Mozilla caves to pressure, will enable HTML5 DRM in Firefox

“The organization is partnering with Adobe to make the change. Mozilla will provide the hooks and APIs in Firefox to enable Web content to manipulate DRM-protected content, and Adobe will provide a closed source Content Decryption Module (CDM) to handle the decryption needs.  In a more technical post, Mozilla CTO Andreas Gal outlines some of the ways that the Firefox developers have tried to isolate the Adobe CDM to ensure that this closed source black box cannot breach user privacy or undermine system security. HTML5’s DRM system also includes a unique identifier that content providers can use to identify devices. Mozilla has taken pains to make this as minimally invasive as possible.”

http://arstechnica.com/information-technology/2014/05/driven-by-necessity-mozilla-to-enable-html5-drm-in-firefox/

Scan to Donate Bitcoin to Freedomwat.ch Staff
Did you like this?
Tip Freedomwat.ch Staff with Bitcoin

NSA routinely tapped in-flight Internet, intercepted exported routers

“The systems—codenamed ‘Homing Pigeon’ by the NSA and ‘Thieving Magpie’ by the GCHQ—allowed the agencies to track which aircraft individuals under surveillance boarded based on their phone data.  ‘We can confirm that targets… are on board specific flights in near real time, enabling surveillance or arrest teams to be put in place in advance,’ a GCHQ analyst wrote in a PowerPoint slide presentation on the program. ‘If they use data, we can also recover email address’s [sic], Facebook IDs, Skype addresses, etc.’  The technology allows the NSA and GCHQ to get a geographic fix on surveilled aircraft once every two minutes in transit.”

http://arstechnica.com/tech-policy/2014/05/nsa-routinely-tapped-in-flight-internet-intercepted-exported-routers/

Scan to Donate Bitcoin to Freedomwat.ch Staff
Did you like this?
Tip Freedomwat.ch Staff with Bitcoin

Your phone is a gateway for spying on you by anyone

“Technologies called MZ-catchers are very effective tool to finding out the unique identifiers on someone’s SIM card and on their mobile phone to find out who is there. So if you imagine that 20 years ago you might have needed a police officer to stop and arrest someone or to stop and search them and ask for ID to get a full list of everyone who is there, now a very affordable piece of equipment can be deployed. You can set the radius of how far you want to kind of scoop up. And then you get a list of every single mobile phone there, which can be tied back to an individual. So it is an exceptionally powerful tool at unmasking anonymous protest.”

http://rt.com/shows/sophieco/158296-spy-us-eric-king/

Scan to Donate Bitcoin to Freedomwat.ch Staff
Did you like this?
Tip Freedomwat.ch Staff with Bitcoin

Phishers Divert Home Loan Earnest Money By Altering E-mails

“Real estate and title agencies are being warned about a new fraud scheme in which email bandits target consumers who are in the process of purchasing a home.  An alert sent by First American Title to its agents.  In this scheme, the attackers intercept emails from title agencies providing wire transfer information for borrowers to transmit earnest money for an upcoming transaction. The scammers then substitute the title company’s bank account information with their own, and the unsuspecting would-be homeowner wires their down payment directly to the fraudsters.  This scam was laid out in an alert sent by First American Title to its title agents.”

http://krebsonsecurity.com/2014/04/phishers-divert-home-loan-earnest-money/

Scan to Donate Bitcoin to Freedomwat.ch Staff
Did you like this?
Tip Freedomwat.ch Staff with Bitcoin

Hacker faces 115 years in prison after lowering customers’ cable bills

“Two men pleaded guilty to a scam that lowered the bills of 5,790 Comcast customers in Pennsylvania by a total of $2.4 million. They now face prison time and will have to pay their ill-gotten wealth back to Comcast.  The accused ringleader, 30-year-old Alston Buchanan, pleaded guilty last week. ‘Buchanan faces up to 57½ to 115 years in prison, although Buchanan will likely serve a lesser sentence than the maximum,’ the newspaper wrote.  Comcast customers saved an average of $414 in exchange for paying the defendants $75 to $150.”

http://arstechnica.com/tech-policy/2014/04/comcast-bills-lowered-2-4-million-by-scammers-who-accessed-billing-system/

Scan to Donate Bitcoin to Freedomwat.ch Staff
Did you like this?
Tip Freedomwat.ch Staff with Bitcoin

BitPay’s Copay Team Broadcasts First Multisig Transaction

“Many think it’s the future of bitcoin, and for a good reason.  In short, multisignature transactions are unique in that they allow for more than one private key to control a wallet address. At present, most users deal with one public address, and one public.  The issue with that is that it becomes incredibly easy to lose access to funds should the private key become compromised.  BitPay’s Bitcore team recently announced that a multisignature wallet, dubbed Cosign, was in development. It’s since been re-named to Copay, and all six of the software’s developers have come together in Tucuman, Argentina to create a prototype.”

http://newsbtc.com/2014/04/18/bitpays-copay-team-broadcasts-first-bip32-p2sh-multisig-transaction-argentina/

Scan to Donate Bitcoin to Freedomwat.ch Staff
Did you like this?
Tip Freedomwat.ch Staff with Bitcoin

Heartbleed vulnerability exploited months before patch?

“Usernames and passwords on some systems may have been exposed for months or years by the vulnerability, which has been part of every OpenSSL release since March 2012. There are signs that exploits for the vulnerability were in use by someone for some time before the vulnerability was revealed.  Terrence Koeman of MediaMonks told Ars he found signs of attempts dating back to November 2013. He used the packet content of a successful exploit of the Heartbleed vulnerability to check inbound packets logged by his servers and found a number of incoming packets from a network suspected of harboring a number of ‘bot’ servers that were apparently scans for the vulnerability.”

http://arstechnica.com/security/2014/04/heartbleed-vulnerability-may-have-been-exploited-months-before-patch/

Scan to Donate Bitcoin to Freedomwat.ch Staff
Did you like this?
Tip Freedomwat.ch Staff with Bitcoin

Fandango, Credit Karma exposed millions of smartphone users’ data

“Developers of two popular smartphone apps—Fandango and Credit Karma—have been caught transmitting passwords, social security numbers, birth dates, and other highly sensitive user data over the Internet without properly encrypting it first, officials with the Federal Trade Commission said.  As a result, it was trivial for hackers to intercept the data when people used the apps on both Apple’s iOS and Google’s Android mobile operating systems, complaints filed by the FTC alleged. The complaints leveled charges of other shortcomings in the developers’ security, including the failure to properly test and audit the safety of apps before making them available for download.”

http://arstechnica.com/security/2014/03/how-fandango-and-credit-karma-exposed-millions-of-smartphone-users-data/

Scan to Donate Bitcoin to Freedomwat.ch Staff
Did you like this?
Tip Freedomwat.ch Staff with Bitcoin

Critical crypto bug exposes Yahoo Mail, other passwords

“Lest readers think ‘catastrophic’ is too exaggerated a description for the critical defect affecting an estimated two-thirds of the Internet’s Web servers, consider this: at the moment this article was being prepared, the so-called Heartbleed bug was exposing end-user passwords, the contents of confidential e-mails, and other sensitive data belonging to Yahoo Mail and almost certainly countless other services.  The two-year-old bug is the result of a mundane coding error in OpenSSL, the world’s most popular code library for implementing HTTPS encryption in websites, e-mail servers, and applications.”

http://arstechnica.com/security/2014/04/critical-crypto-bug-exposes-yahoo-mail-passwords-russian-roulette-style/

Scan to Donate Bitcoin to Freedomwat.ch Staff
Did you like this?
Tip Freedomwat.ch Staff with Bitcoin

Tesla Model S security system vulnerable to outside hacking

“A security researcher has discovered a way to locate, hack and unlock Tesla Motors premiere Model S from a remote computer using traditional hacking techniques.  Nitesh Dhanjani announced his findings at the Black Hat Asia security conference in Singapore over the weekend, where the author of multiple books on hacking revealed that by cracking a six-character password transmitted wirelessly over the Internet, a hacker could locate and gain access to any Model S.  Using Dhanjani’s technique, hackers could find and break into Teslas to steal any contents inside the car, but would be unable to hijack and drive the car itself, which requires the owner’s electronic key fob.”

http://dailycaller.com/2014/03/31/tesla-model-s-security-system-vulnerable-to-outside-hacking/

Scan to Donate Bitcoin to Freedomwat.ch Staff
Did you like this?
Tip Freedomwat.ch Staff with Bitcoin