Thursday, May 5, 2011

Sony Knew Software Was Outdated Three Months Ago

Logo of the PlayStation NetworkIn congressional testimony this morning, Dr. Gene Spafford of Purdue University said that Sony was using seriously outdated software on its servers and knew about it approximately three months before, the company was informed by security experts monitoring open Internet forums that its version of Apache Web Server was out of date.

This version was unpatched and had no firewall protection of any kind.

Read the congessional testimony here (PDF)

Sony Blames Partially Anonymous For Security Breach and Data Theft

Logo of the PlayStation Network
Sony has blamed the online vigilante group Anonymous for indirectly allowing the security breach that allowed a hacker to gain access to the personal data of more than 100m online gamers.

In a letter to the House Energy and Commerce Committee's panel on commerce, manufacturing and trade, Sony said the breach came at the same time as it was fighting a denial-of-service attack from Anonymous, also they discovered a file planted on one of its servers named "Anonymous" with the words "We are Legion," the tagline for the group that has brought down the websites of big corporations such as Visa, the letter said.

In response, Anonymous released a statement Wednesday denying the allegations, but did allow that individual members may have been involved.
"Sony is incompetent," the group said. "While it could be the case that other Anons have acted by themselves AnonOps was not related to this incident and takes no responsibility."


Possible Security Breach At LastPass

Image representing LastPass as depicted in Cru...Users who manage and store their passwords through password management service LastPass are being forced to change their master passwords after the site noticed an issue this week that raised the spectre of a possible security breach.

LastPass wrote on their blog yesterday that because they can't account for the anomaly they detected in one of the databases, the company made the decision to assume the worst that some of its data had been hacked, even though they say you shouldn't be impacted by this issue if you have a strong, non-dictionary-based password.

LastPass hasn't identified a specific breach, it's erring on the site of caution by now forcing its members to change their master passwords.

LastPass let users create and manage passwords to more easily log in to the vast array of secure Web sites they visit.
Those passwords can be stored on a PC or mobile device as well as online. As one means of protection, LastPass typically urge users to create a single complex master password that can unlock the key to accessing their passwords.
Of course, if that master password is compromised, hackers potentially can gain access to all the individual passwords, one reason why these companies advise users to employ complex master passwords.

In the meantime, LastPass have moved services to other servers for now. They also compared the code on the live servers with code from their repositories to make sure it was not tampered with.
The company is also enhancing the encryption used to protect its data.

Wednesday, May 4, 2011

The Woz Tells Paul Allen To Stop Trolling

Steve Wozniak thumbs upApple and Microsoft have battled it out on many fronts over the years, but now there's a new one: the battle of the lesser-known co-founders.

Apple co-founder Steve Wozniak isn't entirely happy with the behavior of Microsoft co-founder Paul Allen and decided to tell him so.


Wozniak dedicated some pointed, if not poignant, remarks toward Allen at the Embedded System Conference Silicon Valley in San Jose, Calif., last week.

He reportedly declared: "That patent-troll thing...the other night Paul Allen was speaking at the Computer History Museum and I had four tickets.  And I decided at the last minute not to go, because I remembered he's suing all these companies like Apple and Google but he's not suing Microsoft because he bought all these patents."

Wozniak later said that Allen should be "investing in companies that are doing something, making products, actually making a new future for the world," rather than "get in bed with the lawyers to make my money."

Still, you might be wondering what Wozniak did instead of going to see Allen at the Computer History Museum. He reportedly wandered off with some friends to Marie Callender's. Not so much because he loves the pies, but because he loves the split-pea soup with ham.

Post-raid Satellite Image Of Osama Bin Laden Compound

Satellite images of the compund where Osama bin Laden was likely shot and killed have been released by GeoEye, a satellite imagery provider.


 
GeoEye:
This one-meter resolution image shows a walled compound in Abbottabad, Pakistan. According to news reports Abbottabad is the town where Osama bin Laden was killed by U.S. forces. The image was collected by the IKONOS satellite on May 2, 2011 at 10:51 a.m. local time while flying 423 miles above the Earth at an average speed of 17,000 mph, or four miles per second.
The timing of this image would be taken place 10 hours after the attack.

The crash site of the problem-helicopter seems plainly visibly as a blackened helicopter-shaped mass.
While there are photographs around of helicopter chunks eventually being hauled away, this satellite image seems to have been taken before then:


Tuesday, May 3, 2011

Sony Hacked Again 25 Million More Accounts Hacked

Logo of the PlayStation NetworkHackers may have stolen the personal information of 24.6 million Sony Online Entertainment users.

More than 20,000 credit card and bank account numbers were also put at risk.

This in addition to the recent leak of over 70 million accounts from Sony’s PlayStation Network and Qriocity services.

Sony said that the compromised personal information includes customers’ names,
addresses, e-mail addresses, birth dates, gender, phone numbers, logins and hashed passwords.

Also at risk are the credit card numbers and expiration dates of 12,700 non-U.S. customers, plus 10,700 direct debit records from customers in Austria, Germany, Netherlands and Spain, containing bank-account numbers, customers’ names and addresses.

This information was stored in what Sony said was an “outdated database from 2007.”

Man liveblogs Osama Bin Laden operation unknowingly

A 33-year-old computer programmer, Sohaib Athar, who moved to the sleepy town of Abbottabad to escape the big city, became in his own words "the guy who liveblogged the Osama raid without knowing it.".
He did what any social-media addict would do: he began sending messages to the social networking site Twitter.

His first tweet was : "Helicopter hovering above Abbottabad at 1AM (is a rare event)."

Nestled in the mountains around 60 miles (95 kilometers) northeast of the capital, Abbottabad is a quiet, leafy town featuring a military academy, the barracks for three army regiments and even its own golf course.

Soon the sole helicopter multiplied into several and gunfire and explosions rocked the air above the town, and Athar's tweets quickly garnered 14,000 followers as he unwittingly described the U.S. operation to kill one of the world's most wanted militants.

He tweeted."The few people online at this time of the night are saying one of the copters was not Pakistani,"

As the operation to kill Osama Bin Laden unfolded, Athar "liveblogged" what he was hearing in real time, describing windows rattling as bombs exploded.

Athar then said one of the aircraft appeared to have been shot down. Two more helicopters rushed in, he reported.

The aircraft might be a drone. The army was conducting door-to-door searches in the surrounding area. The sound of an airplane could be heard overhead.

Throughout the battle, he related the rumors swirling through town: it was a training accident. Somebody was killed.

Soon, however, the rumbling of international events far beyond the confines of this quiet upscale suburb began to dawn on Athar, and he realized what he might be witnessing.

"I think the helicopter crash in Abbottabad, Pakistan and the President Obama breaking news address are connected," he tweeted.

Eight hours and about 35 tweets later, the confirmation came: "Osama Bin Laden killed in Abbottabad, Pakistan," Athar reported. "There goes the neighborhood."

http://www.reallyvirtual.com/
http://twitpic.com/4s8nfq

Monday, May 2, 2011

Scan Your Music Library For Missing Songs

How do you make sure that no songs are missing in your library?
That every album is complete?

Applications to scan a library of songs for missing tracks are very rare.
One application that can be used for the job is Jaikoz Audio Tagger.
This is not freeware but the trial version is good enough to find out if songs are missing in your whole music library.

The trial version is limited in functionality, but that is not a problem, we only use the software to find missing tracks in a local music collection, and that feature does not appear to be limited.

After installation the first step is to load the music library into the program.
This is done with a click on File --> Open Folder. Just pick the root folder of your collection to add it to the software. The application scans all folders and files under that structure automatically, and information about the identified music appears in the program interface afterwards.

Select Action --> Auto Correct, or press Ctrl-1 on the keyboard after this first step. This will look up all songs and albums at the online music database MusicBrainz.
This can take quite some time, depending on the number of songs and files stored under the root folder.

Use Reports --> List Missing Songs For Albums in the final step to run a scan for missing songs. All albums that have been identified in the second step will be scanned for missing songs. This is done by comparing the information from the MusicBranz music database with the existing tracks on the computer.

A report is generated and displayed in a popup window. Here you find information about the albums, artists and song titles that are missing.

The report is available as a HTML or CSV version, which can be both saved to the local directory. With those information at hand, it is now possible to obtain the missing songs to complete the music library on your computer.

The application is available for Microsoft Windows, Apple Macintosh and Linux.

Sony Details PlayStation Network Revival

Logo of the PlayStation NetworkWithin a week Sony will turn on most features of the PlayStation Network and offer its customers a selection of free downloads.

The PlayStation maker’s online service for its PlayStation 3 and PSP consoles will come back online this week following a massive security breach in which the personal information of over 70 million accounts, possibly including credit card numbers, was obtained by hackers.

Here's what's going to be coming back, as well as details on the new security measures that they hope will prevent events like this from happening again:
  • Restoration of Online game-play across the PlayStation®3 (PS3) and PSP® (PlayStation®Portable) systems
    -This includes titles requiring online verification and downloaded games
  • Access to Music Unlimited powered by Qriocity for PS3/PSP for existing subscribers
  • Access to account management and password reset
  • Access to download un-expired Movie Rentals on PS3, PSP and MediaGo
  • PlayStation®Home
  • Friends List
  • Chat Functionality
  • Added automated software monitoring and configuration management to help defend against new attacks
  • Enhanced levels of data protection and encryption
  • Enhanced ability to detect software intrusions within the network, unauthorized access and unusual activity patterns
  • Implementation of additional firewalls

All PlayStation 3 owners will have to download a system update and change their passwords before they will be allowed to sign in to the service again; all password changes must take place on the PlayStation 3 console on which the password was originally registered. This, says Sony, is an additional security

Sony has issued a press release read it here.

Sunday, May 1, 2011

Anonymous targets Iran with DoS attack

The hacker group Anonymous says its next target is Iran.

According to their latest online proclamation, members of the loosely organized group are planning  an attack designed to shut down Iranian Web sites beginning Sunday.

The "Operation Iran" seemed to already have begun late today with Web page defacements ostensibly targeted at Iranian hackers.
Anonymous left messages on several Web sites that had allegedly been previously attacked by the Iranian Cyber Army, including the site of a Canadian information systems firm and the site of a Ukrainian dancing group, according to an observer on an Anonymous Internet Relay Chat channel that members use to coordinate their operations.

"The people of Iran have the admiration of Anonymous, and the entire world," the statement says. "We can see that Iran still suffers at the hands of those in power. Your former government has seized control, and tries to silence you. People of Iran your rights belong to you."

Anonymous is known for its renegade cyberattacks in defense of perceived underdogs or to support freedom of expression or other anti-establishment causes.

Earlier this month, Anonymous targeted Sony in protest of the company's treatment of Sony PlayStation hacker George Hotz. Hotz and Sony have since settled the lawsuit Sony filed, and Anonymous has denied any involvement in a recent serious breach that exposed information of millions of Sony PlayStation Network customers.

In defense of WikiLeaks, the group targeted PayPal, Visa, MasterCard, and other companies late last year that had stopped enabling WikiLeaks to receive contributions.

Other Anonymous targets have been: Broadcast Music Inc., the Church of Scientology; the governments of Egypt, Iran, and Sweden; the Westboro Baptist Church; conservative activist billionaires Charles and David Koch and their companies; as well as security firm HBGary Federal, which had reportedly been working with the FBI to identify the leaders of Anonymous.

But everyone knows there's no leaders