Your personal data just got permanently cached at the US border - isn't it cute how countries that otherwise always emphasize freedoms so much issue the most absurd regulations? Which freedoms are actually being defended when you give them all up?
sicherheit
RFID System Mifare Classic cracked? - "According to the recently published work of Nicolas Courtois, Karsten Nohl and Sean O'Neil, it is possible to crack the encryption within seconds using PC hardware without having to pre-calculate extensive tables (Rainbow Tables). The security of the algorithm, according to the researchers' conclusion, is 'close to zero'."
CCC publishes Schäuble's fingerprint - cool action.
Hacking implanted defibrillators: shockingly easy - "But, more disturbingly, they could also shut off the device's ability to respond to cardiac events. The pinnacle of their hacking was to send the device into test mode, in which a carefully-timed current would trigger an arrhythmic event, something that's normally done under controlled conditions to determine if the device responds successfully. In effect, they hacked the device in a way that could stop a heart."
Cryptanalysis of A5/1 - "What's new about this attack is: 1) it's completely passive, 2) its total hardware cost is around $1,000, and 3) the total time to break the key is about 30 minutes. That's impressive."
IE pwns SecondLife - bah. I've always had something against fancy URL handlers that also inherit parameters from the calls. The problem is - why should an application trust a URL? If a call is made via a URL, the program should always classify this as untrusted and never initiate an activity that could potentially be dangerous without informing the user. The culprit here is -autologin in SecondLife - it shouldn't work in this situation at all. The browsers should of course also check the data (and Mozilla's reaction is correct, that Firefox was fixed accordingly when the problem also appeared there), but the real problem lies with the Second Life client.
Tor-Server-Betreiber stellt nach Razzia Anonymisierungsserver ab - the biggest danger when using Tor or similar techniques: the technical ignorance of the authorities. They simply don't know what the stuff is and how they should react (taking the tor server would not have helped either, but would at least be logically justifiable). And of course the possibility for the authorities to intimidate people into stopping - which I do not want to imply here, I really just see the ignorance of the deciding official here. Tor is just exotic. For operators of such systems, however, this is part of the necessary risk assessment - you often and "gladly" encounter ignorance.
Anonymity network Tor "phished" - Encryption and network security is still difficult to understand for many. TOR secures the transport within its own network against manipulation and spying. Not the protocols that are used.
New FCC rules may impact Linux-based devices - the FCC thinks that Security-by-Obscurity is a great idea for radio technologies. And undermines both Open Source projects and the security of wireless solutions. Idiots.
Major setback for US voting machine manufacturer - wow. I'd love to see something like this here in Germany.
Light Blue Touchpaper » Electoral Commission releases e-voting and e-counting reports - The Commission’s criticism of e-counting and e-voting was scathing; concerning the latter saying that the “security risk involved was significant and unacceptable.” They recommend against further trials until the problems identified are resolved. - Grossbritannien auch. Und wann wacht unsere Politik auf?
US-Election computers cannot guarantee trustworthy elections - this will certainly be completely ignored. Because, it's only about elections.
Virtualization Rootkit Blue Pill available - here comes the fun.
Scan This Guy's E-Passport and Watch Your System Crash - e-Passport. A complete disaster.
Results of the largest "hacker" test for US voting machines are available - the politicians will surely argue everything nicely after corresponding payments from the industry ...
Microsoft's Digital Rights Management bypassed - well, anyone who relies on DRM is building on sand ...
Police defused explosive device in London - Passersby discovered the vehicle. No surveillance cameras (in which the British are pioneers) and no telephone surveillance (in which they are also at the forefront). None of that silly security hocus-pocus, but simply and plainly passersby who found the car suspicious. What do you want to bet that this bomb find will now be used to justify further - ineffective - surveillance measures?
Millionenschaden durch manipulierte Geldautomaten - if you're affected, have fun discussing it with the bank. Because they still assume that ATMs are secure and the customer is initially suspected of fraud. Because that's the best way to deal with customers who have a problem.
Expert report confirms manipulability of voting computers - will certainly be ignored by the prolethicians in Berlin, just like all other facts.
HD-DVD and Blu-ray Disc copyable again - Hare and Hedgehog.
Breaking WEP in Under a Minute - and thus WEP for WLANs is considered dead and unusable.
StudiVZ: "Gegendarstellung" per Defacement [Update] - cool action! Give the manager-babble and the Web 2.0 bubbles a good pinch.
Ophcrack - Crack NTLM password hashes using rainbow tables. Comes with a ready-made Linux live CD including the software and the tables.
Real-World Passwords - Bruce Schneier analyzes user data from a phishing attack and reports on password distributions, lengths, frequencies, etc. Very interesting, "password1" is the new "password".
Microsoft's Zune DRM cracked - cute. Just rename the files and Microsoft DRM on the Zune no longer works ...
StudiVZ: 700 Stalker and Data Protection - something from practice. Nicely researched and prepared by Don Alphonso. For all those who always come up with "I have nothing to hide, it's not that bad" when you find a vulnerability in an online system.
Cracked it! - and what did they crack? The British RFID passport.
Would you like fries with your spyware? - funny. Our most hated fry factory (hey, their working conditions are at UPS level and their customers - who go to the factory next door - are too stupid to pay attention to traffic lights) distributes SpyWare.
Hackers Clone RFID Passports - oh, great, the blackhats have demonstrated how easy it is to clone a German passport with RFID (i.e. the RFID part of it). Result? A blank piece of paper with an RFID chip that looks like the original ID to the electronic reader.
Caller ID Spoofing - what is worse than a broken authorization system? One that millions of people and machines trust.
How Secure is WEP, Anyway? - an interesting link about the security of WLAN, specifically how easy it is to crack a WLAN with WEP.