Tuesday, March 25, 2008

China Calls for 'Patriotic Education' for Tibet Monks

Via Washington Post -

BEIJING, March 25 -- China's security chief called for stepping up "patriotic education" in Tibet's monasteries, the state-run Tibet Daily said Tuesday, as prosecutors for the first time charged demonstrators in the largely peaceful, monk-led protests that later exploded into riots in the region.

Public Security Minister Meng Jianzhu led the first high-level central government visit to Tibet since the riots broke out this month. In the face of international criticism of China's crackdown, he stressed that the government would "fight an active publicity battle" and solicit the help of Communist Party cadres.

His call for broader "patriotic education" indicated the party would also move to exert greater control over religion in Tibet, requiring more Tibetans to accept the region as an inalienable part of China, denounce the Dalai Lama as a separatist and recognize the Chinese-appointed Panchen Lama. Such campaigns were first launched in 1996.

Angered by foreign sympathy for the protesters and support for the Dalai Lama, China is bearing down hard on the exiled Tibetan religious leader, blaming him and his followers for stirring up trouble in an effort to sabotage the Beijing Olympics in August.

The Chinese crackdown has drawn international concern, with some government leaders suggesting a boycott of the opening ceremony of the Games. On Tuesday, when asked about the possibility, French President Nicolas Sarkozy said, "All options are open, and I appeal to the Chinese leaders' sense of responsibility." He added that he had sent a message to Chinese President Hu Jintao noting his concern over the violence.

The European Parliament, whose president has said a boycott should be considered, has scheduled a special debate on the Tibet situation Wednesday in Brussels.

Pentagon Mistakenly Sent Ballistic Missile Fuses to Taiwan

Via FoxNews -

WASHINGTON — The Pentagon has announced that it mistakenly shipped non-nuclear ballistic missile components to Taiwan from a U.S. Air Force base in Wyoming.

It said the items have been returned to the United States.

At a news conference, Air Force Secretary Michael Wynne said Tuesday that the misshipped items were four nose cone assemblies for ballistic missiles. He also said it was sent instead of helicopter batteries that had been ordered by Taiwan, he said.

Wynne said the matter is under investigation.

Ryan Henry, the No. 2 policy official in the office of Defense Secretary Robert Gates, said President Bush was notified of the mistake and the actions to recover the items. Henry called the mistake "disconcerting" and intolerable.

---------------------

UPDATE (3/25/08 3:48pm CST)

Via NYTimes -

Instead of sending helicopter batteries, the United States shipped four electrical fuses for Minuteman nuclear missile warheads to Taiwan, a mistake that was discovered only last week — a year and a half after the erroneous shipment, Pentagon officials disclosed on Tuesday.

Officials said the nose-cone fuses contained no nuclear material, and were similar in function to the ones used for conventional munitions, although these were designed specifically to send an electrical signal to the trigger of the MK-12 nuclear warhead as it was approaching the ground.

CanSecWest PWN to OWN 2008

Updated Rules of Enagagment from Tipping Point's ZDI Crew
http://dvlabs.tippingpoint.com/blog/2008/03/19/cansecwest-pwn-to-own-2008

---------------------

In addition, I was told by one of my ZDI pal that Quicktime is now in scape for Day 2 attacks.

Day 2: March 27th: Default client-side apps
The attack surfaces increases to also include any default installed client-side applications which can be exploited by following a link through email, vendor supplied IM client or visiting a malicious website. First one to pwn it receives the laptop and a $10,000 cash prize. The pwned machine(s) will be taken out of the contest at that time.

I noticed last week that this product was absence from the list and was highlighted in at least one media write-up, which got me wondering as well.

Let the games begin...

Monday, March 24, 2008

CSRF Threat Grows Stronger

Via InfoWorld.com -

The latest research report out of Web applications security specialist WhiteHat finds that most sites are still woefully vulnerable to hacker attacks.

Just as in its previous research, WhiteHat estimates that some 90 percent of all pages are hack-able, the same figure that it has attached to several previous reports.

The message? Things aren't getting much better out there!

Over the last two years that WhiteHat has been issuing its paper, the company has reported that the volume and variety of Web site attacks have in fact only continued to rise, with Cross-Site Request Forgery (CSRF) tabbed as the next big thing by the experts this go round.

According to the company, nine out of ten sites still have serious vulnerabilities with an average of seven vulnerabilities per site.

The leading forms of exploit that WhiteHat is observing on the Net haven't budged much in recent months either, with classic techniques including SQL injection, buffer overflows and cross-site scripting (XSS) leading the way. However, the company is predicting that CSRF threats will soon begin to multiply.

Cross-Site Request Forgery (CSRF), as defined by OWASP, is an attack that attempts to fool end users into loading a Web page that contains a malicious request, much like traditional phishing attacks or XSS threats.

Using the technique, hackers then try to misappropriate victims' identities and privileges to carry out activities such as changing their applications passwords to gain entrance to banking sites, or to log into e-commerce sites to make fraudulent purchases in their names. In some cases, the attacks are hidden on the vulnerable sites themselves.

CSRF attacks are also known by a number of other names, including XSRF, Sea Surf, Session Riding, Cross-Site Reference Forgery, and Hostile Linking.

WhiteHat researchers said that attackers using CSRF exploits can "easily" manipulate today's Web browsers to send unintended HTTP requests such as fraudulent wire transfers, change passwords and download illegal content.

And based on its research, the company said that CSRF attacks will eventually move into the number two spot behind XSS exploits in terms of its frequency among the leading site hacking techniques.

iBooter Firmware Console Released for iPhone

Via arstechnica.com -

As you've probably noticed, the number of big iPhone jailbreak/hack releases we cover has been gradually decreasing over the past few months as development has settled down. That's not to say that there aren't some great iPhone hacking utilities being released, though. One such hack is iBooter, a tool for interactively communicating with the iBoot bootloader on the iPhone an iPod touch.

iBooter certainly isn't as mainstream a tool as the jailbreak and unlock applications, but it should come in handy for a number of people. Basically, iBooter will let you talk directly to the iPhone bootloader and tinker with it, allowing you to customize your iPhone in a few ways, and also diagnose any booting problems. Normally, you can only send commands to the bootloader, but this new utility will let you get replies back as well, making it an improvement over previous tools. Perhaps more importantly, iBooter works on Windows, Linux, and OS X, and doesn't require iTunes to be installed (as similar tools do). It has a lot of commands that will be useful for developers, or for anyone who's interested in the inner workings of their iPhone, so give it a whirl if you're curious.

Terrorism Money is Still Flowing

Via LATimes.com -

WASHINGTON -- The U.S.-led effort to choke off financing for Al Qaeda and other terrorist groups is foundering because setbacks at home and abroad have undermined the Bush administration's highly touted counter-terrorism weapon, according to current and former officials and independent experts.

In some cases, extremist groups have blunted financial anti-terrorism tools by finding new ways to raise, transfer and spend their money. In other cases, the administration has stumbled over legal difficulties and interagency fighting, officials and experts say.

But the most serious problems are fractures and mistrust within the coalition of nations that the United States admits it needs to target financiers of terrorism and to stanch the flow of funding from wealthy donors to extremist causes.

"The international cooperation and focus is dropping, the farther we get from 9/11," said Michael Jacobson, who was a senior advisor in the Treasury Department's Office of Terrorism and Financial Intelligence until March 2007. "Some countries lack political will. Others just don't have the basic capacity to govern their countries, much less create a viable financial intelligence unit."

Many current and former officials and experts say that because of political, legal, cultural and technical problems, the administration-led coalition is deteriorating.

"Al Qaeda, the Taliban and other terrorist groups continue to have access to the funds they need for active and expanded indoctrination, recruitment, maintenance, armament and operations," said Victor D. Comras, a former United Nations terrorism finance official.

Internationally, the sense of urgency over terrorism financing has waned since the 2001 attacks. As political climates have changed and negative perceptions of the United States have risen, key allies are cooperating less, current and former officials say.

In the Middle East and elsewhere, many countries have resisted U.S. pressure to investigate and identify financiers.

Saudi Arabia, Pakistan and other key nations have not taken the necessary steps to crack down on terrorist financing or suspect money flowing across their borders. Other countries, including Afghanistan and some African nations, lack the financial infrastructure to cooperate meaningfully.

Also, the most deadly terrorist attacks since Sept. 11, 2001, have cost so little -- often less than $10,000 -- that they are virtually impossible to detect by following a money trail.

Terrorist networks need larger sums to travel, train operatives, bribe government officials, evade capture and expand support bases. Increasingly, however, they are moving funds below the radar of U.S.-led enforcement and intelligence-gathering efforts, officials and experts said.

Cash couriers use donkeys and camels in places like Pakistan and Afghanistan, for instance, and private jets are used in oil-rich Persian Gulf kingdoms to move cash, gold and jewels. The networks continue to rely on a centuries-old informal banking system known as hawala, which leaves virtually no trail.

Overall, it is nearly impossible to distinguish funds meant for potential terrorism from legitimate transactions, said a senior State Department official, who, like some of the those interviewed, spoke on condition of anonymity because of prohibitions against commenting on the record on counter-terrorism.

Current and former U.S. officials acknowledge they are struggling, especially because much-needed allies are unwilling or unable to assist.

"It's not as much that we're not properly executing our strategy," said Robert Grenier, a former senior CIA official. "It's that the strategy is of limited utility in countering terrorism financing given the mechanisms that terrorists use."

-----------------------

In my mind, tracing terrorism money is less about stopping a specific attack and more about bring to light the terrorist organization as a whole entity.

If we understand their money making techniques, their common money laundering channels, then we can build a much better overall picture of the organizational nature of these groups.

Thus allowing those that fight their organizations to find the weak link in the system.

Following the money trail is a very important piece of the terrorism research puzzle, but it is just that...only a piece.

Engineer Gets 24 1/2 Years in Prison

Via Philly.com -

SANTA ANA, Calif. - A Chinese-born engineer convicted of conspiracy to export U.S. defense technology to China was sentenced Monday to 24 1/2 years in federal prison.

Chi Mak, 67, was also convicted last year of acting as an unregistered foreign agent, attempting to violate export control laws and making false statements to the FBI.

He worked on highly sensitive submarine propulsion systems in his job as an engineer for the Anaheim-based naval defense contractor Power Paragon.

Mak was arrested in late 2005 in Los Angeles after FBI agents stopped his brother and sister-in-law as they boarded a flight to Hong Kong and Guangzhou, China.

Investigators said they found three encrypted CDs in their luggage that contained documents on a submarine propulsion system, a solid-state power switch for ships and a PowerPoint presentation on the future of power electronics.

Mak sought a new trial earlier this year, but a judge rejected the request.

Medicine's Cutting Edge: Re-Growing Organs

Via CBSNews -

Three years ago, Lee Spievack sliced off the tip of his finger in the propeller of a hobby shop airplane.

What happened next, Andrews reports, propelled him into the future of medicine. Spievack's brother, Alan, a medical research scientist, sent him a special powder and told him to sprinkle it on the wound.

"I powdered it on until it was covered," Spievack recalled.

To his astonishment, every bit of his fingertip grew back.

"Your finger grew back," Andrews asked Spievack, "flesh, blood, vessels and nail?"

"Four weeks," he answered.

Andrews spoke to Dr. Steven Badylak of the University of Pittsburgh's McGowan Institute of Regenerative Medicine and asked if that powder was the reason behind Spievack's new finger tip.

"Yes, it is," Badylak explained. "We took this and turned it into a powdered form."

That powder is a substance made from pig bladders called extracellular matrix. It is a mix of protein and connective tissue surgeons often use to repair tendons and it holds some of the secrets behind the emerging new science of regenerative medicine.

"It tells the body, start that process of tissue regrowth," said Badylak.

Badlayk is one of the many scientists who now believe every tissue in the body has cells which are capable of regeneration. All scientists have to do is find enough of those cells and "direct" them to grow.

"Somehow the matrix summons the cells and tell them what to do," Badylak explained. "It helps instruct them in terms of where they need to go, how they need to differentiate - should I become a blood vessel, a nerve, a muscle cell or whatever."

If this helped Spievack's finger regrow, Badylak says, at least in theory, you should be able to grow a whole limb.

...

Dr. Atala, one of the pioneers of regeneration, believes every type of tissue already has cells ready to regenerate if only researchers can prod them into action. Sometimes that prodding can look like science fiction.

Emerging from an everyday ink jet printer is the heart of a mouse. Mouse heart cells go into the ink cartridge and are then sprayed down in a heart shaped pattern layer by layer.

Dr. Atala believes it's a matter of time before someone grows a human heart.

"The cells have all the genetic information necessary to make new tissue," Atala explained. "That's what they are programmed to do. So your heart cells are programmed to make more heart tissue, your bladder cells are programmed to make more bladder cells."

Atala's work with human bladder cells has pushed regenerative medicine to a transformational breakthrough.

In this clinical trial at Thomas Jefferson Hospital in Philadelphia, Dr. Patrick Shenot is performing a bladder transplant with an organ built with this patient's own cells. In a process developed by Dr. Atala, the patient's cells were grown in a lab, and then seeded on a biodegradable bladder-shaped scaffold.

Eight weeks later, with the scaffold now infused with millions of regrown cells, it is transplanted into the patient. When the scaffold dissolves, Dr. Shenot says what's left will be a new, functioning organ.

"The cells will differentiate into the two major cells in the bladder wall, the muscle cells and the lining cells," he explained. "It's very much the future, but it's today. We are doing this today."

-----------------------

Holy crap, this is crazy technosorcery my friends...but I love it.

Shooting Flying Cars with Machine Guns, Rocket Launchers

Via gizmodo.com -

I'm on the beach on semi-vacation now, here in the south of Spain, and we have BBC One via satellite. This means one thing on Sunday nights: Top Gear. Chances are that you probably have watched Top Gear clips on YouTube, like the one above, in which Jeremy Clarkson replaces clay pigeons and shotguns with real flying cars, machine guns and, at the end of it, a gas-tank-seeking (no kidding) rocket launcher.

-----------------------------

Heres the video.
http://view.break.com/175421

Comcast Wants to Watch You with DVR Cams

Via PCWorld -

In a scene straight out of 1984, Comcast said it will begin placing actual cameras in DVR units to track data for who is watching the digital television.

This statement is so farfetched I almost don't believe it, but it came out of the mouth of Gerard Kunkel, the senior vice president of user experience for Comcast. At the Digital Living Room conference he said that Comcast is already experimenting embedding cameras into DVR boxes that actually watch the television watchers. Big Brother, anyone?

Comcast is shilling this as a type of customization features. The camera would be capable of recognizing specific individuals and therefore loading a user's favorite channels and on the other hand block certain content as well. Stop the schtick, Comcast. Nobody, and I mean nobody would ever voluntarily allow you to place a camera in a household, for any purpose. It's a shame that I can already imagine the headlines when Comcast does this involuntarily.

----------------------

Screw that, count me out...

Pilot's Gun Discharges on US Airways Flight

Via wcnc.com (Carolinas' Local News) -

CHARLOTTE, N.C.-- A US Airways pilot’s gun accidentally discharged during a flight from Denver to Charlotte Saturday, according to a statement released by the airline.

The statement said the discharge happened on Flight 1536, which left Denver at approximately 6:45 a.m. and arrived in Charlotte at approximately 11:51 a.m.

The Airbus A319 plane landed safely and none of the flight’s 124 passengers or five crew members was injured, according to the statement. It was a full flight. An airline spokeswoman said the plane has been taken out of service to make sure it is safe to return to flight.

A Transportation Safety Administration spokeswoman reached by WCNC Sunday said the pilot is part of TSA’s Federal Flight Deck Officer (FFDO) program, which trains pilots to carry guns on flights. Andrea McCauley said the gun discharged in the cockpit, but she could not release how the gun was being transported at the time. She did not release the pilot’s name, but said he was authorized to carry the weapon and was last requalified in the FFDO program last November.

A statement from TSA said the airplane was never in danger, and the TSA and the Federal Air Marshals Service are investigating the incident.

----------------------------

I'm glad the TSA is worried about the plane...but what about the people, they WERE clearly in danger.

Sunday, March 23, 2008

Ohio Outsourcing: Tata The Latest Indian IT Company Hiring In The U.S.

Via InformationWeek -

India's IT service providers want to prove they can innovate--not just serve up low-cost talent--but that's proving a difficult task from the other side of the globe. One solution: They're hiring more U.S. talent.

Tata Consultancy Services said last week it has opened a development center in a former paper plant outside Cincinnati, with initial plans to employ 1,000 people, which would make it one of the largest U.S. development centers by an India-based IT services company. The 200,000-square-foot facility will include a lab where TCS hopes to show off its experience in such areas as industrial engineering and services. TCS plans to hire Midwest tech talent for the facility.

It's similar to plans by Wipro Technologies, which in August acquired U.S. infrastructure management vendor InfoCrossing, with 900 employees, for $600 million. Wipro is recruiting about 500 people, largely recent college grads, for a new Atlanta development center, and it plans two more centers with staffing of up to 500 people each in to-be-announced U.S. cities. Wipro's also set up a center outside Detroit.

Indian IT companies also are buying small consulting companies, looking to add regional and industry experience. Satyam Computer paid $35 million in January for Chicago-based Bridge Strategy Group, a firm of 36 management consultants. Infosys also is doing select hiring in the United States, particularly for consulting. None of these add up to a big chunk of the workforce for Indian IT vendors; TCS, for example, has more than 100,000 employees, about 10% of whom are not Indian.

But companies believe they need more people close to the customer to work on innovation efforts such as process change and new product rollouts. "Globalization of our delivery model is something we're doing at a very aggressive pace," says N.S. Bala, Wipro's senior VP of manufacturing solutions.

A bigger U.S. presence also makes Indian providers a more viable option for companies that don't want to send sensitive data or product development offshore.

---------------

Am I the only one that thinks this is just strange?

Microsoft Building Searched By Feds Investigating High-Priced Hookers

Via InformationWeek -

Federal investigators executed a search warrant at Microsoft (NSDQ: MSFT)'s Mountain View, Calif., offices earlier this month as part of an investigation into a high-priced call girl ring similar to the one used by former New York Gov. Eliot Spitzer. Court records show that that an Internal Revenue Service agent carried out the search order at Building 4 of Microsoft's Mountain View campus on March 4.

The investigator, IRS special agent Anthony Romero, was seeking the Microsoft Hotmail account records of a woman accused of involvement in a pricey escort service operating out of Denver, Colo. Records show that Romero seized from Microsoft more than 3,000 files of "preserved data" from the account of Kitty_Crimson@hotmail.com.

Authorities believe that "Kitty Crimson" is actually Heather Bruck, a Denver-area woman who allegedly worked as a prostitute for an escort service that went by the names Denver Sugar and Denver Players, according to court papers.

The ring, which charged clients upwards of $400 an hour for sex, catered to prominent and wealthy Denver residents, including businessmen and professional athletes, according to local media reports.

Denver's Rocky Mountain News last week reported that the chief judge of the U.S. District Court for Colorado, Edward Nottingham, has also been identified as one of the escort service's customers.

Giant Cupcake Seats

What do you get when you take a giant cupcake, and add chocolate frosting made out of molded rubber? Easy...it's the Jellio Cupcake Seat...guaranteed to generate instant laughter in any room. Use it as a seat, an ottoman or just an incredibly cool conversation piece. Adults love them for the fun they bring to any room, and kids love them because...well, because they're giant cupcakes, silly. A Jellio Exclusive.

http://www.jellio.com/store/cupcakeseat.html

--------------------

freaking sweet...

Love It or Hate It, In-Flight Cellphone Use Has Arrived

Via Wired.com -

Say goodbye to one of the last remaining phone-free havens.

Emirates Airlines is outfitting its planes with technology that will allow passengers to use their mobile phones in flight. The system went into effect for the first time this week on an Airbus A340 flight between Dubai and Casablanca. Emirates is partnering on the project with AeroMobile, which has developed technology that allows cellular phones to work at a low-enough level that they don't risk interfering with a plane's other systems. Emirates is shelling out $27 million to roll the system out fleetwide.

Perhaps hoping to allay passenger fears about being stuck next to a cellphone-wielding Chatty Charlie on a 13-hour flight to Tokyo, Emirates says passengers will only be allowed to make five or six calls per flight. And they point out that flight crews will have the power to turn the system on and off as needed, making it less likely that the woman sitting in 26D is able to initiate a conference call at 3 in the morning. Plus, the airline will ask all passengers to switch their phones to silent or vibrate when they board. Which is great, because, you know, that works really well at the movies.

The airlines have been threatening to do this for years. American Airlines has tested technology developed by Qualcomm, and Air France and bmi have also experimented with the in-flight calls.

Depending on your point of view, this is either a great step forward, or just another reason to dread boarding an airplane.

----------------------------------

I still think this is a horrible idea.

Just think about those bluetooth phone users that are basically talking aloud on the phone, add in plane noise..and we will now have at least 10 people yelling on the plane at once.

F'in great idea eh?

Whitepaper: Firewire Hack on Windows Vista

This paper from the SEC Consult vulnerability lab describes how the fireware hack can be applied to Windows Vista. By overwriting certain memory regions using the firewire DMA feature, password authentication under Vista can be deactivated.

SEC Consult Whitepaper
http://www.sec-consult.com/fileadmin/Whitepapers/Vista_Physical_Attacks.pdf

PM Candidate Seen As Tough on Musharraf

Via AP -

ISLAMABAD, Pakistan (AP) — Pakistan's prime minister-in-waiting has the experience and track record to hold together an unwieldy coalition as it moves to neutralize President Pervez Musharraf, lawmakers and analysts said Sunday.

But Yousaf Raza Gilani also has a personal reason to ignore Musharraf's appeals for cooperation: he spent years in jail under the U.S.-backed leader.

Lawmakers are expected to confirm him in a parliamentary vote Monday. He is a shoo-in after opposition parties swept elections last month and Musharraf is then expected to swear him in Tuesday.

"Mr. Gilani is a man who suffered from Musharraf's martial law," said Ahsan Iqbal, a lawmaker for one of four parties which have agreed to form a new coalition government and are expected to elect him with a thumping majority. "He understands well that getting rid of dictatorship is important."

Gilani, a loyalist of slain former premier Benazir Bhutto, will lead an administration facing mounting economic problems, including double-digit inflation, power shortages and sagging foreign investment.

Bhutto's Pakistan People's Party named Gilani as its candidate on Saturday after winning the largest bloc in parliament in Feb. 18 elections.

Western governments fearful of a resurgence of al-Qaida in Pakistan's ungoverned region bordering Afghanistan urgently want to know what changes the government will make to Musharraf's unpopular, military-led policies against Islamic extremism.

In a speech marking Pakistan's national day on Sunday, Musharraf hailed the start of a "new era of real democracy" in Pakistan and vowed to support the new cabinet.

"I hope the new government can maintain peace and the fast pace of socio-economic development in Pakistan," Musharraf said at a parade of jets and missiles from Pakistan's nuclear-capable arsenal. "And I hope it will also continue our struggle against the curse of terrorism and extremism with the same force."

However, the declared priority for the parties which won the parliamentary vote is bolstering democracy by further capping Musharraf's already diminished powers.

"All political forces have to work together to take the country out of this crisis," Gilani said Sunday, vowing to restore the independence of Pakistan's judges and media.

Asked whether he would work with Musharraf or push him from office, he said only: "I will follow the constitution."

Information Storage in Three Dimensions

Via Physorg.com -

For the first time, researchers have successfully turned a glass material into three-dimensional information storage using a light-based technique. This achievement may be a big step forward for the real-life implementation of such materials, which have the potential to store terabits of data (1,000 gigabits, or about 125 gigabytes) in just a single cubic centimeter.

The research was performed by scientists from the University of Bordeaux 1, one of the four universities in Bordeaux, France. The work is described in a paper published in the February 13, 2008, online edition of Optics Letters.

“The necessity for increasing data storage capacity of memory devices, along with the growth of high-density technologies, requires the use of three-dimensional optically based systems,” said physicist Lionel Canioni, one of the paper's authors, to PhysOrg.com.

There are a few methods being explored for optical-based three-dimensional information storage. One method is based on the phenomenon of “photochromism,” which, simply put, is when a material can reversibly change color -- i.e. undergo a chemical change -- when exposed to electromagnetic radiation (light). An everyday example are “transition”-type sunglass lenses.

Photochromism is an example of “single-photon” excitation, meaning that each photon in the light source (such as a laser beam) excites a single electron in the material. When those electrons quickly become de-excited, they each emit a single photon with almost the same energy as the absorbed photon.

Another promising method, explored by Canioni and his colleagues, involves multi-photon excitation—the excited electrons each absorb multiple photons—and is therefore a bit more sophisticated. Because each electron that is excited absorbs more than one photon, the laser interacts with a smaller volume of material. This allows the storage material to be activated with a higher spatial resolution in three dimensions, which allows for a larger information storage density.

---------------------------

Awesome, the future is going to be sweet...

Ultra-Fast Quantum-Dot Information Storage

Via Physorg.com -

The information-storage market is dominated by two main types: Flash memory, used in memory sticks and cell phones, and dynamic random access memory (DRAM), which is the main memory in a personal computer. Both types have their advantages and disadvantages, but a new type of memory, based on tiny atom clusters, called quantum dots, may soon displace both of them.

In research published in the March 4, 2008, online edition of Applied Physics Letters, scientists from the Technical University of Berlin, in Germany, and Istanbul University, in Turkey, describe how they created a type of quantum-dot-based memory device that can save information at speeds of only a few nanoseconds (billionths of a second).

The paper's lead author, Technical University of Berlin scientist Martin Geller, explained to PhysOrg.com, “Flash memory, which is today's market-driver in the semiconductor industry, and which everybody knows from memory sticks, digital cameras, and mp3-players, has a slow write time. The semiconductor industry is seeking faster Flash memories, but hasn't found an ultimate solution yet. Our quantum-dot-based memory may provide long storage time without power consumption of Flash memory, as wells as a fast write time and better scalability to real-life devices."

To be fair, the other established predecessor of quantum-dot memory, DRAM, does have some excellent qualities. It offers very fast information-access times—under 20 nanoseconds—and the information can be repeatedly written and rewritten on a DRAM; it has excellent so-called endurance. But a DRAM device has a big disadvantage: It is volatile, meaning the information has to be refreshed every ten milliseconds to be maintained, also resulting in a high power consumption.

"The very first prototype of our new quantum-dot-based memory scheme is already almost as fast as DRAM,” said Andreas Marent, a physicist at the Technical University of Berlin who took part in the research. “And in contrast to DRAM or Flash, the physical characteristics of quantum dots limit the write time to the picosecond, or trillionth of a second, range. That means a better device prototype should be more than 100 times faster than today's DRAM.”

Saturday, March 22, 2008

More Malvertising on Myspace

Yet again, another example of malvertising on Myspace. Does this ad look familiar??



The VML ActiveX Control is loading from the IP address highlighted in red.

The WHOIS for the IP points to Russia. Thanks to Fergie for point out the error in my intial research.



This IP address have been connected to other malware issues in the past.

I didn't dig too much into this malware ad, since I wasn't in a secure VM.

Malvertising is a very serious issue and it will only get worse before it gets better.