The Linkielist

Linking ideas with the world

Washington State released thousands of inmates early in error due to poor software

Gov. Jay Inslee says the Washington Department of Corrections has been making mistakes in calculating sentences since 2002, resulting in thousands of inmates leaving prison early. Corrections officials learned of the problem in 2012. Source: ‘Totally unacceptable’: State knew thousands of inmates were released in error This is why QA is so important!

Swedish researchers reveal (fixable) security hole in quantum cryptography

The energy-time entanglement technology for quantum encryption studied here is based on testing the connection at the same time as the encryption key is created. Two photons are sent out at exactly the same time in different directions. At both ends of the connection is an interferometer where a small phase shift is added. This Read more about Swedish researchers reveal (fixable) security hole in quantum cryptography[…]

BadWinmail (Flash) Microsoft Outlook Bug Can Give Attackers Control Over PCs

When a user opens an Outlook email or previews the email in one of the Outlook panels, the OLE mechanism will automatically read the embedded Flash object and try to execute it, to provide a preview. Since most Flash exploits only need to be executed to work, and because there’s a flaw in the Outlook Read more about BadWinmail (Flash) Microsoft Outlook Bug Can Give Attackers Control Over PCs[…]

Some Rainbows Don’t Have Every Color of the Rainbow: there are 12 types

There are at least 12 kinds of rainbows, a new study reveals, and some skip a color or two. Since the 1950s, rainbow classification has been based on the size of the raindrops that create them. The bigger the drops, the more vivid the colors. Another attempt organized them by the height of the sun Read more about Some Rainbows Don’t Have Every Color of the Rainbow: there are 12 types[…]

RayZone InterApp: The Gadget That Can Spy on Any Smartphone

InterApp can allow its operators to break into nearby smartphones that have their WiFi connection open, and then, employing a diverse arsenal of security vulnerabilities, gain root permission on devices and exfiltrate information to a tactical server. According to Rayzone, InterApp can steal a user’s email address password and content, passwords for social networking apps, Read more about RayZone InterApp: The Gadget That Can Spy on Any Smartphone[…]

Database leak exposes 3.3 million Hello Kitty fans

A database for sanriotown.com, the official online community for Hello Kitty and other Sanrio characters, has been discovered online by researcher Chris Vickery. The database houses 3.3 million accounts, and has ties to a number of other Hello Kitty portals. The records exposed include first and last names, birthday (encoded, but easily reversible Vickery said), Read more about Database leak exposes 3.3 million Hello Kitty fans[…]

Project Zero: FireEye security appliance Exploited by passing jar file through it

FireEye sell security appliances to enterprise and government customers. FireEye’s flagship products are monitoring devices designed to be installed at egress points of large networks, i.e. where traffic flows from the intranet to the internet. Source: Project Zero: FireEye Exploitation: Project Zero’s Vulnerability of the Beast All you need to do is send the jar Read more about Project Zero: FireEye security appliance Exploited by passing jar file through it[…]

Bionic eye will send images direct to the brain to restore sight via 500 pixel “display”

The plan is to implant up to 11 small tiles, each loaded with 43 electrodes, into areas of the brain that deal with vision. When these areas are stimulated, people report seeing flashes of light. Lowery believes that each electrode could create a dot of light that is similar to seeing one pixel. In total, Read more about Bionic eye will send images direct to the brain to restore sight via 500 pixel “display”[…]

Microsoft: Upgrade to Windows 10 NOW or TONIGHT!

The large pop-up screen, which first appeared over the weekend, gives users the option of upgrading straight away or … that evening. Users can still opt out by clicking on the red ‘X’ in the top right corner of the window, but less savvy computer users (part of Redmond’s core market segments) might not figure Read more about Microsoft: Upgrade to Windows 10 NOW or TONIGHT![…]

Machine Learning Inspired by Human Learning  – AI can learn handwriting using a single example

Taking inspiration from the way humans seem to learn, scientists have created AI software capable of picking up new knowledge in a far more efficient and sophisticated way. The new AI program can recognize a handwritten character about as accurately as a human can, after seeing just a single example. The best existing machine-learning algorithms, Read more about Machine Learning Inspired by Human Learning  – AI can learn handwriting using a single example[…]

Congress strips out privacy protections from CISA ‘security’ bill

Under the original CISA legislation, companies would share their users’ information with federal government departments once it had been anonymized. The government could then analyze it for online threats, while the companies received legal immunity from prosecution for breaking existing privacy agreements. But as the bill was amended, the privacy parts of the proposed law Read more about Congress strips out privacy protections from CISA ‘security’ bill[…]

Grub2 Authentication Bypass: press backspace 28 times

A vulnerability in Grub2 has been found. Versions from 1.98 (December, 2009) to 2.02 (December, 2015) are affected. The vulnerability can be exploited under certain circumstances, allowing local attackers to bypass any kind of authentication (plain or hashed passwords). And so, the attacker may take control of the computer. Source: Back to 28: Grub2 Authentication Read more about Grub2 Authentication Bypass: press backspace 28 times[…]

Cox Is Liable for Pirating Subscribers, Ordered to pay $25 million

Internet provider Cox Communications is responsible for the copyright infringements of its subscribers, a Virginia federal jury has ruled. The ISP is guilty of willful contributory copyright infringement and must pay music publisher BMG $25 million in damages. cox-logoToday marks the end of a crucial case that will define how U.S. Internet providers deal with Read more about Cox Is Liable for Pirating Subscribers, Ordered to pay $25 million[…]

Ted Cruz campaign using firm that harvested data on millions of unwitting Facebook users

Ted Cruz’s presidential campaign is using psychological data based on research spanning tens of millions of Facebook users, harvested largely without their permission, to boost his surging White House run and gain an edge over Donald Trump and other Republican rivals, the Guardian can reveal. A little-known data company (Cambridge Analytica), now embedded within Cruz’s Read more about Ted Cruz campaign using firm that harvested data on millions of unwitting Facebook users[…]

MIT Creates messaging system which becomes unsniffable through chaffing data: Vuvuzela

Vuvuzela relies on dummy traffic to hide the real connections Before it’s decided where to store its content, the message goes through different servers, which send out dummy traffic to all interconnected users. The server notifies the recipient that there’s a message for them, the user then goes to retrieve it, also passing through different Read more about MIT Creates messaging system which becomes unsniffable through chaffing data: Vuvuzela[…]

Latest Philips Hue update closes the system, makes it impossible to connect other ZigBee lights

Haven’t they learned from Apple? Closing your system makes users run for more open products. Not a good idea, Philips, I’m not buying this anymore! De laatste firmware-update voor de Philips Hue bridge brengt een onaangekondigde wijziging. Slimme lampen van andere fabrikanten kunnen niet langer gekoppeld Source: Philips Hue wordt een gesloten systeem

UK citizens may soon need licenses to photograph some stuff they already own

Copyright strikes again, with photographers and publishers hit particularly hard. Changes to UK copyright law will soon mean that you may need to take out a licence to photograph classic designer objects even if you own them. That’s the result of the Enterprise and Regulatory Reform Act 2013, which extends the copyright of artistic objects Read more about UK citizens may soon need licenses to photograph some stuff they already own[…]