Category: Computer

I Have to Give an A for Inventiveness

The European Union has classified spyware as a restricted item requiring an export license, much like weapons:

Companies which make spyware will have to apply for permission to export the software once new EU regulations come into effect in late December.

Officially referred to as “intrusion software”, the software will now be included on the EU’s list of “dual use” items, defined as “goods, software and technology normally used for civilian purposes but which might have military applications or contribute to the proliferation of weapons of mass destruction.”

The restriction means that companies will have to apply for a licence to export spyware, although it doesn’t affect the sale of the software within the UK. Inclusion on the dual-use list places the technology alongside nuclear reactors, ultra-high-resolution cameras, and rocket fuel.

While the regulation is implemented by the European commission, the British government supports the restriction of spyware. “The UK has made it clear over the last two years that we believe that while these kind of technologies do have legitimate uses, they also pose threats to national security and to human rights and should be subject to export controls,” said a spokesperson for the Department for Business, Innovation and Skills.

Hopefully, this the export of such software to repressive regimes, as FinFisher did with its FinFish spyware, which it probably exported to Egypt, Bahrain, Ethiopia, etc.

Additionally, I hope that it will serve to also restrict the use of such programs by commercial entities.

Things like tracking cookies, and Verizon’s new “super cookies”, should be included in this category.

Kind of Like Your Mother in Law Driving off a Cliff in Your Brand New Car

The huge cyberattack on JPMorgan Chase that touched more than 83 million households and businesses was one of the most serious computer intrusions into an American corporation. But it could have been much worse.

Questions over who the hackers are and the approach of their attack concern government and industry officials. Also troubling is that about nine other financial institutions — a number that has not been previously reported — were also infiltrated by the same group of overseas hackers, according to people briefed on the matter. The hackers are thought to be operating from Russia and appear to have at least loose connections with officials of the Russian government, the people briefed on the matter said.

I have a real hard time choosing sides between Russian Hackers and Wall Street.

Law Enforcement Technology Used to Steal Celebrity Pix

This is we should not create technology allow for unlimited access to our private affairs by the state security apparatus. Because whatever technologies they develop will end up in the hands of criminals:

As nude celebrity photos spilled onto the web over the weekend, blame for the scandal has rotated from the scumbag hackers who stole the images to a researcher who released a tool used to crack victims’ iCloud passwords to Apple, whose security flaws may have made that cracking exploit possible in the first place. But one step in the hackers’ sext-stealing playbook has been ignored—a piece of software designed to let cops and spies siphon data from iPhones, but is instead being used by pervy criminals themselves.

On the web forum Anon-IB, one of the most popular anonymous image boards for posting stolen nude selfies, hackers openly discuss using a piece of software called EPPB or Elcomsoft Phone Password Breaker to download their victims’ data from iCloud backups. That software is sold by Moscow-based forensics firm Elcomsoft and intended for government agency customers. In combination with iCloud credentials obtained with iBrute, the password-cracking software for iCloud released on Github over the weekend, EPPB lets anyone impersonate a victim’s iPhone and download its full backup rather than the more limited data accessible on iCloud.com. And as of Tuesday, it was still being used to steal revealing photos and post them on Anon-IB’s forum.

“Use the script to hack her passwd…use eppb to download the backup,” wrote one anonymous user on Anon-IB explaining the process to a less-experienced hacker. “Post your wins here ;-)”

Apple’s security nightmare began over the weekend, when hackers began leaking nude photos that included shots of Jennifer Lawrence, Kate Upton, and Kirsten Dunst. The security community quickly pointed fingers at the iBrute software, a tool released by security researcher Alexey Troshichev designed to take advantage of a flaw in Apple’s “Find My iPhone” feature to “brute-force” users’ iCloud passwords, cycling through thousands of guesses to crack the account.

If a hacker can obtain a user’s iCloud username and password with iBrute, he or she can log in to the victim’s iCloud.com account to steal photos. But if attackers instead impersonate the user’s device with Elcomsoft’s tool, the desktop application allows them to download the entire iPhone or iPad backup as a single folder, says Jonathan Zdziarski, a forensics consult and security researcher. That gives the intruders access to far more data, he says, including videos, application data, contacts, and text messages.

You can be sure that whatever the NSA is using is light years ahead of this, and that at some point in the next 5 years, it will be available in the criminal underground, along with whatever back doors the NSA has managed to put into our network infrastructure.

Gee, You Think?!?!?!?

In an exercise worthy of Captain Obvious, the CFPB is warning people that their Bitcoins are probably not safe from hackers:

“The CFPB advises consumers to be aware of potential issues with virtual currencies such as unclear costs, volatile exchange rates, the threat of hacking and scams, and that companies may not offer help or refunds for lost or stolen funds,” the government agency announced in an advisory on Monday . Consumers who’ve experienced problems with the virtual currency can also submit a complaint with the bureau, the CFPB said. “Virtual currencies are not backed by any government or central bank, and at this point consumers are stepping into the Wild West when they engage in the market,” it warned.

Well duh!

Gaaaahhhh!!!!!

My daughter’s phone has stopped working.

The display and touch screen are dead, but the rest of the phone, an LG Mach LS 860, still works.

I’ve been trying to figure out a way to get the already MyPhoneExplorer synching software to run with no access to the screen.

Why do I do this sh%$?

Gaah!!!!

I just spent the better part of three f#@&ing hours fixing an esoteric server problem with the Verizon SMTP servers that read bedeviling my wife’s email program (Eudora).

We are talking in the weeds bulsh#@ port numbers and authentication settings.

I knew that one would work, but the permutations are a mind f#@$.

My gears us that someone retaken the thing because of Heartbleed.

FWIW, it was an SMTP server of smtp.verizon.net, authentication on, SSL/TLS on, port 465.

Shoot me now.

Posted via mobile.

This Comes as No Surprise

Maryland is dumping its healthcare exchange, and replacing it with Connecticut’s technology:

Maryland officials are set to replace the state’s online health-insurance exchange with technology from Connecticut’s insurance marketplace, according to two people familiar with the decision, an acknowledgment that a system that has cost at least $125.5 million is broken beyond repair.

The board of the Maryland exchange plans to vote on the change Tuesday, the day after the end of the first enrollment period for the state’s residents under the 2010 Affordable Care Act.

Marylanders will be able to use the exchange even as it is being overhauled. The first enrollment period opened Oct. 1 and closes Monday for insurance coverage that kicks in this year. A second open enrollment period starts Nov. 15.

Like Maryland, Connecticut was one of the first and most enthusiastic states to embrace the idea of building its own insurance exchange rather than using a federal site to implement the law’s sweeping changes in health-care coverage.

But unlike Maryland, where the system crashed within moments of launching and has limped along ever since, Connecticut’s exchange has worked as smoothly as any in the country.

I do think that this means that I have to reevaluate my assessment of O’Malley as the front-runner in the “Not Hillary” presidential primary.

Still, the fact that Maryland has decided to end its attempt and move to a working system, and that it did so before Oregon, Minnesota and Hawaii, all of whom have similar problems, was the right thing to do.

Time to Go Back to Using a Bank Teller

Am I the only one who is concerned about the fact that 95% Of ATMs Are Still Using Windows XP?

Who is still using Windows XP, an operating system which is now twelve years old? Other than “everyone’s mom,” the real answer might not be as obvious: the nation’s network of automated teller machines. ATMs all contain computers, of course. Computers are susceptible to malware. Systems running Windows XP may be more susceptible to malware after April 8 of this year, when Microsoft finally ends support and security patches for XP.

Don’t worry: it’s unlikely that the machines will start setting your savings account on fire anytime soon. Yet it boggles the mind to learn that 95% of ATMs in the world run on Windows XP. Still. That number won’t decrease very much after the deadline: one expert told Bloomberg Businessweek that maybe 15% would be upgraded by the deadline.

We are completely f%$#ed.

Has anyone considered secure BSD?  It’s free, and it’s, you know, not the Petri dish for security exploits that is Microsoft’s operating systems.

Remember When I Wrote that High Frequency Trading was Front-Running?

Well, Yves Smith has found a whistleblower video that is a must watch: (Background on front-running here):

Yes, it’s almost an hour long but the short version:

Mr. Bodek had been using common “limit orders,” which specify a price limit at which to buy or sell. Mr. Davidovich, according to Mr. Bodek, suggested that he instead use an order type called Hide Not Slide, which Direct Edge had introduced in early 2009, about the same time Trading Machines’ performance started to suffer.

Mr. Bodek says Mr. Davidovich told him Direct Edge had created this order type—which lets traders avoid having their orders displayed to the rest of the market—to attract high-frequency trading firms…

Mr. Bodek says he realized the orders he was using were disadvantaged, compared with Hide Not Slide orders. He says he found that in certain situations, the fact that a Hide Not Slide order was hidden allowed it to slip in ahead of some one-day limit orders that had been entered earlier. He also learned that other stock exchanges had order types somewhat like Hide Not Slide, with different twists.

“Man I feel like an idiot. Never grasped the full negative alpha embedded in a normal day limit,” Mr. Bodek emailed Mr.

We really need to start prosecuting these rat-f%$#s.

A Couple of Important Education Stories from New York State

I would note that the New York Daily News has looked at administrator salaries, and discovered that executives at 16 charter schools in the city are payed more than the New York City school chancellor.

Like I said, looterz want to loot.

More significant is that the Southold School District Superintendent on Long Island has demanded that all student data be removed from Bill Gates’ latest attempt to monetize our children:

After finding out that student data is being shared through the New York State Department of Education Department with a private third-party vendor, Southold School District Superintendent David Gamberg has formally requested to have its students’ data removed from the controversial software system, citing privacy concerns.

Newsday has reported that although student data is currently kept on state computer systems, New York is moving toward contracting with nonprofit Atlanta data company inBloom, Inc. to “store student test scores, disciplinary records, disabilities and other vital subjects.”

Mr. Gamberg fired off a letter to inBloom CEO Iwan Streichenberger on Monday, requesting to “opt-out” from its data storing system, known as the Shared Learning Infrastructure. He has found a clause in the contract that allows districts to request their records be removed from the system, according to Mr. Gamberg’s letter.

“It is our position that this data contains sensitive and highly personal student information that we prefer not be subjected to the potential for breach, unintentional distribution, access, or abuse without parental consent.,” Mr. Gamberg wrote.

Gee, you think?

I figured out that it was evil when I heard Bill Gates.