Army seeking psychologically inspired object recognition system
[Via Wired, image courtesy of ACM]
Posts with tag security
Pairing up display-laden Wireless USB device with another machine is quite possibly one of the easiest processes known to man, but what if your W-USB device is screen-less? Enter WiQuest, the self-proclaimed leader in WiMedia-based ultra-wideband solutions, which has just revealed a new Wireless USB PIN Association method "specifically designed for Wireless USB-enabled devices that do not have a display." In its words, "once the Association process is initiated, a software screen on the host PC requests that the unique PIN printed on the Wireless USB device be entered and the secure pairing is completed -- wirelessly." We just love it when a good plan comes together.
It looks like those that enjoy a little remote control over their coffee could be unwittingly leaving both their PCs and their precious brew vulnerable, at least according to BDO risk advisory services manager Craig Wright, who found that his Jura F90 internet-connected coffee maker had several significant security holes, including a buffer overflow in its internet connection software. That, he says, could potentially allow an attacker to take control of the PC connected to the coffee maker, not to mention control the strength of the coffee and perform unwanted diagnostics. Of course, given the number of internet-connected coffee makers out there right now, Wright admits that the potential risk is relatively low (and moot if it's behind a firewall), but he has some dire warnings for the future, saying that eventually "you'll be able to turn on your oven with your mobile phone," which he says could lead to a malicious hacker "burning the house down."
Although several Indian news outlets reported last week that RIM was preparing to let the Indian government monitor the domestic Blackberry network, it appears that the outcry has prompted the company to change course and announce that it's committed to "serving security-conscious businesses in the Indian market." That's a big reversal from the rumored plan, which would have allowed Indian security agencies access to the network in exchange for taking the blame for any leak of user data. Of course, not everything's quite settled yet: the Indian government is still demanding that RIM furnish "satisfactory answers" to its security questions, and RIM told the AFP that there are some other ways for "government to take care of security concerns" without elaborating further. Based on RIM's enterprise-heavy statements and refusal to comment on the consumer service, we'd guess that enterprise customers will probably get to keep their networks locked down, but that consumers shouldn't expect their messages to be secure. Not the best compromise, but we'll see how this all plays out.
So news is making its way around the internets that at the Wedbush Morgan Securities Management Access Conference, Atari founder Nolan Bushnell proclaimed the end of PC gaming piracy as we know it, thanks to a "stealth encryption chip." The magic chip he's referring to that "will, in fact, absolutely stop piracy of gameplay"? The TPM chip -- what's been on motherboards for years, that apparently Bushnell just found out about. While the tinfoil hats in the house will likely attribute TPM (Trusted Platform Module) and other onboard crypto-chips to the eventual downfall of privacy and personal computing, to date we've yet to see piracy stunted or civil liberties breached because of the little bugger. FUD you later, Nolan.
You know all that network hardware that runs quietly 24 hours a day in server rooms around the world? What if black-hats could exploit remote firmware flashing utilities to take over -- or completely destroy -- vulnerable gear? Though still theoretical, PDOS -- permanent denial-of-service -- attacks will be demonstrated by researchers from HP Security Labs at the EUSecWest security conference in London this week. "Phlashing", as it's being referred to, focuses on exploiting network-enabled firmware updates, making use of a fuzzing tool that tricks hardware into flashing anything from back-door access to a corrupt image, causing complete and permanent hardware failure. There's no reason to panic just yet (especially not when it comes to consumer devices, which typically don't support remote firmware updates), but given the amount of unattended and relatively dormant enterprise network hardware out there, this could be something for admins to seriously think about.
The Z-Wave standard for home automation has already proven itself to be a pretty versatile bit of technology, and it looks like its now set to ensnare yet another part of your house, with lock-maker Schlage set to introduce some web-enabled Z-Wave door locks. Those will let you lock or unlock your door from your PC, cellphone or any other wireless, web-enabled device -- or, of course, from the lock itself. That's done with the aid of a Z-Wave gateway that connects to your router, which relays the RF signals to and from the lock (or one of up to 256 other Z-Wave devices), and gives you the added benefit of extending the life of the batteries in the lock, which Schlage says should last for up to three years. Otherwise, the details on the locks themselves are pretty light, with the folks at Schlage only going so far as to say that they'll look "pretty similar" to their non-Z-Wave locks (pictured at right), and that they'll be "affordable," though presumably not less than the $150 their current locks go for.






Other Weblogs Inc. Network blogs you might be interested in: