Saturday, August 15, 2009

Critical Vulnerability in the Linux Kernel (CVE-2009-2692)

Via H-online.com -

Google security specialists Tavis Ormandy and Julien Tiennes report that a critical security vulnerability in the Linux kernel affects all versions of 2.4 and 2.6 since 2001, on all architectures. The vulnerability enables users with limited rights to get root rights on the system. The cause is a NULL pointer dereference in connection with the initialisation of sockets for rarely used protocols.

[...]

Ormandy and Tiennes believe that all Linux version 2.4 and 2.6 since May 2001 are affected, which means 2.4.4 up to and including 2.4.37.4, as well as 2.6.0 up to and including 2.6.30.4. Instead of fixing all incompletely implemented protocols, the kernel developers have simply remapped sock_sendpage to the function kernel_sendpage, which also handles the case of an uninitialised pointer. So far, this correction has only gone into the kernel repository.

------------------------

Check out more over @ Julien Tiennes' blog...
Brad Spengler also wrote an exploit for this and published it. The bug triggering is based on our exploit which leaked to Brad though the private vendor-sec mailing list. He implements the personality trick Tavis and I published in June to bypass mmap_min_addr and also makes use of a feature that allows any unconfined user to gain the right to map at address zero in Redhat's default SELinux policy.

E-Voting Machine Hack Steals Votes

Via Darkreading.com -

Electronic voting machine security suffered another blow as researchers this week showed how they were able to hack a machine and steal votes.

A team of computer scientists from University of California-San Diego, the University of Michigan, and Princeton University used an attack based on "return-oriented programming" to turn a Sequoia AVC Advantage e-voting machine against itself and shift votes from one candidate to another.

Return-oriented programming basically takes snippets of code from the application and totally reassembles it into something with no resemblance to the program -- akin to selecting words or phrases from a story and putting them together into a different paragraph that means something completely different, says Hovav Shacham, a professor of computer science at UC San Diego's Jacobs School of Engineering and one of the lead researchers in the hack. UCSD had previously shown how the technique could work on desktop machines.

The attack (PDF) doesn't require any new code, either: "The attacker reuses short snippets of the existing system and recombines them in such a way that the computation they perform is exactly the computation he wants to carry out," he says.

The researchers exploited a buffer-overflow vulnerability in the Sequoia voting machine, which has built-in defenses against code injection into its RAM. "This is exactly the defense that our use of return-oriented programming defeats," Schacham says.

Brian Chess, CTO of Fortify Software, says return-oriented programming is an effective attack technique. "The lesson here is that there's no substitute for good code," Chess says.

Unlike previous e-voting hacks that have been demonstrated, the UCSD, Princeton, and Michigan researchers didn't have source code or documentation on the machine. "We were able to reverse-engineer the hardware and software of the AVC Advantage using only the physical artifacts -- a voting machine and a memory cartridge -- that an attacker could obtain by stealing a machine left unattended at a polling place the night before an election," UCSD's Shacham says.

It took the researchers about 16 months of work and $100,000 to pull off the hack, he says. "It might take an attacker longer to reverse-engineer the machine without source, but even so, the total time and money it took for us to develop our attack was not very large," he says.

The researchers pooled their resources, with Princeton computer scientists reverse-engineering the hardware of the Sequoia AVC Advantage purchased via a government auction, and a memory cartridge they obtained. They then wrote an exploit using the return-oriented method that simulated an election. "But after the polls are closed, it shifts votes from one candidate to another," Shacham says.

China Will Not Enforce Green Dam Filter Plan

Via NetworkWorld.com -

China said Thursday it will not force PC makers to bundle an Internet filtering program with computers sold in the country, backing down from a plan that stirred global controversy.

China will "definitely not" require the program, called Green Dam, to be packaged with all consumer PCs, said Li Yizhong, China's Minister of Industry and Information Technology, according to a transcript of his statements on a government Web portal.

China originally ordered all foreign and domestic PC vendors to pre-install Green Dam on new machines or to include the software on a CD-ROM. That mandate, issued in May, was indefinitely postponed just hours before it was slated to take effect last month. At the time, the Chinese government said it delayed the plan only to give PC makers more time to comply, but it did not set a new date for enforcement.

Thursday's statements were the first clear sign that China would not enforce the plan, which drew strong protest from Western PC makers and industry organizations. China has insisted that the Web filter was meant to protect children from pornography, but the program was also found to block Web sites that mentioned sensitive political topics such as Falun Gong, a spiritual movement banned in China as a cult.

Concerns about the program ranged from free speech and user privacy to PC security and intellectual property violations. A California-based software maker last month said it was preparing legal action over Green Dam for its use of programming code stolen from the company.

Li said use of the filter was meant to be optional and that the plan was misunderstood because it was not explained clearly. The software can be disabled or uninstalled.

PC makers including Lenovo, Acer and Asustek Computer have gone ahead with plans to distribute the program.

China's government will go ahead with installation of Green Dam on computers in public schools, Internet cafes and other public places, Li said. It is also working to address flaws in the program and would not rule out introducing a better filter, he said.

Friday, August 14, 2009

UK Anti-Terror Technology: 007 or 1984?

Via Wired.com -

The British government is launching a new initiative for technology to fight terrorism. As the BBC report it this will involve “real life versions of the scientist Q in the 007 films” getting funding for gadgets to defeat groups like al-Qaeda. The BBC even uses a picture of the fictional Q. But a closer look at the initiative suggests that much of the technology being sought is closer to George Orwell than James Bond.

The announcement is illustrated with a video of one of the programs under consideration, the Air Launch Running Gear Entanglement System. Danger Room looked at this a few months back as a possible anti-pirate weapon for use against small speedboats. The system releases a high-tensile line which snags on the boat’s propeller, immobilising it so that the stranded pirates/terrorists can be dealt with in due course. The version being demonstrated this time is fired from a bazooka-like weapon using compressed air giving it longer range. It would be useful for stopping a suspicious boat approaching a warship without having to blast it out of the water.

The initiative is known as Innovative Science and Technology in Counter-Terrorism (INSTINCT), and it’s part of the broader Science and Technology Counter-Terrorism Strategy known as CONTEST. It’s not all about stopping boats and defusing bombs though, as the website of a recent INSTINCT event shows.

Called “Intent in Crowded places” the event was held to solicit ideas on how to spot a terrorist in a crowd. Other initiatives look at spotting terrorists by sniffing out explosives but “In this instance we would like to concentrate on intent and behaviour. ” This means looking at any possible indicators of intent, however they might be detected:

INSTINCT seeks any innovative science or technology that could enhance our ability to understand, characterise, detect, or influence intent in crowded places, be it hostile or not. … While OSCT is interested in developing knowledge around hostile intent, the intent of those who are friendly or ambivalent is also important. The intent of the innocent in a terrorist incident is significant because it will affect the level of danger and the likelihood of injury. In a search scenario, it is important that we can focus effort on those who are most likely to have hostile intent.

This briefing goes on to explain that detecting non-hostile individuals is also useful, so the hostile ones can be identified by a process of elimination. It also describes some of the research that will be required to back it up, in terms of characterising and understanding exactly what “hostile intent” is and how it changes over time. Someone may start off with no particular intent but may become hostile in response to a particular stimulus (like “this way, sir, we need to do a full body search”). The domains being investigated include social science, neurology, psychology and related disciplines.

The program even goes as far as asking about influencing intent –- though this seems to be more about designing buildings to encourage safe movement away from danger than mind control rays.

Darpa’s have previously investigated brain-screening technology which might be able to detect intent, which led to some concern about prosecutions for “thoughtcrime.” And Darpa’s Rapid Checkpoint Screening Program looked at a range of physiological indicators to see whether it would be possible to spot whether someone was lying at a checkpoint interview (the answer appears to be “yes”, with some provisos), and whether the technology could be extended to read the body language, pulse rate and so on of people just standing in line.

Britain differs from America in the level of surveillance that is considered acceptable. Omnipresent CCTV cameras are a fact of life here, though their effectiveness in combatting crime and terrorism is still a matter of debate. The Evening Standard newspaper complained that in spite of over 10,000 official CCTV cameras, 80% of crimes in London remain unsolved. The existing network means that, unlike in the US, it would be relatively easy to deploy new technology to detect hostile intention alongside or within the CCTV set up.

Admiral Lord West, Britain’s counter terrorism minister, also mentioned to the BBC that there were other initiatives which include countering cyber terrorism and “investigating how to intercept new methods of telecommunications.”

New technology is clearly on the way. And it’s not just about providing James Bond with a boat-stopping bazooka.

Sudan President Dismisses Powerful Spy Chief

Via Yahoo! News (AP) -

Sudan's official news agency says the president has dismissed the country's powerful head of national security and intelligence.

Thursday's SUNA report says Salah Ghosh has been appointed an adviser to President Omar al-Bashir, a less prominent position.

It was not immediately clear why the intelligence chief was dismissed.

Ghosh assumed his post in the mid-1990s and has cooperated closely with the U.S. in the fight against terror.

Ghosh was replaced by his deputy.

Happy Birthday Pakistan

Pakistan just turned 62....

The Dominion of Pakistan was formed on 14 August 1947 pursuant to the Indian Independence Act 1947, which created the independent dominions of Pakistan and the Union of India and received the Royal Assent on 18 July, 1947.

The Dominion of Pakistan became the Islamic Republic of Pakistan in 1956, and the People's Republic of Bangladesh became an independent state in 1971.

Thursday, August 13, 2009

Stephen Hawking Awarded the Highest US Civilian Honour

Via BBC -

President Barack Obama has awarded the highest US civilian honour - the Presidential Medal of Freedom - to 16 people praised as "agents of change".

Recipients included South African human rights champion Archbishop Desmond Tutu and British scientist Stephen Hawking.

Tennis player Billie Jean King and former Irish President Mary Robinson were also honoured at the White House.

Posthumous medals were awarded to US gay-rights activist Harvey Milk and Republican Senator Jack Kemp.

-------------------------------

The Presidential Medal of Freedom is a decoration bestowed by the President of the United States and is, along with the equivalent Congressional Gold Medal bestowed by an act of Congress, the highest civilian award in the United States. It is designed to recognize individuals who have made "an especially meritorious contribution to the security or national interests of the United States, world peace, cultural or other significant public or private endeavors." The award is not limited to United States citizens and, while a civilian award, can also be awarded to military personnel and worn on the uniform.

Why Flamingoes Stand on One Leg

Via BBC (Earth News) -

It is one of the simplest, but most enigmatic mysteries of nature: just why do flamingoes like to stand on one leg?

The question is asked by zoo visitors and biologists alike, but while numerous theories abound, no-one has yet provided a definitive explanation.

Now after conducting an exhaustive study of captive Caribbean flamingoes, two scientists believe they finally have the answer.

Flamingoes stand on one leg to regulate their body temperature, they say.

[...]

At first, they examined whether standing on one leg helps reduce fatigue in the birds' legs, or helps flamingos escape from predators more quickly, by shortening the time to take flight.

Both are commonly proposed as reasons for unipedal resting in flamingoes.

The scientists ruled out each as a benefit of standing on one leg, as their research showed it took flamingoes longer, and therefore more energy, to move forward after resting on one leg than after resting on two.

The birds also showed no preference for which leg they stood on.

Nor did standing on one leg help the birds balance when conditions were windy, another proposed idea.

[...]

However, the researchers did find that flamingoes prefer to stand on one leg far more often when they are standing in water than when standing on land, they report in the journal Zoo Biology.

"As water invariably draws away more body heat, this result supports the thermoregulation hypothesis," says Anderson.

In short, the birds stand on one leg to conserve body heat. If they put two legs in the water, rather than one, they would lose more heat than is healthy, particularly as they spend so much time wading.

"The results provide definitive evidence that thermoregulation is a principal function of unipedal resting in flamingoes," Anderson confirms.

The birds also likely alternate which leg they stand on to avoid one leg becoming too cold.

"If they stood on one leg consistently, they would risk greater loss of body heat and potential tissue damage in the cold," says Anderson.

The researchers also discounted some other more outlandish theories, such as one that suggests standing on one leg helps flamingoes circulate blood better by limiting the Effects of gravity on their circulatory systems.

But they don't eliminate the idea that there may be added benefits as well as conserving body heat.

"Given the wading lifestyle of flamingoes, perhaps unipedal resting helps reduce fungal or parasite load as well," says Anderson.

Others birds, such as herons, storks, ducks and many others also often stand on a single leg in water, perhaps for the same reasons as flamingoes.

But as flamingoes tend to spend much longer filter feeding in water than these other birds, this remains speculation, Anderson says.

Wednesday, August 12, 2009

Novel H1N1 Flu Situation Update

http://www.cdc.gov/h1n1flu/update.htm

Data reported to CDC by August 7, 2009, 11:00 AM ET.

A total of 6,506 hospitalizations and 436 deaths associated with novel influenza A (H1N1) viruses have been reported to CDC in 50 reporting States and Territories (including the District of Columbia, American Samoa, Guam, Puerto Rico and the U.S. Virgin Islands).

The number of hospitalized novel H1N1 cases and deaths presented above are an aggregate of reports received by CDC from U.S. states and territories and will be updated weekly each Friday at 11am. For state level information, refer to state health departments.

CDC discontinued reporting of individual confirmed and probable cases of novel H1N1 infection on July 24, 2009. CDC will report the total number of hospitalizations and deaths weekly, and continue to use its traditional surveillance systems to track the progress of the novel H1N1 flu outbreak. For more information about CDC’s novel H1N1 influenza surveillance system, see Questions & Answers About CDC's Novel H1N1 Influenza Surveillance.

--------------------------------------

Pandemic (H1N1) 2009 - update 61
6 August 2009

The breakdown of the number of laboratory-confirmed cases is given in this map.

Cumulative number of global laboratory-confirmed cases = 177,457 (1462 deaths)

WHO has a very cool interface map as well...which requires Flash. The numbers are a little behind, but it gives a very cool overall.

Six Arrested in Al-Qaeda Plot on U.S. Base in Kuwait

Via CNN -

Kuwaiti security forces arrested six Kuwaitis linked to al Qaeda who planned to attack a U.S. military installation, the country's state-run news agency reported Tuesday.

The suspects had planned to bomb Camp Arifjan during the upcoming Muslim holy month of Ramadan, Kuwaiti security sources said.

It is unclear when the arrests took place.

Camp Arifjan, outside Kuwait City near the country's border with Saudi Arabia, is used as a logistical base and transit point for U.S. troops deploying to and from neighboring Iraq, according to the U.S. Defense Department.

U.S. State Department spokesman Robert Wood congratulated Kuwait "on the reported arrest of terrorists targeting U.S. forces and Kuwait facilities."

"... Kuwait has been an outstanding host for the United States armed forces. This is evidence of the strong U.S.-Kuwait partnership against al Qaeda."

The U.S. military had no further information.

The operation was a Kuwaiti-led one, and so the Kuwaitis have the details on the intel and the people they apprehended," said Navy Capt. Jack Hanzlik, a spokesman for U.S. Central Command.

The plot also involved an attack on Kuwait's State Security Service headquarters and other government facilities, according to the Kuwait News Agency, which cited a statement from the Interior Ministry.

An investigation into the alleged plot is ongoing, the news agency reported.

Two suspects confessed Tuesday that they planned to attack Camp Arifjan with an explosives-laden truck during Ramadan, which begins August 21, the security sources said.

The other four suspects will be interrogated Wednesday, the sources said.

Camp Arifjan is the forward headquarters for the U.S. Army Central Command in the region. It is a major logistics base for the U.S. military and generally houses thousands of American troops.

GAO Report: Security Problems Persist at U.S. Biolabs

Via NTI.org -

The United States should move faster to implement security recommendations at laboratories handling the most lethal pathogens, congressional investigators said in a report released today (see GSN, June 9).

The Government Accountability Office faulted the "limited action" of the Centers for Disease Control and Prevention to establish a consistent security strategy for the nation's five Biosafety Level 4 laboratories, which handle incurable disease agents such as Ebola, the Associated Press reported after obtaining a copy of the document before its release.

"Although CDC has taken some modest steps for studying how to improve perimeter security controls for all BSL-4 labs, CDC has not established a detailed plan to implement our recommendation," the report states.

A CDC panel is expected to review security vulnerabilities at the sites; congressional auditors urged the agency to release records that would open its proceedings to public scrutiny.

Last year, the investigators noted security problems at two sensitive biological defense facilities, which AP identified as an Atlanta laboratory managed by Georgia State University and the Southwest Foundation for Biomedical Research in San Antonio, Texas (see GSN, Oct. 16, 2008). Among the security deficiencies cited were the failure to fully wall off the Atlanta facility and inadequate deployment of surveillance cameras, intruder detectors and armed guards at the Texas research center, the 2008 report said.

Without naming specific laboratories, this week's report says that two sites have taken steps to address previously noted security problems. The Atlanta facility has implemented "a significant number" of GAO recommendations to bolster security while the San Antonio sites has made only "a few changes," the report states. The other three BSL-4 sites had notably better security measures, according to AP.

"I am very troubled that the GAO found significant deficiencies in perimeter security," said Senator Susan Collins (R-Maine), who called for this week's report.

Collins and Senator Joseph Lieberman (I-Conn.) are expected to introduce a bill in September that would heighten security requirements at the sensitive germ facilities (Sam Hananel, Associated Press/Yahoo!News, Aug. 5).

Killer Drones to Get Sound System

Via Wired (Danger Room) -

Your Predator drone has all the latest gear, including communications, laser target designator, day and night cameras and, of course, Hellfire missiles. But, according to Special Operations Command, it still needs that essential finishing touch: the latest sound system. They are setting out to correct this, providing speakers not just for drones but also for plenty of other applications, in a new high-tech loudspeaker program.

Loudspeakers are already used for psychological warfare operations (psyops) in Iraq and elsewhere, but the current Family of Loudspeakers is looking a bit old, having been designed in the 90’s. So SOCOM is looking for a Next Generation Loudspeaker System (NGLS) “which will consist of seven variants: manpack; ground vehicle/watercraft; unmanned air vehicle; unmanned ground vehicle; scatterable media long duration; scatterable media short duration; and sonic projection (focused sound).”

The manpack and vehicle speakers will be a direct replacement for existing systems, but the unmanned and scatterable versions will be a new capability, especially as they are intended to be “interconnected using secure wireless technology to form sets of loudspeakers that provide high quality recorded audio, live dissemination, and acoustic deception capability.”

A set of scattered, networked speakers could certainly create some confusing sound effects. It could create the impression of a patrol or a vehicle moving around, surrounding the enemy with phantoms while masking the presence of real forces.

Special Forces have already had good results using focused sound in the form of the long Range Acoustic Device (LRAD). The unofficial PsyWarrior site reports that LRAD could be clearly heard at 1,400 meters, and it proved a handy way of communicating with the locals. “Iraqis were seen writing down the counter-terrorism tip-line number at over 600 meters range.”

It also has its uses in operations, not only for clearing civilians from streets and rooftops during operations and issuing instructions, but also for “drawing out enemy snipers who are subsequently destroyed by our own snipers.”

Diebold Quietly Patches Security Flaw in Vote Counting Software

Via Wired (Threat Level) -

Premier Election Solutions, formerly Diebold, has patched a serious security weakness in its election tabulation software used in the majority of states, according to a lab that tested the new version and a federal commission that certified it.

The flaw in the tabulation software was discovered by Wired.com earlier this year, and involved the program’s auditing logs. The logs failed to record significant events occurring on a computer running the software, including the act of someone deleting votes during or after an election. The logs also failed to record who performed an action on the system, and listed some events with the wrong date and timestamps.

A new version of the software does record such events, and includes other security safeguards that would prevent the system from operating if the event log were somehow shut down, according to iBeta Quality Assurance, the Colorado testing lab that examined the software for the federal government.

It’s not known if Premier will offer the more secure version to election officials who purchased previous software. The company did not respond to a call for comment Tuesday.

Called the Global Election Management System, or GEMS, the software is used to tabulate votes cast on Premier/Diebold touchscreen and optical-scan machines, among other functions, and is used in more than 1,400 election districts in nearly three dozen states. Maryland and Georgia, which use Premier systems exclusively, count every vote statewide with the software. GEMS runs on the Windows 2003 and Windows XP operating systems.

Official federal voting system standards require audit logs to record all normal and abnormal events that occur on the system.

Premier publicly acknowledged the flaw two months after Wired.com’s report, in a public hearing last March. When asked by a member of the California secretary of state’s staff if Premier had done anything to address the problem, Justin Bales, general service manager for Premier’s western region said, “No, not yet.”

Bales went on to say that the GEMS logs had been the same since the software was first created more than a decade ago.

“We never, again, intended for any malicious intent and not to log certain activities,” Bales said. “It was just not in the initial program, but now we’re taking a serious look at that.”

What Stormtroopers Do On Their Day Off

Via wildammo.com -

Stormtroopers aren’t fighting in battles every single day like you see in the Star Wars films. Here’s what they do when they have some free time.

Photographs by Stéfan. View his entire daily series of Stormtrooper photographs here.

McAfee Leaks 1,400 Security Pro Details

Via Risky.biz (July 29th, 2009) -

Security software maker McAfee has accidentally e-mailed the full contact details of 1,400 IT security professionals to an unknown number of recipients.

The marketing spreadsheet contained the full names, titles, organisation names, phone numbers and e-mail addresses of all who had registered for or attended the company's recent Strategic Security Summit on July 17 in Sydney.

"We did have a human error where the seminar contact list was attached to a promotional e-mail that was sent to... we don't know how many of the delegates," McAfee's Asia Pacific President, Steve Redman, told Risky.Biz by phone. "The important thing to note is this was not financial information, not mission critical information, it was a contact list."

The list was mostly comprised of the details of in-house IT security professionals for Australian organisations. It included the details of those who had attended, those who registered but never showed up, and those who walked in without registering.

The company tried recalling the message after it accidentally leaked, and subsequently sent an e-mail asking those who may have received it to delete the contact list.

As such, Redman says the company will not be contacting everyone on the marketing list to inform them of the leak. "We don't know whether all those people deleted it," he says. "If 50 people got our list... and then we asked them all to delete it and they did, then the information's not out there."

Risky.Biz has sighted the list -- which contains comprehensive contact details for security professionals from banking institutions, government departments and other large enterprises -- throwing doubt on Redman's hopes the list has been deleted.

Chris Gatford, director of HackLabs attended the event and was alarmed when he learned of the leak. "It contained my registration information," he says. "I am not happy about it sitting in unknown hands."

He says he's surprised McAfee would be so careless with what he describes as sensitive information. He also disputes Redman's assertion the leak is trivial because it is a mere contact list.

"I am sure [McAfee's] competitors would be very excited to have this fall into their inbox," he says. "[And] that list would be great to attack as it is a who's who of the security gatekeepers of Australia's largest organisations."

One in 78: The Chances Your Comms are Being Monitored by the UK Gov

Via Silicon.com -

What are the chances the government wants to monitor you?

Worries over ordinary citizens being tracked by the government may seem like Big Brother paranoia, but the likelihood you're on the Whitehall's watch list is far higher than you might suppose.

Figures that emerged this week reveal that, in 2008, government bodies asked to see the communications data for one in 78 adults in the UK under the Regulation of Investigatory Powers Act (Ripa).

ZDNet.co.uk has more - click here for the full story on the government's Ripa requests to monitor citizens' communications data.

UK Convicts Two for Refusal to Decrypt Data

Via The Register UK -

Two people have been successfully prosecuted for refusing to provide authorities with their encryption keys, resulting in landmark convictions that may have carried jail sentences of up to five years.

The government said today it does not know their fate.

The power to force people to unscramble their data was granted to authorities in October 2007. Between 1 April, 2008 and 31 March this year the first two convictions were obtained.

The disclosure was made by Sir Christopher Rose, the government's Chief Surveillance Commissioner, in his recent annual report.

The former High Court judge did not provide details of the crimes being investigated in the case of either individual - neither of whom were necessarily suspects - nor of the sentences they received.

The Crown Prosecution Service said it was unable to track down information on the legal milestones without the defendants' names.

Failure to comply with a section 49 notice carries a sentence of up to two years jail plus fines. Failure to comply during a national security investigation carries up to five years jail.

Sir Christopher reported that all of the 15 section 49 notices served over the year - including the two that resulted in convictions - were in "counter terrorism, child indecency and domestic extremism" cases.

The Register has established that the woman served with the first section 49 notice, as part of an animal rights extremism investigation, was not one of those convicted for failing to comply. She was later convicted and jailed on blackmail charges.

Of the 15 individuals served, 11 did not comply with the notices. Of the 11, seven were charged and two convicted. Sir Christopher did not report whether prosecutions failed or are pending against the five charged but not convicted in the period covered by his report.

To obtain a section 49 notice, police forces must first apply to the National Technical Assistance Centre (NTAC). Although its web presence suggests NTAC is part of the Home Office's Office of Security and Counter Terrorism, it is in fact located at the government's secretive Cheltenham code breaking centre, GCHQ.

GCHQ didn't immediately respond to a request for further information on the convictions. The Home Office said NTAC does not know the outcomes of the notices it approves.

NTAC approved a total of 26 applications for a section 49 notice during the period covered by the Chief Surveillance Commissioner's report, which does not say if any applications were refused. The judicial permission necessary to serve the notices was then sought in 17 cases. Judges did not refuse permission in any case.

One police force obtained and served a section 49 notice without NTAC approval while acting on "incorrect information from the Police National Legal Database", according to Sir Christopher. The action was dropped before it reached court.

----------------------------

Yet another reason not to live in the UK...but it is might only be a matter of time before the US government gets its way and goes down the same road. I hope our population doesn't roll over as easy here...

DNA Proves Body Not Terror Leader Noordin Top

Via ABC News -

Indonesian police have confirmed a man killed in a raid in Central Java on Saturday was wanted, but he was not the notorious fugitive Noordin Mohammad Top.

Indonesian police had hoped and then believed the man they had surrounded and then killed after a 17-hour siege in a remote rural house in Temanaggung was Top - the region's most wanted terrorist.

DNA tests have now confirmed that the man responsible for every terrorist attack in Indonesia since the first Bali bombings has escaped yet again.

The identity of the dead man is now confirmed to be Ibrohim, the florist who worked at Jakarta's Ritz Carlton and Marriott hotels.

Ibrohim left a resignation letter and disappeared the morning of the suicide bombings on July 17.

The bomb attacks at the Ritz Carlton and the nearby JW Marriott hotel killed nine people, including three Australians.

Police have released new security camera footage showing Ibrohim escorting the alleged Marriott bomber around the hotel nine days before the attack, and later bringing bomb-making material into the hotel's loading bay.

Officials say Ibrohim was hiding while a truck bomb was being completed near Jakarta with the intention that he would launch a suicide bomb attack targeting Indonesia's president.

Judge Orders Microsoft to Stop Selling Word

Via Neowin.net -

On Tuesday, a judge ordered Microsoft to stop selling Word, its flagship word processing software and one of the main components of the Microsoft Office System - namely part of Word 2003 and Word 2007. This also now extends to Word 2010 which contains the same feature set.

Judge Leonard Davis of the U.S. District Court for the Eastern District of Texas issued a permanent injunction that "prohibits Microsoft from selling or importing to the United States any Microsoft Word products that have the capability of opening .XML, .DOCX or DOCM files (XML files) containing custom XML," according to a statement released by attorneys for the plantiff, i4i, CNET reports. Microsoft stated that it planned to appeal the verdict. i4i sued Microsoft in March 2007 that Microsoft violated its 1998 patent (No. 5,787,449) for a document system that "eliminated the need for manually embedded formatting codes. "

XML (Extensible Markup Language) is considered a "page description language," with one of its key features being that humans are able to read it legibly, not just PC's and other devices. XML allows developers to create their own tags for data.

In May 2009, a jury in Tyler, Texas, ruled in favor of i4i that the custom XML tagging of Word 2003 and Word 2007 infringed on the patent owned by i4i and ordered Microsoft to pay $200 million in compensation.

In Tuesday's ruling, Microsoft was also ordered to pay an additional $40 million for willful infringement, as well as $37 million in prejudgment interest. Microsoft must comply with the injunction within 60 days and the injunction specifically states that Microsoft way not test, demonstrate or market Word products that contain the XML feature in question.

The Microsoft Office system overall generated a 9.3 billion dollar profit in 2008 alone, and this move would hurt that business immensely.

---------------------------

Wow...freaking unbelievable. I went to college in Tyler, TX and spent many years of my life in that town...and I really can't see how they can find a jury that has the ability to fully understand this stuff....

Plus, Smith County (of which Tyler is the seat) isn't really known for its high-standard legal system......Smith County Justice anyone?

Tuesday, August 11, 2009

Chechen Activist & Husband Found Dead in Car Trunk

Via Yahoo! News (AP) -

The bullet-riddled bodies of a Chechen activist and her husband were found in the trunk of their car Tuesday, the latest in a string of high-profile killings in Chechnya under its Kremlin-backed leader.

Zarema Sadulayeva and her husband, Alik Dzhabrailov, both 33, had been abducted on Monday from the offices of Save the Generation, the children's charity she runs in the southern Russian republic.

Her relatives, who gathered in her home village of Shalazhi for her burial on Tuesday, said the men who took the couple away identified themselves as police.

The killings followed last month's kidnapping and shooting death of one of Chechnya's best-known rights activists, Nataliya Estemirova, whose body was found on a roadside. As head of Memorial rights group's Chechen branch, Estemirova had exposed alleged rights abuses by the forces of Chechen President Ramzan Kadyrov.

Amnesty International called the killing a reminder "of the climate of impunity in Chechnya," and said officials' failure to investigate the murders of rights activists was a "strong indication that those authorities are at least acquiescent to these crimes," according to a statement.

The Chechen leader, who has denied accusations of being behind Estemirova's July 15 killing, blamed the latest killings on unspecified forces that want to destabilize the republic.

"It was a cruel crime and a challenge to the authorities," Kadyrov said in televised comments. "People who committed this crime wanted to split society. Some don't like stability in the Chechen republic."

A lone security guard witnessed the abduction in Grozny, the Chechen capital. Those who talked to him, including Sadulayeva's uncle and a rights activist, said he described five or six men, some in military fatigues and others in civilian clothing.

Rights activist Kheda Saratova said the guard, who is now under the protection of Chechnya's human rights ombudsman, described the men taking Sadulayeva and her husband away from the office, and then returning to collect the couple's two cell phones and Sadulayeva's car.

Vakhit Sadulayev, the victim's uncle, cited the security guard as saying the men identified themselves as police. Their main target appeared to have been Dzhabrailov, he said, and when they tried to take him away alone his wife insisted on going with them.

The couple were found shot in the head and chest, the Chechen Interior Ministry said. Their bodies had been stuffed into the trunk of their car, which was parked in a Grozny suburb, according to the rights group Memorial.

Sadulayeva and Dzhabrailov had married a few months ago, after he served time in prison on charges of being a member of a Chechen separatist movement.

Kadyrov speculated that Dzhabrailov was killed in a blood feud, and said he could see no reason for the death of Sadulayeva, whose work helping disabled children had "not bothered anyone."

Sadulayeva's group, which worked with UNICEF, had been helping Chechen children injured during the region's two devastating separatist wars over the last 15 years.

In 2005, a previous leader of the organization was taken into custody by security forces on suspicions of sympathizing with the separatists. He later turned up dead.

At Sadulayeva's funeral Tuesday, her father told a story of her refusing to allow her grandmother to take a few pounds from a large rice shipment. "You have four sons who can buy you rice," Abdulla Sadulayev recalled his daughter saying. "These children have no one."

"She was never driven by money or riches, and honestly fulfilled her mission," he said.

Kadyrov promised to find the killers and punish them. Federal prosecutors also said they would join the investigation.

The Chechen leader had much harsher words for Estemirova, whom he denounced in a recent Radio Liberty interview as a person who "never had any honor, dignity or conscience." The interview was published on the broadcaster's Web site Saturday.

Chechen separatists battled Russian troops and pro-Moscow Chechen forces through two wars after the 1991 Soviet collapse. The fighting has dwindled in recent years as Kadyrov consolidated his control, but opponents accuse him of imposing a regime of fear and impunity. Many of his critics and political rivals have been killed.

Rights activists say that Moscow, by backing Kadyrov, has created a climate that encourages unchecked brutality.

"Our law enforcement structures no longer exist to protect us," Lyudmila Alexeyeva, head of the Moscow Helsinki Group, said Tuesday on Ekho Moskvy radio. "They are protecting the authorities from citizens."

Members of the Helsinki Group issued a statement decrying the killings and promising to continue the fight for the protection of human rights in Russia.

In preparation for the radio program, Ekho Moskvy tried to contact other rights activists in Chechnya.

"We looked down our list and next to almost every name is the word 'died,' 'died,' 'died,'" the anchor said.

CIA Lock Picking Field Operative Training Manual

http://www.mentalswitch.com/stuff/ebooks/CIA-Lock-Picking-Manual.pdf

Was it really put together by the CIA? Who knows...but unlikely.

Does it contain some good information? Yep

How old is the "manual"? Who knows..but the metadata says the PDF was created in 2002



Hat tip to @indi303 for the information....

US Soldier Charged in Mexican Cartel Killing

Via Yahoo! News (AP) -

An 18-year-old U.S. Army soldier and two other men have been charged with capital murder in the contract killing of a midlevel Mexican drug cartel official who was also a U.S. informant.

Pfc. Michael Jackson Apodaca, who was based at Fort Bliss, near El Paso, and Christopher Duran, 17, were hired by 30-year-old Ruben Rodriguez Dorado to carry out the May 15 shooting of Jose Daniel Gonzalez Galeana, police said Tuesday. Gonzalez was shot eight times outside his pricey El Paso home.

The three men were arrested Monday night and were being held on $1 million bond each. It was not immediately clear if any of the men had retained a lawyer. Online court records did not list an attorney for any of the men, and police said they did not know either.

Gonzalez, a lieutenant in the Juarez drug cartel, was also an informant for the U.S. Immigration and Customs Enforcement agency, according to three U.S. officials who spoke on condition of anonymity because they were not authorized to speak about it.

A law enforcement official familiar with the case told The Associated Press on Tuesday that Rodriguez, who police believe orchestrated Gonzalez's killing, is also a lieutenant in the Juarez cartel.

That official spoke on the condition of anonymity because he is not authorized to speak about the case.

Details of Apodaca's military service were not immediately available.

"Anytime someone does something like this, and a soldier in our case, it's terrible," Fort Bliss spokeswoman Jean Offutt said, without commenting directly on the case.

Before the killing, Gonzalez lived what appeared to be a routine life in an upscale east El Paso neighborhood where his neighbors include El Paso Police Chief Greg Allen and El Paso County District Attorney Jaime Esparza. Business records show that he ran a freight company from his two-story stucco house, along with a day care and an auto business.

Google Provides Peek into New Search Engine

Via physorg.com (AP) -

Google has lifted the lid on a new version of its search engine, allowing users to look at the results it will generate.

The new engine, available at a separate address, looks the same as the current one but ranks results differently, which could affect businesses who rely on Google results to drive traffic.

In a blog posting late Monday, Google Inc. says the new engine, code-named "Caffeine," will be faster, more accurate and more comprehensive.

The public testing of the new engine comes two weeks after Microsoft Corp. struck a deal to replace Yahoo Inc.'s search engine, with its own Google competitor, called Bing. Yahoo Search and Bing are the second and third most popular engines after Google.

-----------------------------------

Check out "Caffeine" yourself....
http://www2.sandbox.google.com/

Monday, August 10, 2009

Photo of the Day - Winner of the Nokia Photography Competition @ Cambridge


http://news.bbc.co.uk/2/hi/in_pictures/8192569.stm

Each year, Cambridge University runs a competition to find the best photos taken by staff and students from its engineering department. The winning picture shows "Pebble", a low-cost, deep-sea photographic vessel.

------------------------------

http://www.eng.cam.ac.uk/news/stories/2009/photocomp_winner09/

In 2009 a small team at the Department of Engineering designed and built a low-cost, deep-sea photographic vessel. This photograph shows "Pebble" undergoing pool trials at Cranfield University. Whilst deep-sea photography has been done before, Pebble differed in one key respect. Cost. Pebble was built for £1800, making her tens of times less expensive than comparable deep-sea craft. This was achieved by using off-the-shelf components, almost no moving parts, and a pressure-balanced design. It is planned that subsequent years of Cambridge undergraduate engineers will improve the design and reduce the cost to less than £1000, making deep sea photography more affordable than ever before. Project Pebble was sponsored by BAE Systems Submarine Solutions, and supported by Tritech International, EADS, and Pentax.

The winning team won a Nokia N95 8GB phone that has been generously donated by Nokia.

iPhone 3GS Hardware Encryption Easy to Circumvent

Via Tidbits.com -

A mere three days after I published an article touting the enhanced security of the iPhone 3GS - see "iPhone 3GS Offers Enterprise-Class Security for Everyone", 2009-07-20 - security researcher Jonathan Zdziarski revealed a simple, only moderately technical technique for completely circumventing the iPhone's passcode lock and encryption. As a result, the iPhone 3GS encryption can no longer be considered a security control for consumers or enterprises until Apple releases a fix.

Although encryption is one of the most fundamental tools available in the security arsenal, it can be difficult to implement properly. In this case, it isn't that the encryption itself is flawed (although that happens), but that the implementation of the encryption leaves cracks for attackers.

Implementation issues that can hamper encryption security include generating keys improperly, protecting them poorly, exchanging them insecurely - and even leaving doors wide open such that the encryption can be sidestepped entirely. This has allowed exploits in WEP (Wired Equivalent Privacy) in Wi-Fi (which also had cryptographic flaws), early SSL implementations in Web browsers, and stored passwords in most major operating systems.

It appears that Apple made a fundamental mistake in encrypting the iPhone 3GS. It's a mistake we've seen before in other tools, but one Apple has managed to avoid elsewhere, such as Mac OS X's FileVault.

Taliban Leadership: Who's Dead, Who's Alive

Via MEMRI -

Friday, August 7

Pakistan's Interior Minister Rehman Malik reports about "information and evidences" being received that Baitullah Mehsud was killed in a U.S. drone attack two days previously in the tribal district of South Waziristan, according to the website of Urdu-language newspaper Roznama Jang.

Later the same day, Pakistani Foreign Minister Shah Mehmood Qureshi quotes Pakistani intelligence as saying that Baitullah Mehsud "has been taken out" and that the government is collecting evidence "to confirm 100 percent," according to the website of ARY OneWorld television. Qureshi's statement is taken as confirmation of Baitullah's killing and speculation grows as to who will succeed him.

Saturday, August 8

According to the Afghan website Pajhwok.com, Qari Hidayatullah, a close aide of Baitullah Mehsud, rejects media reports that Baitullah Mehsud has been killed.

That same day, a report on the website of Pakistani daily The News quotes Hakimullah Mehsud, a strong contender to succeed Baitullah Mehsud, as saying that the Taliban chief is alive. Hakimullah Mehsud also dismisses media reports stating that a meeting of Taliban's Shura (executive council) is discussing who should succeed Baitullah Mehsud, saying that Shura meetings are routine.

Sunday, August 9

The mystery over Baitullah Mehsud's death deepens, after a report on the website of Pakistani daily Dawn quotes "government and security officials" as saying that a Taliban commander, either Hakimullah Mehsud or Waliur Rahman, has been killed during the Shura meeting to choose a successor to Baitullah Mehsud.

On the same day, Interior Minister Rehman Malik said that either Hakimullah Mehsud or Waliur Rahman has been killed, according to the Urdu-language newspaper Roznama Jang. The same daily quotes Hakimullah Mehsud as saying that "the Emir [Baitullah Mehsud is alive and safe. He is in hiding like Osama bin Laden and Mullah Omar, under a war strategy."

According to a report in Lahore-based Daily Times newspaper, Taliban commander Qari Hussain maintains that Baitullah Mehsud is alive. On the same day, Foreign Minister Shah Mehmood Qureshi throws a challenge, saying that if Baitullah Mehsud is alive, he should prove it.

Monday, August 10

According to a report in the Lahore-based Daily Times, pro-government rival militant commander Haji Turkistan Bhitani says that Baitullah Mehsud was killed along with 40 fighters in the August 5 U.S. attack, and that Hakimullah Mehsud and Waliur Rahman were killed in a fight over the succession.

According to a report in the Pakistani daily The News, Maulana Noor Said, a close aide of Baitullah Mehsud, insisted that Baitullah Mehsud survived the U.S. drone attack, but is "ill and poor in health." He adds that a video of Baitullah Mehsud will be released soon, either today or tomorrow (August 11, 2009) to prove that he is alive.

Gh0st RAT Source Code

http://xfocus.net/tools/200803/1245.html

Ghost Rat (or Gh0st RAT), is a Trojan horse that Chinese operatives of GhostNet used to hack into some of the most sensitive computer networks on Earth.

Security Researchers Zero in on Twitter Hackers

Via ComputerWorld -

Security experts are making progress in their efforts to identify the hackers responsible for the distributed denial-of-service (DDoS) attacks that crippled Twitter for several hours yesterday.

They have also come up with strong evidence that confirms claims the DDoS rampage that brought down Twitter and hit Facebook, Google's YouTube and LiveJournal, were caused by attacks targeting a pro-Georgian activist and blogger.

But they have yet to nail down exactly who was behind the attacks, how they were conducted, and from where.

Twitter, meanwhile, admitted that the attacks were "geopolitical in motivation."

"This was a very targeted attack, and what the research shows is that it was aimed at one particular person, and that person's accounts on Twitter, Facebook, YouTube and LiveJournal," said Dave Marcus, director of security research at antivirus vendor McAfee.

McAfee has identified six separate DDoS attacks against various accounts registered to a user pegged as "Cyxymu," as well as a simultaneous spam e-mail campaign aimed at Cyxymu's Gmail account.

"We back-traced and correlated the data the attacks targeting Facebook, Twitter and others, and found commonalities in the IP [address] information," Marcus said.

Although McAfee was as of yet unable to identify the botnet responsible for the DDoS attacks, its trace-backs revealed that 29% of the machines composing the army of hijacked computers were located in Brazil. Turkish PCs accounted for another 9%, and Indian systems made up another 8%.

Marcus declined to guess the botnet's size. "That's kind of point of contention," he said. "In the case of Twitter, they've gone down before anyway, so it could have been small. Facebook, however, tends to be a lot more resilient, with a lot more load balancing and defensive measures." That might indicate the botnet, which hampered Facebook but didn't knock it offline, is larger.

"We're still looking at which botnet it was that did this," Marcus said.

So is Don Jackson, director of threat intelligence for SecureWorks and a noted DDoS expert, who last year at this time investigated Russian "cybermilitia" attacks against Georgia, the former Soviet republic that was then battling Russian military forces over a territorial dispute. "We don't have indication that it's part of a known botnet," Jackson said today. "For such a high-volume, high-profile DDoS [attack], there's a conspicuous lack of evidence."

Jackson and other researchers at SecureWorks haven't seen the usual chatter in known hacker and "hacktivist" forums, been able to locate any botnet command-and-control servers showing evidence of having ordered the DDoS attack, or found any clues that the usual commercial DDoS suspects, who make a living renting out bots for such attacks, were involved.

Sunday, August 9, 2009

Early Assessment of the Elimination of Taliban Commander Mehsud

Via CT Blog (by Dr Walid Phares) -

As reports are confirming the elimination of Pakistan Taliban leader Baitullah Mehsud, including Pakistani sources to al Jazeera, a growing debate is widening in the international media about the "value" of that event. Some analyses are using terms such as "turning point," while other are describing it as "lethal hit against Pakistan's Taliban." Evidently, authorities in Pakistan and the United States are logically rejoicing for the fact that a tough foe is gone. Intelligence estimates will soon tell how important what that successful drone and what would the field consequences be in the next weeks, months and maybe a year or two.

But it is important that the expert community help the public and decision makers in making a fair and accurate assessment of the event with the correct understanding of the value of the tactics employed on the Pakistan's front with the Taliban; but also one should suggest that no excesses should be projected in over estimating the impact on the "war." As the discussion is ongoing in the media and inside Government circles, following are eight points of assessment to be considered:

1. Tactically, the elimination of Baitullah Mehsud, as the direct commander of the Taliban terror networks is a real field victory for Pakistan's Government and, in perspective, a payback for the assassination of slain former Prime Minister Benazir Bhutto. Moreover, the vanishing of Mehsud can create conditions for progress of Pakistan's forces in south Waziristan, only for a short period of time and if Islamabad can mobilize enough popular support for the next stage of engagement against the Taliban.

2. It is also a victory to the global US intelligence and an indicator to current and future successful strikes via the technology employed by American deployment out of Afghanistan. It adds some deterrence to NATO presence in the region, but again, within limitations.

3. It will put some pressure on the Taliban and also on al Qaeda inside Pakistan, and psychological pressure on the Taliban inside Afghanistan

4. It could ease some past tensions between US and Pakistan military authorities regarding the use of missiles and drone attacks against Taliban, across the borders; but it will not transform the current discrete cooperation into a NATO like open collaboration.

However, on the other hand

a. We know almost for sure that the Taliban will select a new leader who will replace Mehsud. They may well select or add later a member of his own clan, family or entourage. The assessment will be made by the "war room" of the Jihadists in the region. In short, undoubtedly the Taliban campaign will continue.

b. Also one has to be ready that Taliban Pakistan, or their allies inside the country (and they have many) may try to assassinate important figures inside Pakistan, in retaliation.

d. Hence the elimination of Baitullah Mehsud is a tactical turning point that could be used to provoke more crumbling, but the window is very short.

e. Jihadi media and some al Jazeera commentators say his elimination will affect but not crumble the Taliban.

------------------

Dr Walid Phares is the Director of the Future Terrorism Project at the Foundation for the Defense of Democracies. He is the author of The Confrontation: Winning the War against Future Jihad.

Saturday, August 8, 2009

Skin Growths Saved Poisoned Ukrainian President

Via NewScientist.com -

Benign skin growths that erupted on the face of Ukrainian president Victor Yushchenko helped save his life after he was poisoned with dioxin five years ago.

That's the verdict of doctors who have treated and monitored Yushchenko since an unknown assassin made the attempt on his life by lacing his soup with dioxin during a dinner in Kiev on 5 September 2004.

It now turns out that the lumps that grew on his face and body as a result probably saved his life by isolating the dioxin away from his vital, internal organs. They also helped to detoxify the poison, known chemically as TCDD (2,3,7,8-tetrachlrodibenzo-p-dioxin), by producing powerful enzymes called cytochrome p450s that are normally confined to the liver.

The growths are rearrangements of skin, created from skin stem cells. "A new organ was created out of normal structures of the skin, and the tissue expressed very high levels of dioxin-metabolizing enzymes," says Jean Saurat, the dermatologist heading the team which treated Yushchenko at the Swiss Centre for Human Applied Toxicology in Geneva. "They were made to detoxify the dioxin."

"A hamartoma is a new organisation of normal cells that simply organise themselves differently," says Saurat. "So skin can be regarded as a detoxifying organ," he says.

Saurat says that at the start of treatment, Yushchenko had concentrations of TCDD 50,000 times higher than those typically found in people.

Benign skin growths that erupted on the face of Ukrainian president Victor Yushchenko helped save his life after he was poisoned with dioxin five years ago.

That's the verdict of doctors who have treated and monitored Yushchenko since an unknown assassin made the attempt on his life by lacing his soup with dioxin during a dinner in Kiev on 5 September 2004.

It now turns out that the lumps that grew on his face and body as a result probably saved his life by isolating the dioxin away from his vital, internal organs. They also helped to detoxify the poison, known chemically as TCDD (2,3,7,8-tetrachlrodibenzo-p-dioxin), by producing powerful enzymes called cytochrome p450s that are normally confined to the liver.

The growths are rearrangements of skin, created from skin stem cells. "A new organ was created out of normal structures of the skin, and the tissue expressed very high levels of dioxin-metabolizing enzymes," says Jean Saurat, the dermatologist heading the team which treated Yushchenko at the Swiss Centre for Human Applied Toxicology in Geneva. "They were made to detoxify the dioxin."

"A hamartoma is a new organisation of normal cells that simply organise themselves differently," says Saurat. "So skin can be regarded as a detoxifying organ," he says.

Saurat says that at the start of treatment, Yushchenko had concentrations of TCDD 50,000 times higher than those typically found in people.

Saurat declined to specify details of how his team treated Yushchenko, saying these will be disclosed in a forthcoming paper.

However, the study released this week reveals that the treatment involved the anti-obesity drug orlistat, and olestra, a zero-calorie, indigestible fat product developed but rejected for use in food because it absorbed vitamins on its way through the gut, and caused "anal leakage" in some consumers. Dioxin is known to be stored in fat. Saurat said Olestra was used early on, but was not the main component of the treatment.

By monitoring concentrations of dioxin in blood, fatty tissue, faeces, skin, urine and sweat, Saurat established that about 60 per cent of the dioxin was excreted unchanged, mainly in the faeces. It took about 15 months for half of the contaminant to be excreted.

"He's not completely clean yet, but we've got more than 95 per cent of it out now," says Saurat.

Measurements of 17 different types of dioxin showed that all except the TCDD were at concentrations expected in the general population, proving that he was poisoned with pure TCDD.

U.K. Defence Ministry Encourages Social Media Use

Via NextGov.com -

While the Pentagon studies the vulnerabilities of social networking sites, the United Kingdom's Defence Ministry issued a policy on Thursday that encouraged its troops to "blog, Tweet and engage online."

According to the Online Engagement Guidelines, U.K. troops "can make full use of Web sites such as Facebook and YouTube as long as they follow the same high standards of conduct and behavior online as would be expected elsewhere; always maintain personal information and operational security and be careful about the information they share online; and, get authorization from their chain of command when appropriate."

The Defence Ministry added that troops and civilian workers could post to social networking sites without prior authorization as long as they adhere to the guidelines on operational security and online behavior. The policy, touted in a Defence blog, represents "an important change over earlier rules, under which personnel always needed to seek authorization before publishing any work-related material," the ministry said.

The ministry released the new policy just days after the Pentagon announced it would study how social networking threatened security, with the intention of developing a new Web 2.0 strategy.

Shortly after the Pentagon announcement, it was reported that the U.S. Marine Corps had banned the use of social media. But the Corps has not prohibited its personnel from using their own computers to access or post to social network sites, said Lt. Craig Thomas, a spokesman for the Marines. The Corps has "absolutely not" banned access to sites such as YouTube, MySpace or Twitter, he said.

The Marine Corps issued an administrative instruction this week clarifying a policy for the entire Defense Department in May 2007. The policy, issued by the Defense Information Systems Agency, barred the use of department networks to access social networking sites because of the demand on limited bandwidth.

The instruction actually relaxed the 2007 policy, allowing organizations or personnel whose jobs or missions require access to social network Web sites to request a waiver to use Marine networks to do so, Thomas said.

He said recruiters, public affairs personnel and criminal investigators all need to access social network sites as part of their official duties. Other Marines can continue use their personal computers connected to non-Defense networks to access social network sites. Marines deployed in Afghanistan and Iraq can use non-Defense networks in those countries to post to social Web sites.

The Marine Corp issued a statement that similar to the United Kingdom, it embraced social networking. "Marines are encouraged to tell their stories on social networking sites using personal accounts, remembering the importance of operational security and that they are Marines at all times," the statement said.

Noordin Mohammed Top Commits Suicide During Standoff

Via The Long War Journal -

Noordin Mohammed Top, Asia's most wanted terrorist, committed suicide after a 12-hour standoff with Indonesian police in a remote farm house in Central Java.

Police made visual confirmation of Top through cameras attached to remote control robots that were deployed into the house and watched as he fled into a bathroom and, surrounded by a woman and three children, blew himself up, Metro TV reported. The explosion occurred at 8 am Saturday local-time (9 pm EDT Friday) and was carried on live television.

Top was a senior leader in Jemaah Islamiyah and was originally from Malaysia. He was known as a top recruiter, strategist, and fundraiser, and was behind the most deadly terror attacks in Indonesia. He masterminded the October 2002 Bali bombings, which killed 202 people and injured 209; the August 2003 Marriott Hotel bombing in Jakarta; the September 2004 bombing of the Australian Embassy in Jakarta; and the October 2005 Bali bombings. He split from Jemaah Islamiyah in late 2005 after disagreement over the use of violence with other leaders and became the emir of Tandzim al-Qaedat Indonesia. While ties between Top's group and al Qaeda have not yet been confirmed, his group has run Web forums that have collaborated with Jihadi forums known to be associated with al Qaeda. One such forum released an Indonesian-language propaganda video with the well-known al-Ekhlaas Forum in early 2008.

LTTE Leader Arrested

Via CT Blog -

Yesterday, Sri Lankan officials announced the arrest of the new leader of the Liberation Tigers of Tamil Elam (LTTE), Kumaran Pathmanathan (also known as KP or Selvarasa Pathmanathan). This is a major blow to the organization, especially coming on the heels of the major battlefield defeat that it suffered in May.

Of special relevance is a profile of Pathmanathan that Rohan Gunaratna contributed to the Center for Terrorism Research's newly-released report Terrorism in the West 2008, which I co-authored. To read the entire report, click here.

Friday, August 7, 2009

Apple Files "Consumer Abuse Detection System and Method" Patent

Via The Register UK -

Apple has filed a patent application for a technology that could detect, time-stamp, and remember "whether consumer abuse has occurred in an electronic device."

Apple's many patent filings usually focus on technologies that could benefit consumers. This one is aimed directly at benefitting Apple itself.

The filing, "Consumer Abuse Detection System and Method," describes a system that can determine when an "abuse event [is] detected by the one or more sensors [and] includes at least one of a liquid ingress event, a thermal event, a shock event, and a tamper event."

The system could then let customer-service personnel know that a device which had failed had been mucked around with by its owner and not simply failed on its own. Thus alerted, the service provider could determine that the problem was not covered by the device's warranty.

All well and good. What concerns us, however, is the following:

Consumer abuse may include exposing an electronic device to liquids, extreme temperatures, or excessive shock (e.g., the resulting impact from dropping the device). Consumer abuse may also result from tampering which may include any interaction with the device that is not related to operating the device in a normal manner (e.g., opening the casing or housing of a device and adding, removing, or altering the internal components).

Liquids? Of course. Excessive heat? Reasonable. Shock? Likewise. But "opening the casing or housing of a device"? That worries us.

Ever since the iPod was introduced, Apple has been sealing up its devices tighter than a drum, making such traditionally user-serviceable parts as batteries inaccessible. iPods, iPhones, MacBook Pros - all are locked up tight.

What's more, the filing indicates that the system could be employed in such a way as to disable a device if "customer abuse" - including "tampering" - were detected.

As alpha-geeks, we prefer to be able to open up any and all of our devices whenever it suits our needs - or, for that matter, even our whims.

The idea that a tamper-sensing system could disable our Apple devices if we had the temerity to open them up gives us pause.

Detecting that a dishonest cad had lied about how he dropped his iPhone into a pot of boiling beef broth is reasonable enough. But disabling said smartphone simply because an adventurous soul peeked inside seems a bit extreme.

Preventing a jive-ass mo-fo from gaming the warranty system? Good. Punishing curiosity? Bad.

Thursday, August 6, 2009

Theory: Twitter Attack Targeted Anti-Russian Blogger

Via The Register UK -

As Twitter struggled to return to normal Wednesday evening, a trickle of details suggested that the outage that left 30 million users unable to use the micro-blogging service for several hours, at least in part, may have been the result of a spam campaign that targeted a single user who vocally supports the Republic of Georgia.

According to Bill Woodcock, research director at the non-profit Packet Clearing House, the torrent of traffic that brought the site to its knees wasn't the result of a traditional DDoS, or distributed denial of service attack, but rather people who clicked on a link in spam messages that referenced a well-known blogger called Cyxymu.

As spam goes, the emails looked benign enough. One of them carried the subject "Visit my blog" and contained the words "thanks for looking at my blog" in the body. They contained respective links to Cyxymu's accounts on Twitter, Facebook, LiveJournal and YouTube, all of which also reported receiving abnormal amounts of traffic on Thursday.

"This was not like a botnet-style DDoS," Woodcock told The Register. "This was a joejob where people were just clicking on links in email and the people clicking on the links were not malefactors. They were just the sort of idiots that click on links in email without knowing what they are."

Joejobs are spam messages that are designed not to push Viagra but to induce someone to click on a link in the hopes of harming the site being linked to.

Twitter has so far said little on its blog and status page except that it spent much of the day fighting against a denial of service attack and that as late as 4:45 pm California time, latency problems caused some users to receive error pages. Company representatives didn't respond to emails seeking comment.

The theory was backed up by this article from CNET News, which quoted Facebook's security officer executive as saying the attacks targeting multiple websites all contained traffic linking to accounts held by Cyxymu.

"It was a simultaneous attack across a number of properties targeting him to keep his voice from being heard," Facebook's Max Kelly told reporter Elinor Mills. "We're actively investigating the source of the attacks and we hope to be able to find out the individuals involved in the back end and to take action against them if we can."

Kelly made no reference to spam messages, so it remained unclear if the emails were the only cause of the mass requests to Cyxymu's profiles or if there were other causes as well.

Cyxymu has long been viewed as an antagonist by some pro-Russian supporters, who take issue with the blogger's coverage of recent military conflicts in Georgia.

Hacker Deletes 3,000 Photos From Man's Flickr Account

Via switched.com -

A Flickr user recently woke up to his worst nightmare. His account, to which he had uploaded more than 3,000 photos over five years, was hacked and terminated by someone using a Hotmail account. But that's not all.

According to Gawker, Morgan Tepsic, a photographer and student living in Taiwan, spent days sending e-mails and making phone calls to both Flickr HQ and Yahoo! (owner of the site), only to have customer service reps tell him there was no way to recover the photographs, which he says he spent thousands of dollars developing. Tepsic says Flickr should have gone further to protect his account (for which he paid subscription fees) from hackers. He's right on, especially since he never received so much as an e-mail asking him to confirm the account's termination. As it stands, we can only assume that Flickr users pay to use a site that doesn't even backup its data. Gawker tried to get to the bottom of the site's backup procedures, but its e-mails to Yahoo! reps weren't returned.

In the meantime, Tepsic has launched a viral campaign against the photo service. While it's not likely that Flickr or Yahoo! will offer assistance, maybe other users can at least learn from Tepsic's nightmare. Don't rely solely on Web backup. [From: Gawker]

-------------------------------

Really, why would a photographer (professional or not) trust the cloud (Flickr, Facebook, Yahoo!, etc) so much...as to totally ignore the need for local backups?

I have even considered burning my photos from my local drive (which I regularly backup to an external HD) to DVDs and storing them along with my other important documents in a fireproof safe. If these photos were my life-blood / my profession...it would have already been done.