Posts tonen met het label arstechnica (source). Alle posts tonen
Posts tonen met het label arstechnica (source). Alle posts tonen

20140112

On the anniversary of the death of Aaron Swartz, Anonymous hacks MIT again

[~Time Published January 12, 2014 at 07:37PM]

*/*/*/*/*/\*\*\*\*\*




ZDNet



Anonymous defaced MIT's SSL-enabled Cogeneration Project page on Friday night, displaying a page that called viewers to “Remember the day we fight back.” “The day we fight back” references a protest planned for February 11 in opposition to surveillance and remembering Internet activist Aaron Swartz. The protest is backed by the EFF, Demand Progress, reddit, and Mozilla, among other big players in Internet culture.The defacement no longer appears on the site, but cogen.mit.edu was down as of Saturday morning.

One year ago on Friday, Aaron Swartz killed himself in what his parents and peers consider to be the act of a person bullied by federal prosecutors, who were suing Swartz for logging into MIT's network to gain access to the JSTOR database. Swartz downloaded millions of academic journal articles, and when he was caught, the federal government charged him with wire fraud, computer fraud, unlawfully obtaining information from a protected computer, and recklessly damaging a protected computer. Prosecutors told Swartz that he could face “up to 35 years in prison.”

Bob Swartz, Aaron's father, has been very vocal about implicating MIT in the suicide of his son, as well. In an interview published this month, Bob Swartz spoke with Boston Magazine about MIT's complicity in Aaron's harsh prosecution, from aiding Secret Service in cracking Aaron's computer to refusing to publicly state that it didn't want jail time for Aaron. “I always felt that MIT would act in a reasonable and compassionate way and that MIT wasn’t the issue... I didn’t understand the depths of what MIT had done at that point,” Swartz told Boston Magazine.


Read 1 remaining paragraphs | Comments




*/*/*/*/*/View@Source\*\*\*\*\* (http://feeds.arstechnica.com/~r/arstechnica/index/~3/NdmkotUGyZc/)



[IFTTTautoSHAREv1.015 | Shared with ifttt.com More shared news etc on: http://bit.ly/Schavuiten_blog | RSS source: http://theoldreader.com/profile/51411ac5bd9279fddb0009c6]

20140109

Security Essentials for Windows XP will die when the OS does

[~Time Published January 09, 2014 at 01:31AM]

*/*/*/*/*/\*\*\*\*\*


There are three months to go for Windows XP. The ancient operating system is leaving extended support on April 8, at which point Microsoft will no longer ship free security fixes. XP itself isn't the only thing that's losing support on that date. The Windows XP version of Microsoft Security Essentials, the company's anti-malware app, will stop receiving signature updates on that date and will also be removed for download.

The message is clear: after April 8, Windows XP will be insecure, and Redmond isn't going to provide even a partial remedy for the security issues that will arise. Anti-virus software is just papering over the cracks if the operating system itself isn't getting fixed.

In contrast, both Google and Mozilla will provide updates for Chrome and Firefox beyond the cessation of Microsoft's support. Google has committed to supporting Chrome until April 2015.


Read 2 remaining paragraphs | Comments




*/*/*/*/*/View@Source\*\*\*\*\* (http://feeds.arstechnica.com/~r/arstechnica/index/~3/rDSS4IlaDnM/)



[IFTTTautoSHAREv1.015 | Shared with ifttt.com More shared news etc on: http://bit.ly/Schavuiten_blog | RSS source: http://theoldreader.com/profile/51411ac5bd9279fddb0009c6]

DoS attacks that took down big game sites abused Web’s time-synch protocol

[~Time Published January 09, 2014 at 01:25AM]

*/*/*/*/*/\*\*\*\*\*




69 percent of all DDoS attack traffic by bit volume in the first week of January was the result of NTP reflection.

Black Lotus



Miscreants who earlier this week took down servers for League of Legends, EA.com, and other online game services used a never-before-seen technique that vastly amplified the amount of junk traffic directed at denial-of-service targets.

Rather than directly flooding the targeted services with torrents of data, an attack group calling itself DERP Trolling sent much smaller-sized data requests to time-synchronization servers running the Network Time Protocol (NTP). By manipulating the requests to make them appear as if they originated from one of the gaming sites, the attackers were able to vastly amplify the firepower at their disposal. A spoofed request containing eight bytes will typically result in a 468-byte response to victim, an increase of more than 58 fold.

"Prior to December, an NTP attack was almost unheard of because if there was one it wasn't worth talking about," Shawn Marck, CEO of DoS-mitigation service Black Lotus told Ars. "It was so tiny it never showed up in the major reports. What we're witnessing is a shift in methodology."


Read 4 remaining paragraphs | Comments




*/*/*/*/*/View@Source\*\*\*\*\* (http://feeds.arstechnica.com/~r/arstechnica/index/~3/b8k3CBU8Oc8/)



[IFTTTautoSHAREv1.015 | Shared with ifttt.com More shared news etc on: http://bit.ly/Schavuiten_blog | RSS source: http://theoldreader.com/profile/51411ac5bd9279fddb0009c6]