Hardware Hacking

Announcing Adafruit Gemma – Miniature Wearable Electronic Platform 44

coop0030 writes "Open source hardware company Adafruit has announced a new tiny wearable electronics platform board called the Gemma. The Gemma is a tiny, 1-inch diameter and 4-mm thick package. It's powered by an Attiny85 and programmable with an Arduino IDE over USB. There are three available I/O pins, one of which is also an analog input and two of which can do PWM output. Gemma is currently wrapping up development, but should be available soon."
Google

How Google Glass Is Evolving As It Heads For Release To Developers 140

hypnosec writes "Babak Parviz, the founder and head of Project Glass at Google, has revealed that the feature set of Google Glass and state of apps is still in flux and that there is a lot of testing going on at the moment. In an interview with IEEE Spectrum, Parviz provided insights into Project Glass, the reasons behind having such a gadget and what's there for the project in near future. Parviz said that they are trying out new ideas and ways in which the platform can be used while also trying to make the platform more robust. There is no specific feature set that Google has been talking about and 'It is still in flux.'" My favorite question / answer pair: "IEEE Spectrum: What kind of business model is associated with Google Glass? Babak Parviz: This is still being worked on, but we are quite interested in providing the hardware."
Government

NSA Targeting Domestic Computer Systems 105

The NSA was originally supposed to handle foreign intelligence, and leave the domestic spying to other agencies, but Presto Vivace writes with this bit from CNET: "'The National Security Agency's Perfect Citizen program hunts for vulnerabilities in 'large-scale' utilities, including power grid and gas pipeline controllers, new documents from EPIC show.' 'Perfect Citizen?' Who thinks up these names?" "The program is scheduled to continue through at least September 2014," says the article.
Security

Interviews: Eugene Kaspersky Answers Your Questions 82

Last week, you asked questions of Eugene Kaspersky; below, find his answers on a range of topics, from the relationship of malware makers to malware hunters, to Kasperky Labs' relationship to the Putin government, as well as whitelisting vs. signature-based detection, Internet ID schemes, and the SCADA-specific operating system Kaspersky is working on. Spoiler: There are a lot of interesting facts here, as well as some teases.
Bug

Researcher Finds Nearly Two Dozen SCADA Bugs In a Few Hours 104

Trailrunner7 writes "It is open season on SCADA software right now. Last week, researchers at ReVuln, an Italian security firm, released a video showing off a number of zero-day vulnerabilities in SCADA applications from manufacturers such as Siemens, GE and Schneider Electric. And now a researcher at Exodus Intelligence says he has discovered more than 20 flaws in SCADA packages from some of the same vendors and other manufacturers, all after just a few hours' work."
Education

Student Refusing RFID Badge Now Fights Expulsion Order 743

BeatTheChip writes "Lawyers representing Andrea Hernandez, a science and engineering student at John Jay High School, are fighting an expulsion notice issued a week ago for refusing to wear a Smart ID badge. To represent her, lawyers filed a preliminary court injunction, seeking legal restraints on the school. She maintains stance of refusal to wear any badge containing an RFID tag for reasons of basic privacy and conflicts with her belief system. The controversial decision for her school to adopt the NFC badges is part of the Student Locator Project, tracking attendance. Local schools started issuing the lanyard badges this fall despite parental outcry at NISD school board meetings."
Books

Ask Slashdot: High-Tech Ways To Manage a Home Library? 230

DeptofDepartments writes "With Kindles and ebooks on everyone's lips (sc. hands) nowadays, this might come as a surprise to some, but besides being a techie, I have also amassed quite a collection of actual books (mostly hardcover and first editions) in my personal library. I have always been reluctant to lend them out and the collection has grown so large now that it has become difficult to keep track of all of them. This is why I am looking for a modern solution to implement some professional-yet-still-home-sized library management. Ideally, this should include some cool features like RFID tags or NFC for keeping track of the books, finding and checking them out quickly, if I decide to lend one." For more on what DeptofDepartments is looking for, read on below.
Security

Stuxnet Infected (But Didn't Affect) Chevron Network In 2010 82

Penurious Penguin writes "The Wall Street Journal, in correspondence with Chevron representatives, reveals that back in 2010, Stuxnet reached Chevron, where it managed to infect — but not significantly affect — the oil giant's network. According to a Chevron representative speaking to CNET, the issue was 'immediately addressed ... without incident.' The Stuxnet worm is believed to be the work of the U.S. and Israel, and this report is confirmation that it struck well wide of its intended targets. Chevron's general manager of the earth sciences department, Mark Koelmel, said to CIO Journal, 'I don't think the U.S. government even realized how far it had spread ... I think the downside of what they did is going to be far worse than what they actually accomplished.'"
Google

Google Wallet May End Up Inside Your Actual Wallet 190

Several outlets are reporting, based on screenshots posted by Android Police that Google is (or "may be" — CNet calls the report "loosely sourced") about to introduce a lower-tech variant on its smartphone-based Google Wallet payment system. Instead of transferring payment information from an NFC-equipped phone, this would mean a physical payment card (like a conventional plastic credit or debit card), but one linked via Google's databanks to the user's existing bank or credit accounts. Upsides: less to carry, a simple way to suspend or cancel service on them (should the card be lost or stolen), and doesn't require you to carry your phone to make a credit or debit transaction — handy, since NFC readers are still thin on the ground. Downside: while perhaps no worse than putting the same information on your phone, it's one more step toward giving a third party all of your personal information in one place. A card that fits in a wallet probably makes a lot of sense: I live in a city with at least three pay-by-phone options in trials or fully available (CitiBank, Isis, and Google Wallet), but I can't buy ice cream or coffee with them yet. And there's no reason a card-shaped token couldn't use mag-stripes and NFC, too.
Security

Trade Show Video Features Iranian Tech, Talk of Stuxnet Retaliation 131

dcblogs writes "Iran recently held a security trade show and conference, attended by high-ranking police and military officials. A video by an Iranian news outlet shows some of the products, from crossbows to unidentified systems, and includes an interview with Iran's police chief, Brig. Gen. Esmail Ahmadi-Moqadam: 'It's true that the U.S. made Stuxnet virus did some damage to our facilities but we were able to get them all up and running in no time. However, those who attack should expect retaliation and we haven't gone there just yet.'"
Security

Kaspersky's Exploit-Proof OS Leaves Security Experts Skeptical 196

CWmike writes "Eugene Kaspersky, the $800-million Russian cybersecurity tycoon, is, by his own account, out to 'save the world' with an exploit-proof operating system. Given the recent declarations from U.S. Secretary of Defense Leon Panetta and others that the nation is facing a 'digital Pearl Harbor' or 'digital 9/11' from hostile nation states like Iran, this sounds like the impossible dream come true — the cyber version of a Star Wars force field. But on this side of that world in need of saving, the enthusiasm is somewhat tempered. One big worry: source. 'The real question is, do you trust the people who built your system? The answer had better be yes,' said Gary McGraw, CTO of Cigital. Kaspersky's products are among the top ranked worldwide, are used by an estimated 300 million people and are embraced by U.S. companies like Microsoft, Cisco and Juniper Networks. But while he considers himself at some level a citizen of the world, he has close ties to Russian intelligence and Vladimir Putin. Part of his education and training was sponsored by the KGB, he is a past Soviet intelligence officer (some suspect he has not completely retired from that role) and he is said have a 'deep and ongoing relationship with Russia's Federal Security Service, or FSB,' the successor to the KGB and the agency that operates the Russian government's electronic surveillance network."
Operating Systems

Kaspersky To Build Secure OS For SCADA Systems 165

Trailrunner7 writes "Attacks against SCADA and industrial-control systems have become a major concern for private companies as well as government agencies, with executives and officials worried about the potential effects of a major compromise. Security experts in some circles have been warning about the possible ramifications of such an attack for some time now, and researchers have found scores of vulnerabilities in SCADA and ICS systems in the last couple of years. Now, engineers at Kaspersky Lab have begun work on new operating system designed to be a secure-by-design environment for the operation of SCADA and ICS systems. 'Well, re-designing ICS applications is not really an option. Again, too long, too pricey and no guarantees it will fit the process without any surprises. At the same time, the crux of the problem can be solved in a different way. OK, here is a vulnerable ICS but it does its job pretty well in controlling the process. We can leave the ICS as is but instead run it in a special environment developed with security in mind! Yes, I'm talking about a highly-tailored secure operating system dedicated to critical infrastructure,' Eugene Kaspersky said in an interview."
Security

Smart-Grid Control Software Maker Hacked 96

tsu doh nimh writes "Telvent, a multinational company whose software and services are used to remotely administer and monitor large sections of the energy and gas industries, began warning customers last week that it is investigating a sophisticated hacker attack spanning its operations in the United States, Canada and Spain. Brian Krebs reports that the attacker(s) installed malicious software and stole project files related to one of Telvent's core offerings — OASyS SCADA — a product that helps energy firms mesh older IT assets with more advanced 'smart grid' technologies. A follow-up story from Wired.com got confirmation from Telvent, and includes speculation from experts that the 'project files' could be used to sabotage systems. 'Some project files contain the "recipe" for the operations of a customer, describing calculations and frequencies at which systems run or when they should be turned on or off. If you're going to do a sophisticated attack, you get the project file and study it and decide how you want to modify the pieces of the operation. Then you modify the project file and load it, and they're not running what they think they're running.'"
Security

Samsung Smartphones Vulnerable To Remote Wipe Hack 151

DavidGilbert99 writes "Security researchers have discovered a single line of code embedded in websites which could wipe all data from your Samsung Galaxy S3 and other smartphones. Samsung smartphones including the Galaxy S3, Galaxy S2, Galaxy Ace, Galaxy Beam and Galaxy S Advance all appear to be affected by the bug which triggers a factory reset on your phone if your web browser is pointed to a particular website. Smartphones can also be directed to the code through NFC or using a QR code. Once the process has been initiated, users are have no way of stopping it. The hack was unveiled at the Ekoparty 2012 security conference in Argentina by Ravi Borgaonkar, a security researcher at the Security in Communications department at Technical University Berlin. ... Only Samsung smartphones running the company's proprietary TouchWiz user interface appear to be affected. According to telecoms engineer Pau Oliva, the Samsung Galaxy Nexus is not affected, as it runs on stock Android and doesn't use the TouchWiz skin on top." Hit the link above for a video demonstration.
Security

Another EUSecWest NFC Trick: Ride the Subway For Free 135

itwbennett writes "At the EUSecWest security conference in Amsterdam, researchers showed how their 'UltraReset' Android app can read the data from a subway fare card, store that information, and reset the card to its original fare balance. The researchers said that the application takes advantage of a flaw found in particular NFC-based fare cards that are used in New Jersey and San Francisco, although systems in other cities, including Boston, Seattle, Salt Lake City, Chicago and Philadelphia, could also be vulnerable."
Android

Android Hacked Via NFC On the Samsung Galaxy S 3 198

An anonymous reader writes with an item from The Next Web: "Security researchers participating in the Mobile Pwn2Own contest at the EuSecWest Conference in Amsterdam [Wednesday] demonstrated how to hack Android through a Near Field Communication (NFC) vulnerability. The 0day exploit was developed by four MWR Labs employees (two in South Africa and two in the UK) for a Samsung Galaxy S 3 phone running Android 4.0.4 (Ice Cream Sandwich). Two separate security holes were leveraged to completely take over the device, and download all the data from it."
Encryption

Private Key Found Embedded In Major SCADA Equipment 105

sl4shd0rk writes "RuggedOS (A Siemens Subsidiary of Flame and Stuxnet fame), an operating system used in mission-critical hardware such as routers and SCADA gear, has been found to contain an embedded private encryption key (PDF). Now that all affected RuggedCom devices are sharing the same key, a compromise on one device gets you the rest for free. If the claims are valid, systems in use which would be affected include U.S. Navy, petroleum giant Chevron, and the Wisconsin Department of Transportation. The SCADA gear which RuggedOS typically runs on is often connected to machinery controlling electrical substations, traffic control systems, and other critical infrastructure. This is the second security nightmare for RuggedCom this year, the first being the discovery of a backdoor containing a non-modifiable account."
Bug

ICS-CERT Warns of Serious Flaws In Tridium SCADA Software 34

Trailrunner7 writes "The DHS and ICS-CERT are warning users of some popular Tridium Niagara AX industrial control system software about a series of major vulnerabilities in the applications that are remotely exploitable and could be used to take over vulnerable systems. The bugs, discovered by researchers Billy Rios and Terry McCorkle, are just the latest in a series of vulnerabilities found in the esoteric ICS software packages that control utilities and other critical systems. The string of bugs reported by Rios and McCorkle include a directory traversal issue that gives an attacker the ability to access files that should be restricted. The researchers also discovered that the Niagara software stores user credentials in an insecure manner. There are publicly available exploits for some of the vulnerabilities."
Cellphones

Alternative To QR Code Uses NFC and Cheap Rectennas 164

An anonymous reader writes "The BBC reports researchers in Korea have developed a technology that can be used as a viable alternative to QR codes. Made of plastic and electronic ink, the rectennas cost less than one penny each to produce and use the NFC standards for wireless radio communication to devices. They are seen as a cheap, easy-to-print and environmentally friendly way to overcome the limitations and inconvenience of QR codes, the usage of which has greatly increased in the last few years."
Cellphones

Did Apple Buy Fingerprint Security Firm For Mobile Wallet? 35

Hugh Pickens writes "Reuters reports that Apple will buy fingerprint sensor technology developer AuthenTec for about $356 million, striking a deal that could help Apple bring fingerprint technology, already used in mobile phones in Japan for authentication of mobile payments, to markets such as the United States, where mobile-wallet services have been slow to catch on. Some analysts expect the iPhone 5 to include some form of mobile payments technology. 'In the past 5 years, the growth of iPhone and Android smartphones has made mobile data security essential, not just a "nice-to-have" feature,' says Ben Yu, Managing Director of Sierra Ventures, one of the early investors in AuthenTec. 'People have their whole lives on the phones.' AuthenTec's embedded fingerprint scanners and other identity-related software is particularly useful now that Near Field Communications, or NFC-enabled, phones have begun to appear in the market. Analyst Colin Gillis says AuthenTec technology could potentially also help Apple combat problems such as theft of its more portable products such as iPhones. 'If they could have a way where they could tie the phone to a user more tightly, that would make sense for them,' says Gillis. The price tag for AuthenTec is a drop in the bucket of Apple's cash pile of $117.2 billion. 'We'll see if it's a one-off or if Tim Cook will start to level his cash balance and acquire talent,' adds Gillis."

Slashdot Top Deals