A Merry Christmas to all Bankers
The bankers' trade association has written to Cambridge University asking for the MPhil thesis of one of our research students, Omar Choudary, to be taken offline. They complain it contains too much detail of our No-PIN attack on Chip-and-PIN and thus "breaches the boundary of responsible disclosure"; they also complain about Omar's post on the subject to this blog.
The bankers also fret that "future research, which may potentially be more damaging, may also be published in this level of detail".
Why the Leather Cover Crashes the Kindle 3
I was in the middle of writing a blog post about how great the Kindle 3 and Connectify work together (which I will post in the next day or two), but started having a problem with my Kindle crashing randomly.
It didn't seem to make a lot of sense that a leather cover would crash an electronic device, so I got curious and started to look closely at my Kindle's case.
Once a bit of paint has rubbed off the hooks, power starts flowing through the cover, leading to brownouts.
Intel's Sandy Bridge processors have a remote kill switch
Intel's new Sandy Bridge processors have a new feature that the chip giant is calling Anti-Theft 3.0. The processor can be disabled even if the computer has no Internet connection or isn't even turned on, over a 3G network.
While a given stolen netbook, laptop, or desktop can no longer be turned on if Intel's new kill switch is flipped, there's nothing stopping the thief from taking out the HDD and putting it in another computer.
Secret Button Sequence Bypasses iPhone Security
A Brazilian iPhone customer demonstrates the quick method to circumvent an iPhone's passcode-protected lock screen: tap the "Emergency Call" button, then enter three pound signs, hit the green Call button and immediately press the Lock button.
An Apple spokeswoman contacted Wired.com with a response regarding the security flaw: "We're aware of this issue and we will deliver a fix to customers as part of the iOS 4.2 software update in November."
Sony: Counterfeit PS3 controllers can explode
Sony informed consumers this week that some counterfeit PlayStation 3 controllers could ignite or explode when used.
The company did recommend that consumers stick with its own wireless controllers, which are available from a number of reputable retail outlets.
Intel Threatens to Sue Anyone Who Uses HDCP Crack
Intel threatened legal action Friday against anybody who uses its proprietary crypto key - leaked on the internet - to produce hardware that defeats the so-called HDCP technology that limits home recording of digital television and Blu-ray.
The anonymous release this week of the HDCP master key means black market hardware makers, perhaps in China, can now create hardware capable of defeating the copy protection scheme.
"Someone has used mathematics and computers to be able to work back to what the master key is"
PSJailbreak cloned, released, freely available
You'll need the code, a PlayStation 3, and a USB microcontroller in order to open your system. Oddly enough, sales of such devices seem to be in the middle of a spike.
Once the PlayStation 3 was hacked it was only a matter of time before the software was made available free of charge; there are simply too many risks involved with selling this sort of thing via a standard storefront, and too many people more interested in the software's spread than profit.
New iPhone Security Patent App: User Protection or 1984 iSpy?
One method the patent describes for detecting a stolen iPhone is checking whether it's been hacked (aka "jailbroken") or its SIM card has been yanked out - things a clever thief would do to override the iPhone's security.
"Ignoring the possibility that a false positive in Apple's proposed theft protection might activate the spy cam while the user is in the bath, or in the middle of some other intimate moment, this technology seems Orwellian for another reason: It gives Steve Jobs and Co. the means to retaliate when iPhones aren't being used in ways Cupertino doesn't expressly permit," The Register wrote over the weekend.
E-Voting Machine Easily Reprogrammed To Play Pac-Man
The really important point is that they did this in three afternoons (and remember, these machines are often left totally unguarded, in the open at polling places for days before elections) without breaking any of the "tamper-resistant" seals that are supposed to alert anyone to any foul play.
So now my only question is whether or not they get a cease and desist from NAMCO.
U.S. Declares iPhone Jailbreaking Legal, Over Apple's Objections
Federal regulators lifted a cloud of uncertainty when they announced it was lawful to hack or "jailbreak" an iPhone, declaring Monday there was "no basis for copyright law to assist Apple in protecting its restrictive business model."
Apple also told regulators that the nation's cellphone networks could suffer "potentially catastrophic" cyberattacks by iPhone-wielding hackers at home and abroad if iPhone owners are permitted to legally jailbreak their shiny wireless devices.