Contos. With vehicles taking up to three years to develop, he says manufacturers will struggle to keep abreast of rapidly-evolving threats unless they organize regular software updates.

Instead, he says, any installed technology should be given a so-called "white list" of permissible activities beyond which any procedures are blocked.

Another option, of course, is to return to driving jalopies whose only concession to technology is a crackling AM radio. But, adds Contos, this isn't a route most drivers are prepared to take.

"People aren't going to go back to driving the Model T any more than they're going to go back to rotary telephones because of the risks on smartphones," he said.

ADVERTISEMENTupdated 5:43 AM EST, Fri March 2, 2012 More cars are including integrated mobile technology. But some fear these vehicles could be hijacked by hackers.updated 1:32 PM EST, Thu March 1, 2012 Developers say quad-core offers faster performance for graphics-intensive, high-end gaming.updated 11:57 AM EST, Wed February 29, 2012 Almost all the hot smartphones at MWC run Android, Google's phone operating system. updated 12:09 PM EST, Wed February 29, 2012 Mobile devices are being used in radical and innovative ways to modernize healthcare. updated 11:56 AM EST, Wed February 29, 2012 Highlights of MWC include a smartphone that turns into a tablet, which then slots into a keyboard, making it a feasible laptop replacement.updated 3:01 PM EST, Tue February 28, 2012 Google's Eric Schmidt gives a press conference in Barcelona on February 28, 2012 on the second day of the Mobile World Congress. The 2012 Mobile World Congress, the world's biggest mobile fair, is held from February 27 to March 1 in Barcelona. The world must act now to prevent a new digital caste system from emerging, Google's executive chairman Eric Schmidt says.updated 10:10 PM EST, Thu March 1, 2012 The latest smartphone and tablet games are unveiled at Mobile World Congress.updated 4:18 PM EST, Tue February 28, 2012 RIM's Rory O'Neill talks about the future of BlackBerry and how cars are becoming more connected.updated 2:51 PM EST, Tue February 28, 2012 Waterproof phones are the latest trend. Some use nano-technology, others special seals, to keep water out.updated 5:31 AM EST, Tue February 28, 2012 Our phones are becoming uncontrollable monsters, argues 'professional skeptic' Andrew Keen.Most popular Tech stories right nowADVERTISEMENTcnnad_createAd("261371","http://ads.cnn.com/html.ng/site=cnn&cnn_pagetype=bst&cnn_position=1x1_bot&cnn_rollup=technology&page.allowcompete=no¶ms.styles=fs","1","1");cnnad_registerSpace(261371,1,1);

View the original article here

Wednesday, November 23, 2011

Chinese hackers took control of NASA satellite for 11 minutes - Geek.com

Chinese hackers took control of NASA satellite for 11 minutes | Geek.com .wp-polls .pollbar {margin: 1px;font-size: 6px;line-height: 8px;height: 8px;background-image: url('http://www.geek.com/wp-content/plugins/wp-polls/images/default/pollbg.gif');border: 1px solid #c8c8c8;}  HomeGeek.com Home AppleApple Reviews GadgetsGadget Reviews MobileMobile Phone Reviews GamesVideo Game Reviews ChipsComputer Processors Technology ForumsForumsTechnology Forums Technology ShopShopTechnology Shop Tech Support Chips Apple Mobile Games Gadgets Software The Lounge Geek.com Stuff Cameras Cell Phones Computers Electronics Laptops Memory Monitors PDAs Software Storage Devices Video Games All Products Search: All Articles Products Glossary Forums Username: Password: Cancel Forgot Username / Password? Back to Geek-Cetera Print Chinese hackers took control of NASA satellite for 11 minutes Nov. 19, 2011 (11:05 am) By: Matthew Humphries


Landsat-7 and Terra EOS satellites

Hacking is becoming a growing problem on Earth. It may seem strange to mention Earth, as there’s not much to hack outside of our planet’s atmosphere unless you count satellites. Even then, how feasible would it be to gain access to the systems running such devices?

Well, China not only has people working on such things, it has been discovered they actually managed to take control of two NASA satellites for more than 11 minutes.

The successful attacks occurred in 2007 and 2008. The more serious of the two happened in ’08 when NASA had control of the Terra EOS earth observation system satellite disrupted for 2 minutes in June, and then a further 9 minutes in October. During that time, whoever took control had full access to the satellites’ systems, but chose to do nothing with it.

The second hack affected the Landsat-7 satellite on two occasions, one in October of ’07, the other in July of ’08. Unlike the Terra OS incident, this hack did not see control taken away, but access was gained.


Washington D.C. captured by Landsat-7 in 2005

We only know about these hacks because of a report becoming available this month. It is entitled the 2011 Report to Congress of the U.S.-China Economic and Security Review Commission and made available online at the USCC website (link below). The specific details can be found on page 216 of the document, which is actually page 224 of the PDF.

It is suggested such malicious cyber activity in relation to satellites can be carried out to either destroy the system rendering it useless, or to exploit it to see what the “enemy” sees and gain intelligence on “ground-based infrastructure.”

Interestingly, the report points to the use of ground stations outside of the U.S. to control satellites as weak points. The reason being they use the Internet for data access and communication, not a closed link. We don’t know if that is still the case, but we’d hope not, or at least hope that the communication link is using better encryption and security checks.

Read the report online at the USCC website (PDF), via ITWorld

Tags: 2007, 2008, 2011 Report to Congress of the U.S.-China Economic and Security Review Commission, China, control, hack, hacking, internet, Landsat-7, NASA, satellite, Terra EOS DiggDigg redditReddit FacebookFacebook StumbleUponStumble TwitterTwitter Email To Email Address:
To Name:
Your Name:
Your Email Address

Popular Geek Pick Articles Chinese hackers took control of NASA satellite for 11 minutes Pure Google? Verizon sneaks two bloatware apps onto the Galaxy Nexus Analyst predicts Amazon smartphone in 2012 Kindle Fire hacked to access Android Market Google and Facebook, it’s time to take the kid gloves off about SOPA Geek Pick Archives November 2011October 2011September 2011August 2011July 2011June 2011May 2011April 2011March 2011February 2011January 2011December 2010November 2010October 2010September 2010August 2010July 2010June 2010 Search: All Articles Products Glossary Forums Previous
World’s first Galaxy Nexus owner finds developer ROM on his phone
Is George Clooney being considered for the role of Steve Jobs?
Kindle Fire hacked to access Android Market
Google’s Nyan cat obsession spills onto Google+
Analyst predicts Amazon smartphone in 2012
Google Music exits beta, Music Store coming to Android Market
Google and Facebook, it’s time to take the kid gloves off about SOPA
Chinese hackers took control of NASA satellite for 11 minutes
FXI Cotton Candy is an ARM PC in a USB stick
Pure Google? Verizon sneaks two bloatware apps onto the Galaxy Nexus Next Recent Geek Pick Activity Popular Article CommentsForum Talk artyiom

there are many ideas a man can think but if he thinks it twice he thought about another idea which makes his idea non...

Posted In: Geek.com Stuff Read More » ExpertOnCoolers

The break in the case came when investigators focused on a grainy surveillance video that showed the boy, wearing his...

Posted In: Geek.com Stuff Read More » davidross

One of the most attracting features of Mac OSX Lion is auto save for documents. And Autosave would not save the modi...

Posted In: Apple Read More » View All Forum Talk » Prachi Desai

I am a big fab of Windows. Windows 8 Developer Edition is now available for download, I have installed it on PC. I must ...

Posted In: Download a preview build of Windows 8 tonight Prachi Desai

I am a big fab of Windows. Windows 8 Developer Edition is now available for download, I have installed it on PC. I must ...

Posted In: Download a preview build of Windows 8 tonight Georgecarlinjr

Apparently that also takes away the neat new task manager and explorer, which is a shame.Of course you can have the bes...

Posted In: How to get a Windows 7 start menu in Windows 8 Chinese hackers took control of NASA satellite for 11 minutes

Pure Google? Verizon sneaks two bloatware apps onto the Galaxy Nexus

Analyst predicts Amazon smartphone in 2012

Kindle Fire hacked to access Android Market

Google and Facebook, it’s time to take the kid gloves off about SOPA

.contentBox { clear: both; } @import url(http://www.geek.com/wp-content/themes/geek5a/styles/price-grabber.css); Geek Shop Categories Cameras Cell Phones Computers Electronics Laptops Memory Monitors PDAs Software Storage Devices Video Games All Products Geek.com Buyer's Guides Desktop Computer Buyer's GuideDigital Camera Buyer's GuideHDTV Buyer's GuideLaptop Buyer's GuideNetbook Buyer's GuideSmartphone Buyer's Guide Geek Feeds Geek Feeds Apple Gadgets Mobile Games Chips More Geek Goes Social Geek on Facebook Geek on Youtube Geek on Twitter Geek.com Archives This Month Last Month All Archives Reviews Newsletters Features Glossary © 1996-2011 Ziff Davis, Inc. AdChoices (function(){var e=document,b,a=(e.location.protocol=="https:"?"https":"http"),c=(a=="https"?"https://info.betteradvertising.com/c/betrad/pub/":"http://cdn.betrad.com/pub/");e.getElementById("_bapw-icon").src=c+"icon1.png";e.getElementById("_bapw-link").onclick=function(){var f=this;function d(i,l){var j=e.getElementsByTagName("head")[0]||e.documentElement,h=false,g=e.createElement("script");function k(){g.onload=g.onreadystatechange=null;j.removeChild(g);l()}g.src=i;g.onreadystatechange=function(){if(!h&&(this.readyState=="loaded"||this.readyState=="complete")){h=true;k()}};g.onload=k;j.insertBefore(g,j.firstChild)}this.onclick="return false";d(a+"://ajax.googleapis.com/ajax/libs/jquery/1.4.4/jquery.min.js",function(){d(c+"pub1.js",function(){BAPW.i(f,{pid:8,ocid:660},false)})});return false};b=e.createElement("img");b.src=a+"://l.betrad.com/pub/p.gif?pid=8&ocid=660&ii=1&r="+Math.random();b.height="1";b.width="1";e.body.appendChild(b)}()); About Contact Us Advertise Posting Guidelines Privacy Statement Terms of Use Glossary document.write(unescape("%3Cscript src='" + (document.location.protocol == "https:" ? "https://sb" : "http://b") + ".scorecardresearch.com/beacon.js' %3E%3C/script%3E")); COMSCORE.beacon({ c1:2, c2:6035546, c3:"", c4:"", c5:"", c6:"", c15:"" });

View the original article here