The Hottest News on Your Laptop

247NEWSMARK.blogspot.com

As Long as It Is Trending, We Got It!!!

The '247NEWSMARK App' Coming Soon

News That You NEVER Knew Was Made!!!

'LIKE' Us On FaceBook

No Matter Where You Are, We've Got YOU Covered

News Fast, Anytime, Anywhere

Try Out Our Mobile Site

m.247newsmark.blogspot.com

Popular Posts

Subscribe Now!

Showing posts with label ICT. Show all posts
Showing posts with label ICT. Show all posts

Tuesday, 3 December 2013

The gentle art of cracking passwords

 
On the internet, the most popular colour is blue, at least when it comes to passwords.
If you are wondering why, it is largely because so many popular websites and services (Facebook, Twitter and Google to name but three) use the colour in their logo. That has a subtle impact on the choices people make when signing up and picking a word or phrase to form a supposedly super-secret password.
It's just one of the many quirks to be found in the password-picking habits of us humans. There are plenty of others. For example studies suggest red-haired women tend to choose the best passwords and men with bushy beards or unkempt hair, the worst.
These studies also reveal that when it comes to passwords, women prefer length and men diversity.
Big data These facts have come to light thanks to the vast number of passwords that have been stolen from websites and online services, says security researcher Per Thorsheim.
Adobe, LinkedIn and game website RockYou have all been hit in breaches that involved the theft of login names and passwords. Add to this the steady drip of security breaches at other firms and you have a vast corpus of data that can shed light on what passwords people pick.
The number one conclusion from looking at that data - people are lousy at picking good passwords.
Computer chip Brute force attacks throw computer power at passwords
"You have to remember we are all human and we all make mistakes," says Mr Thorsheim.
In this sense, he says, a good password would be a phrase or combination of characters that has little or no connection to the person picking it. All too often, Mr Thorsheim adds, people use words or numbers intimately linked to them.
They use birthdays, wedding days, the names of siblings or children or pets. They use their house number, street name or pick on a favourite pop star.
This bias is most noticeable when it comes to the numbers people pick when told to choose a four digit pin. Analysis of their choices suggests that people drift towards a small subset of the 10,000 available. In some cases, up to 80% of choices come from just 100 different numbers.
People power It is this realisation about human bias that has transformed the way that people, both the good guys and the bad, go about cracking passwords.
"Now brute forcing is absolutely the last tactic we would use," says Mr Thorsheim.
Brute forcing, as its name suggests, throws raw computer power at the problem of password cracking. Such an attack on a password would first try "a" and then work through all possible letter and number combinations before ending at "zzzzzzz".
Password security depended on computer power never getting to the point where billions of those sequential combinations could be tried in a reasonable amount of time. The mathematics (time multiplied by tries) defeated the crackers.
"But", says security researcher Yiannis Chrysanthou from KPMG, "it's not about mathematics any more because it's people that select the passwords."
Many security researchers look to improve their password cracking methods so they can advise companies about what they need to do to make people choose phrases that are more secure.

Cracking passwords

I tried to see how easy it is to crack passwords for myself.
Armed with a list of hashed passwords culled from one of the many sites where stolen lists are dumped every day, I looked for software that could crack them.
I turned to two of the best known, Hashcat and John The Ripper, loaded up my hashes, picked my word lists, applied my rules and let them rip.
Soon after I had a list of cracked passwords - not all of them - and I stopped the process before it had completed.
The words and phrases that emerged first were wearyingly familiar. It's no wonder that people's online accounts are regularly breached if so many are choosing obvious combinations such as "aaa123" as a password.
They also try to crack the passwords in the stolen lists to get a better idea of what people have been using. In such situations often what is being cracked is a sequence of letters known as a "hash".
These fixed-length strings of characters cannot be rewound to reveal what characters gave rise to them. However, because hashing algorithms work according to a fixed set of rules then "123456" will always produce the same seemingly random sequence of letters. Under the MD5 hashing system "123456" always produces the string: "e10adc3949ba59abbe56e057f20f883e".
Generate hashes for all the words in a long list related in one way or another to a target and there is a much better chance of guessing their password, says Mr Chrysanthou, who developed novel rules for cracking passwords while studying at Royal Holloway.
It was via this approach that he managed to crack the password: "Ph'nglui mglw'nafh Cthulhu R'lyeh wgah'nagl fhtagn".
At first glance this mangled collection of lower and upper case letters drizzled with apostrophes looks like it would be pretty secure. Unless you are a well-educated geek who knows it comes from a horror story written by HP Lovecraft.
Targeted attacks are likely to scour social media for words, names and dates important to a victim. Knowing the names of someone's children, pets, parents or street can help unpick a password very quickly.
Facebook on a phone What you do and say on social media can give clues to your passwords
The bad guys try to crack passwords, says security researcher Bruce Marshall, because they too know another truth about people - they are lazy.
This means that there is a very good chance, 70% according to some studies, that a password associated with an email address on one site might well be used to log in on one or more other online services.
Many cyber-thieves target smaller sites to get at their lists of passwords and then try them in other places to see if they have been used.
"If a criminal is cracking passwords then most likely they gathered them from a specific site and are trying to gain access to additional accounts," says Mr Marshall.
The sheer number of passwords released to the web has created another problem, he says.
"If an attacker can't gain access to the targeted site's password database then they may resort to an online password guessing attack where they try common usernames, email addresses and password combinations," he says.
So, if you want to pick a stronger password do not use simple combinations of words and numbers, choose words that are only tangentially related to you and make sure the password you use for your online banking is used for nothing else.


 source: bbcnews

Monday, 25 November 2013

Cyberattack Leads to $1 Million Bitcoin Heist


Another Bitcoin company has fallen victim of a massive cyberheist. BIPS, one of the largest European Bitcoin payment processors, lost 1,295 Bitcoin (currently worth $1 million) after a cyberattack.
As the price of Bitcoin continues to rise, cybercriminals are targeting companies with large holdings of Bitcoins in their servers. The attack on BIPS happened just a few weeks after inputs.io, which allegedly lost 4,100 BTC, worth more than $1 million at the time.

Hackers launched their initial Distributed Denial of Service (DDoS) attack on BIPS on Nov. 15, the company wrote in a Reddit post. The hackers attacked again on Nov. 17, overloading BIPS servers and somehow getting access to several online wallets, which allowed them to steal the 1,295 BTC.
BIPS, which claims to have more than 20,000 customers, offered free online wallets to store their Bitcoin online. It also offers a payment processors for merchants who want to accept payments in Bitcoin.
The company released a statement saying the attack compromised "several consumer wallets." However, it didn't specify how many accounts were hacked. BIPS' CEO Kris Henriksen told Mashable that "most of the missing funds were from our company’s own holdings," but declined to be interviewed for lack of time. "This is my fifth day without sleep," he added in an email.
After the attack, Henriksen advised his customers to avoid online wallets altogether, despite the fact that his company offered them to users. BIPS' online wallet service is now suspended.
"Attacks are not isolated to us, and if you are storing larger amounts of coins with any third party, you may want to find alternative storage solutions as soon as possible," he wrote in a BitcoinTalk forum message.
"Web Wallets are like a regular wallet that you carry cash in and not meant to keep large amounts in," he added.
But several BIPS customers, who still don't know if they'll ever get their Bitcoin back, aren't convinced by Henriksen's advice, saying he never warned them of any danger before the attack. On the contrary, the company said it was secure.
Responding to Henriksen's claim that web wallets are only meant for little amounts of Bitcoin, a BitcoinTalk forum user that goes by the name of Cubicdissection said: "At NO point did you EVER say hey you shouldn't keep your BTC with us."
"In fact, your website said: 'Your data is secure at BIPS.' So yeah, I felt pretty goddamn secure leaving my BTC balance there," he added. "Why don't you speak in plain English and quit giving us the runaround? Because it makes me think you're a liar and have something to hide."
Another user, nicknamed Genghis34, said he had 90 Bitcoin (around $73,000) in his BIPS wallet. He his now asking other victims to sign up online to form a group to potentially sue BIPS and use the threat of a lawsuit as a "negotiating block" for a settlement.
Henriksen's conclusion that online wallets aren't safe echoes what the founder of inputs.io said after his website's loss of 4,100 Bitcoin.
"I don't recommend storing any Bitcoins accessible on computers connected to the Internet," he wrote at the time.
But for victims of the BIPS heist, these warnings come too little too late.
"Bitcoin is the wild west," wrote Genghis34. "And I really doubt this was intentional on the part of bips.me — just probably overconfidence to run a wallet service without proper security."




source:mashable

Android 4.4 KitKat update hits HTC One Google Play Edition


If you own the HTC One Google Play Edition smartphone, some good news has started to turn up that you will be interested in. Reports are indicting that HTC One Google Play edition owners have begun to receive a 320MB OTD software update.
iMovie-2-580x302

Reports indicate the software update is bringing the device Android 4.4 KitKat. There are no screen shots of the update in action at this time. The update was previously tipped by HTC to be coming to this device in late January. The update is also said to be available as a developer update.
We reviewed the HTC One Google Play Edition smartphone in the past along with its sibling the Samsung Galaxy S4 Google Play Edition. There is no word at this time if the S4 Google Play Edition is getting the update soon.
The HTC One Google Play Edition smartphone uses a Snapdragon 600 processor with 2GB of RAM. It has 32GB of storage and a microSD card slot for expansion. It also has the other features you expect like Bluetooth 4.0, WiFi, NFC, and GPS.



source: slashgear

Thursday, 21 November 2013

Why Intel Is Bailing On Its Plan To Sell A Digital TV



Earlier this year, Intel Corp rented temporary retail space in New York, Los Angeles and Chicago for a splashy launch of Intel TV, a new Internet entertainment service that the chipmaker promised could revolutionize the television industry.
But when customers walk into those stores this holiday season, they will not find any set-top TV boxes or programming services for sale. Instead, they will see ultra thin laptops and new tablets from a variety of vendors that Intel hopes will help boost its massive but flagging computer chip business.
The drastic change in plans for the retail spaces follows the company's abrupt abandonment of a grand plan to become an entertainment hub in living rooms around the world - a retreat that has been rumored but not yet acknowledged by the company.
The project faced daunting challenges from the start, and Intel's new CEO, Brian Krzanich, ultimately decided the company could not afford the distraction and expense, sources familiar with the decision told Reuters.
At his first annual investor day on Thursday, Krzanich is expected to discuss the growing use of chips in everyday devices, plans to breath new life into PCs, and Intel's growing contract manufacturing business - but not Intel TV.
Sources close to the project said Intel Corp is looking to sell the TV technology, called OnCue, with Verizon Communications Inc emerging as the most likely buyer, as first reported by the AllThingsD website.
An Intel spokesman declined to comment.
Intel's retreat is a disappointment not only to former British Broadcasting Corp executive Erik Huggers, who led the project, but also to others in Silicon Valley who saw it as part of a wave of next-generation digital television products that might help break open a market tightly controlled by a handful of cable companies and entertainment conglomerates.
Technology heavyweights including Apple Inc, Amazon.com Inc Google Inc Sony Corp and Microsoft Corp all have similar ambitions. Yet thus far only Netflix Inc has proven to be a major disruption to the lucrative relationship between pay TV operators and the entertainment companies that provide them with content.

THINKING OUTSIDE THE CHIP

Intel, a storied semiconductor company that has struggled to manage the transition from traditional personal computers to mobile devices, was always an unlikely player in the digital television wars. Its traditional strengths are in chip design and manufacturing, and it has little experience selling consumer products, much less television programming.
But Paul Otellini, Intel's CEO from 2005 until May of this year, saw an opportunity for Intel to diversify into a new consumer business, one centered on a high-tech set-top box and a slick user interface. The often-clunky hardware and software provided by cable companies, and the highly controlled structure of cable packages, seemed to beg for a better solution.
Otellini entrusted the project to Huggers, a veteran TV executive who all but boasted that he knew nothing about chips. Huggers, who had originally pitched the idea, developed a business plan, and soon set up his group in offices with the flashy look of a media startup on the chipmaker's Santa Clara, California, campus.
Making his case for Intel TV to the public for the first time in February 2013 at a conference near Los Angeles, Huggers assured the audience that Intel would not offer channels a la carte, an industry buzz word despised by entertainment companies that count on "bundling" lower rated channels with popular ones.
But Huggers also said Intel would offer channel packages that "are bundled right," which many in Hollywood took to mean an attempt to slice off the less popular channels - something that would not come cheaply or easily.
While Intel never said how much it planned to charge for its TV service, Huggers billed it as a premium product, rather than a cut-rate option for consumers hoping to save money by canceling their cable subscriptions.
Huggers ultimately made only modest progress negotiating slimmer packages of channels, people familiar with the talks said. Still, by this summer, Huggers had more than 300 employees and was testing the OnCue device in the homes of thousands of Intel employees.
Many people who saw a prototype of the device, a nondescript black box, and toyed with the all-important graphical interface software, described OnCue as far superior to what is generally offered by cable and satellite TV companies.
Representatives for Verizon, Viacom Inc, NBC, CBS, Fox, Time Warner Inc and Disney's ABC all declined to comment on their discussions with Intel.

THE NEW BOSS

Krzanich, a manufacturing expert who won the top job after the Intel board decided to stick with an in-house executive, never shared Otellini's interest in Intel TV.
Meeting with a group of reporters a month into his tenure as CEO, he spoke for an hour about his mobile chip strategy. When pressed about the TV business he struck a surprisingly cautious tone, saying the company is not expert at content.
Intel's TV project was a distraction to Krzanich, company sources say. He spent his first six months as CEO focused on two threats to the chipmaker's core business - a declining PC industry and a lack of progress in smartphones and tablets.
"It's not wrong for them to look for growth wherever they can find it because they need to," said Bernstein semiconductor analyst Stacy Rasgon. "But (Krzanich) has enough on his plate to worry about."
While Huggers came close to finalizing deals with some of the major programmers, according to industry sources on both sides of the talks, the terms were such that Intel would have faced upfront outlays in the hundreds of millions regardless of how quickly the service caught on, the same sources say.
"The problem is Intel's appetite for the size of the financial risk required to launch," said Rich Greenfield, a media analyst at BTIG, noting the big commitments to media companies as well as large consumer marketing and customer service operations. He pegged launch costs in the hundreds of millions of dollars but declined to be more specific.
Intel also had to make concessions to media companies that might have made it harder to sell the service: Viewers streaming previously aired shows from some networks would not be allowed to fast-forward through commercials, for example.
Still, Intel TV would have offered far easier navigation, simple access to archived programming, and innovations in advertising delivery and personalized services. It would have also held out the potential for other features that could be readily implemented with an advanced Intel-powered set-top box and associated Internet-based services.
Ultimately, Krzanich was not willing to make the bet. Media company sources say tentative deals with Intel are now on hold as the chip company seeks a buyer for the service.
Huggers hopes to sell the television project as turnkey operation, including its technology and engineers, and would like to see the service launch under a more media-oriented company, some of the industry sources say.
For Intel, it has been a tough lesson in reinvention.
Krzanich "is a bit more of a realist than Paul was," Bernstein's Rasgon said, referring to Otellini.
"They really believed they could differentiate on the hardware," he said. "What they didn't understand when they started, because it is new, is it's about the content - not about the hardware."

Monday, 18 November 2013

Meet The 'Assassination Market' Creator Who's Crowdfunding Murder...

As Bitcoin becomes an increasingly popular form of digital cash, the cryptocurrency is being accepted in exchange for everything from socks to sushi to heroin. If one anarchist has his way, it’ll soon be used to buy murder, too.

Last month I received an encrypted email from someone calling himself by the pseudonym Kuwabatake Sanjuro, who pointed me towards his recent creation: The website Assassination Market, a crowdfunding service that lets anyone anonymously contribute bitcoins towards a bounty on the head of any government official–a kind of Kickstarter for political assassinations. According to Assassination Market’s rules, if someone on its hit list is killed–and yes, Sanjuro hopes that many targets will be–any hitman who can prove he or she was responsible receives the collected funds.
For now, the site’s rewards are small but not insignificant. In the four months that Assassination Market has been online, six targets have been submitted by users, and bounties have been collected ranging from ten bitcoins for the murder of NSA director Keith Alexander and 40 bitcoins for the assassination of President Barack Obama to 124.14 bitcoins–the largest current bounty on the site–targeting Ben Bernanke, chairman of the Federal Reserve and public enemy number one for many of Bitcoin’s anti-banking-system users. At Bitcoin’s current rapidly rising exchanges rate, that’s nearly $75,000 for Bernanke’s would-be killer.
Sanjuro’s grisly ambitions go beyond raising the funds to bankroll a few political killings. He believes that if Assassination Market can persist and gain enough users, it will eventually enable the assassinations of enough politicians that no one would dare to hold office. He says he intends Assassination Market to destroy “all governments, everywhere.”
“I believe it will change the world for the better,” writes Sanjuro, who shares his handle with the nameless samurai protagonist in the Akira Kurosawa film “Yojimbo.” (He tells me he chose it in homage to creator of the online black market Silk Road, who called himself the Dread Pirate Roberts, as well Bitcoin inventor Satoshi Nakamoto.)  ”Thanks to this system, a world without wars, dragnet panopticon-style surveillance, nuclear weapons, armies, repression, money manipulation, and limits to trade is firmly within our grasp for but a few bitcoins per person. I also believe that as soon as a few politicians gets offed and they realize they’ve lost the war on privacy, the killings can stop and we can transition to a phase of peace, privacy and laissez-faire.”
I contacted the Secret Service and the FBI to ask if they’re investigating Assassination Market, and both declined to comment.
Like other so-called “dark web” sites, Assassination Market runs on the anonymity network Tor, which is designed to prevent anyone from identifying the site’s users or Sanjuro himself. Sanjuro’s decision to accept only Bitcoins is also intended to protect users, Sanjuro, and any potential assassins from being identified through their financial transactions. Bitcoins, after all, can be sent and received without necessarily tying them to any real-world identity. In the site’s instructions to users, Sanjuro suggests they run their funds through a “laundry” service to make sure the coins are anonymized before contributing them to anyone’s murder fund.
As for technically proving that an assassin is responsible for a target’s death, Assassination Market asks its killers to create a text file with the date of the death ahead of time, and to use a cryptographic function known as a hash to convert it to a unique string of characters. Before the murder, the killer then embeds that data in a donation of one bitcoin or more to the victim’s bounty. When a target is successfully murdered, he or she can send Sanjuro the text file, which Sanjuro hashes to check that the results match the data sent before the target’s death. If the text file is legit and successfully predicted the date of the killing, the sender must have been responsible for the murder, according to Sanjuro’s logic. Sanjuro says he’ll keep one percent of the payout himself as a commission for his services.
Just reading about that coldly calculative system of lethal violence likely inspires queasy feelings or outrage. But Sanjuro says that the public’s abhorrence won’t prevent the system from working. And as a matter of ethics, he notes that he’ll accept only user-suggested targets “who have initiated force against other humans. More specifically, only people who are outside the reach of the law because it has been subverted and corrupted, and whose victims have no other way to take revenge than to do so anonymously.”
Even setting aside the immorality of killing, doesn’t the notion of enabling small minorities of angry Bitcoin donors to assassinate elected officials sound like an attempt to cripple democracy? “Of course, limiting democracy is why we even have a constitution,” Sanjuro responds. “Majority support does not make a leader legitimate any more than it made slavery legitimate. With this market the great equalising forces of capitalism have the opportunity to work in politics too. One bitcoin paid is one vote closer to a veto of whatever legislation you dislike.”
Sanjuro didn’t actually invent the concept of an anonymous crowdfunded assassination market. The idea dates back to the cypherpunk movement of the mid-1990s, whose adherents dreamt of using encryption tools to weaken the government and empower individuals. Former Intel INTC +0.12% engineer and Cypherpunk Mailing List founder Tim May argued that uncrackable secret messages and untraceable digital currency would lead to assassination markets in his “Cryptoanarchist’s Manifesto” written in 1992.
A few years later, another former Intel engineer named Jim Bell proposed a system of funding assassinations through encrypted, anonymous donations in an essay he called “ Assassination Politics.” The system he described closely matches Sanjuro’s scheme, though anonymity tools like Tor and Bitcoin were mostly theoretical at the time. As Bell wrote then:
If only 0.1% of the population, or one person in a thousand, was willing to pay $1 to see some government slimeball dead, that would be, in effect, a $250,000 bounty on his head. Further, imagine that anyone considering collecting that bounty could do so with the mathematical certainty that he could not be identified, and could collect the reward without meeting, or even talking to, anybody who could later identify him. Perfect anonymity, perfect secrecy, and perfect security. And that, combined with the ease and security with which these contributions could be collected, would make being an abusive government employee an extremely risky proposition. Chances are good that nobody above the level of county commissioner would even risk staying in office.
Bell would later serve years in prison for tax evasion and stalking a federal agent, and was only released in March of 2012. When I contacted him by email, he denied any involvement in Sanjuro’s Assassination Market and declined to comment on it.

Sanjuro tells me he’s long been aware of Bell’s idea. But he only decided to enact it after the past summer’s revelations of mass surveillance by the NSA exposed in a series of leaks by agency contractor Edward Snowden. “Being forced to alter my every happy memory during internet activity, every intimate moment over the phone with my loved ones, to also include some of the people I hate the most listening in, analysing the conversation, was the inspiration I needed to embark on this task,” he writes. “After about a week of muttering ‘they must all die’ under my breath every time I opened a newspaper or turned on the television, I decided something had to be done. This is my contribution to the cause.”

Assassination Market isn’t the first website to suggest funding murder with bitcoins. Others Tor-hidden websites with names like Quick Kill, Contract Killer and C’thulhu have all claimed to offer murders in exchange for bitcoin payments. But none of them responded to my attempts to contact their administrators, and all required advanced payments for their services, so they may be scams.
And how do Assassination Market’s users know that it’s not a similar fraud scheme designed to steal users’ bitcoins? “You don’t,” Sanjuro admits. But he argues that if it were a scam, it would be a very complex and risky one, given that even threatening to harm the president of the United States is a felony.

Forbes

Google Announces New Measures to Block Child Pornography

Google's executive chairman Eric Schmidt has outlined how his company is introducing new measures to block child pornography from appearing in its searches. Schmidt explained the changes to Google's search function in an op-ed in Britain's Daily Mail newspaper following a campaign of pressure from British politicians. Schmidt broke the new measures down into sub-categories that included "cleaning up" more than 100,000 search results, and the introduction of new warnings that appear above more than 13,000 results that reiterate that child porn and child sexual abuse is illegal, and offer avenues for help. Despite these changes, Schmidt says in his op-ed that "There's no quick technical fix when it comes to detecting child sexual abuse imagery." Instead, Google will use humans to review the images to discern the difference between "genuine abuse" and "innocent pictures of kids at bathtime." Schmidt also details plans to send engineers to the UK's Internet Watch Foundation and the US National Center for Missing and Exploited Children, in addition to funding internships at both organizations. UK Prime Minister David Cameron is in the midst of an attempted crackdown on pornography in general, with a particular focus on stopping search engines from showing child porn. Earlier this year, Cameron called for "Google, Bing, Yahoo, and the rest" to censor their search results, saying in July "If there are technical obstacles to acting on [search engines], don't just stand by and say nothing can be done; use your great brains to help overcome them." Google has previously shied away from censoring its results directly, choosing instead to develop an open database to which law enforcement agencies, charities, and relevant organizations could add the details of abusive imagery that could then be hidden or removed. Schmidt's op-ed comes before a British parliamentary meeting today to discuss the clampdown on child porn. Google's new measures — and the fact one of its most public faces addressed the issue in one of the UK's most partisan papers — suggest the search giant is taking the issue very seriously. But despite Google's best efforts, new search filters sadly won't remove child porn from the internet on their own. BBC News cites a report from Cameron's own Child Exploitation and Online Protection Centre that explains most child pornography can't be found through Google or Bing searches, existing instead on peer-to-peer networks or on the "deep web," protected by anonymity software such as Tor. Without large companies such as Google acting as gatekeepers in these darker corners of the internet, Cameron will need to look elsewhere for "great brains" to continue his campaign. SOURCE:THEVERGE