Monday, May 16, 2011

How Bin Laden Baffled US Electronic Surveillance

A still of 2004 Osama bin Laden videoOsama bin Laden didn't have an internet connection or a phone, but for years he was a prolific user of email  by saving messages to a thumb drive and having them sent from a distant internet cafe.


Bin Laden would type the messages on a computer that had no connection to the outside world and then instruct a trusted courier to drive to a cafe so they could be emailed.

The courier would then save messages addressed to bin Laden to the same drive and bring it back so his boss could read them offline.

The process was so tedious that even veteran intelligence officials have marveled at the al-Qaida chief's ability to maintain it for so long.

US Navy Seals seized roughly 100 flash memory drives when they killed bin Laden at his Abbottabad, Pakistan, compound.

The cache of messages is so big that the government has enlisted Arabic speakers from around the intelligence community to pore over them.

Thursday, May 12, 2011

Help Light Your Face During Video Chats With an Empty Browser Window

A Trust 120 SpaceCam webcamIf you live in your basement or a place where you don't have a lot of light, your webcam may have some trouble seeing you.

The solution? Use the light from your monitor.


If you're video-chatting with someone, simply open an blank browser window and type in the URL bar about:blank

Wednesday, May 11, 2011

ALL Your Music From the Cloud With Google Music Streams

Image representing Google as depicted in Crunc...Google Music, the streaming music answer to Amazon, MOG and Rdio, is here.

You can access music in the cloud and stream to devices. But unlike MOG and Rdio, you can only play what you upload.

How do you use it? You use Google's Music Manager on your desktop to add your songs to the service. It adds play counts and ratings as well. It's a "full featured music manager", so you can search and do all the other things you could in iTunes and Windows Media Player.

Here's a look at some of its features:

Library Upload: With the Music Manager app, you can upload your iTunes or Windows Media Player libraries with one click. You can also upload by file or folder.

Offline Listening: It's a pretty standard feature, but Google's gives this feature a neat twist by automatically caching songs you've recently listened to. I'd also love to see them do this for most listened songs. And of course, you can also cache specific songs you select. Necessary, since you can't re-download music from the service.

Seamlessness: Any change you make to your Google Music library on one device is automatically pushed to other devices.

Playlists: Once you upload your tracks to the Google Music cloud, you can play around with it just like it was in a music app. That means playlists which automatically sync across all your connected devices. They also have a smart playlist feature called instant mix, which will automatically build a list for you based on one song. It's like iTunes' genius or Pandora's recommendation bot. Google says that they have servers actually listening to the songs to make their playlist selection.

 The service can store up to 20,000 songs per user on up to eight authorized devices and took five minutes or so for the first 150 songs to upload.

But you don't always have an internet connection, or a good enough one to stream music. So you can either select certain music to cache on your device, and the service automatically caches your recently listened-to music as well.


You can request an invitation to Music Beta here.

Monday, May 9, 2011

White Hat Hackers Find Skype Security Hole For Mac

Image representing Skype as depicted in CrunchBase



Skype has issued an update for all Mac users, due to security concerns in Skype version 5.x for Mac which allows a malicious user to activate code on the victim’s computer.

A security researcher said today that he found a serious hole in the Mac version of Skype and proving that it was possible to send a specific message to a user of Skype and it would crash Skype and make it unusable.

Gordon Maddern, says he discovered the vulnerability about a month ago. He was chatting on Skype to a colleague about a payload when the payload executed in the colleague's Skype client accidentally.

He created a proof of concept that can be used in an attack but is not releasing details on it until Skype fixes the issue. He could not find the vulnerability in the Skype client for Windows and Linux, he said.

Friday, May 6, 2011

How To Embed MP3 Files On Website Or Blog

MP3's logoHow can you embed mp3 files into web pages?
Google audio player is a cool way to embed and play any music mp3 file on your website. This will allow your readers to play audio files directly from web pages.

To embed an MP3 file, add the following code to your web page or blog post.
<embed type="application/x-shockwave-flash" src="http://www.google.com/reader/ui/3523697345-audio-player.swf" quality="best" flashvars="audioUrl=LINK" width="500" height="27"></embed>

Replace LINK with the URL of the MP3 file. The file can be uploaded to any server or file hosting services including your own, as long as the file is directly accessible.

You can change the width of the Google audio player to fit your content width. If you increase the height, a black empty zone starts to appear, so best keep it at 27px.


Try to play the audio file below. It is embedded using the above code.


Thursday, May 5, 2011

Sony Knew Software Was Outdated Three Months Ago

Logo of the PlayStation NetworkIn congressional testimony this morning, Dr. Gene Spafford of Purdue University said that Sony was using seriously outdated software on its servers and knew about it approximately three months before, the company was informed by security experts monitoring open Internet forums that its version of Apache Web Server was out of date.

This version was unpatched and had no firewall protection of any kind.

Read the congessional testimony here (PDF)

Sony Blames Partially Anonymous For Security Breach and Data Theft

Logo of the PlayStation Network
Sony has blamed the online vigilante group Anonymous for indirectly allowing the security breach that allowed a hacker to gain access to the personal data of more than 100m online gamers.

In a letter to the House Energy and Commerce Committee's panel on commerce, manufacturing and trade, Sony said the breach came at the same time as it was fighting a denial-of-service attack from Anonymous, also they discovered a file planted on one of its servers named "Anonymous" with the words "We are Legion," the tagline for the group that has brought down the websites of big corporations such as Visa, the letter said.

In response, Anonymous released a statement Wednesday denying the allegations, but did allow that individual members may have been involved.
"Sony is incompetent," the group said. "While it could be the case that other Anons have acted by themselves AnonOps was not related to this incident and takes no responsibility."


Possible Security Breach At LastPass

Image representing LastPass as depicted in Cru...Users who manage and store their passwords through password management service LastPass are being forced to change their master passwords after the site noticed an issue this week that raised the spectre of a possible security breach.

LastPass wrote on their blog yesterday that because they can't account for the anomaly they detected in one of the databases, the company made the decision to assume the worst that some of its data had been hacked, even though they say you shouldn't be impacted by this issue if you have a strong, non-dictionary-based password.

LastPass hasn't identified a specific breach, it's erring on the site of caution by now forcing its members to change their master passwords.

LastPass let users create and manage passwords to more easily log in to the vast array of secure Web sites they visit.
Those passwords can be stored on a PC or mobile device as well as online. As one means of protection, LastPass typically urge users to create a single complex master password that can unlock the key to accessing their passwords.
Of course, if that master password is compromised, hackers potentially can gain access to all the individual passwords, one reason why these companies advise users to employ complex master passwords.

In the meantime, LastPass have moved services to other servers for now. They also compared the code on the live servers with code from their repositories to make sure it was not tampered with.
The company is also enhancing the encryption used to protect its data.

Wednesday, May 4, 2011

The Woz Tells Paul Allen To Stop Trolling

Steve Wozniak thumbs upApple and Microsoft have battled it out on many fronts over the years, but now there's a new one: the battle of the lesser-known co-founders.

Apple co-founder Steve Wozniak isn't entirely happy with the behavior of Microsoft co-founder Paul Allen and decided to tell him so.


Wozniak dedicated some pointed, if not poignant, remarks toward Allen at the Embedded System Conference Silicon Valley in San Jose, Calif., last week.

He reportedly declared: "That patent-troll thing...the other night Paul Allen was speaking at the Computer History Museum and I had four tickets.  And I decided at the last minute not to go, because I remembered he's suing all these companies like Apple and Google but he's not suing Microsoft because he bought all these patents."

Wozniak later said that Allen should be "investing in companies that are doing something, making products, actually making a new future for the world," rather than "get in bed with the lawyers to make my money."

Still, you might be wondering what Wozniak did instead of going to see Allen at the Computer History Museum. He reportedly wandered off with some friends to Marie Callender's. Not so much because he loves the pies, but because he loves the split-pea soup with ham.

Post-raid Satellite Image Of Osama Bin Laden Compound

Satellite images of the compund where Osama bin Laden was likely shot and killed have been released by GeoEye, a satellite imagery provider.


 
GeoEye:
This one-meter resolution image shows a walled compound in Abbottabad, Pakistan. According to news reports Abbottabad is the town where Osama bin Laden was killed by U.S. forces. The image was collected by the IKONOS satellite on May 2, 2011 at 10:51 a.m. local time while flying 423 miles above the Earth at an average speed of 17,000 mph, or four miles per second.
The timing of this image would be taken place 10 hours after the attack.

The crash site of the problem-helicopter seems plainly visibly as a blackened helicopter-shaped mass.
While there are photographs around of helicopter chunks eventually being hauled away, this satellite image seems to have been taken before then: