Jobben viktigast för S i EU-valet SvD Inrikes(cached at February 17, 2014, 11:33 pm)

De tre mest prioriterade frågorna för Socialdemokraterna i EU-arbetet är nu spikade inför valet till Europaparlamentet den 25 maj, berättar partiledaren Stefan Löfven i en debattartikel i Dagens Industri.
Krugman: Say No To Comcast Acquisition of Time Warner Slashdotby samzenpus on internet at January 1, 1970, 1:00 am (cached at February 17, 2014, 11:32 pm)

nbauman writes "In his column, 'Barons of Broadband' New York Times columnist Paul Krugman says: 'Comcast perfectly fits the old notion of monopolists as robber barons, so-called by analogy with medieval warlords who perched in their castles overlooking the Rhine, extracting tolls from all who passed. The Time Warner deal would in effect let Comcast strengthen its fortifications, which has to be a bad idea. Comcast's chief executive says not to worry: "It will not reduce competition in any relevant market because our companies do not overlap or compete with each other. In fact, we do not operate in any of the same ZIP codes." This is, however, transparently disingenuous. The big concern about making Comcast even bigger isn't reduced competition for customers in local markets — for one thing, there's hardly any effective competition at that level anyway. It is that Comcast would have even more power than it already does to dictate terms to the providers of content for its digital pipes — and that its ability to drive tough deals upstream would make it even harder for potential downstream rivals to challenge its local monopolies.'"

Read more of this story at Slashdot.








CVE-2011-3588 (Natl. Vulnerability Database) SANS ISC SecNewsFeed(cached at February 17, 2014, 11:30 pm)

NTP reflection attacks continue, (Mon, Feb 17th) SANS Internet Storm Center, InfoCON: green(cached at February 17, 2014, 11:30 pm)

 
As we discussed here back in January, there has been a significant rise in large Network Time Protocol (NTP) reflection DDoS attacks. In such an attack, an attacker sends a crafted packet that requests a large amount of data that is ultimately sent to the spoofed host. 
 
In our previous post[1], we discussed in detail the “monlist” command but it’s not just “monlist” that can be abused but many level-6 and level-7 commands such as “showpeer”, “sysstats”, “peers”, “listpeers”.
 
To lock down your NTP server, please follow our previous post and upgrade your NTP version as outlined by US-Cert here[2].
 
Additionally, as a FYI, a recent US Cert alert [3] identified other possible sources of UDP amplification attacks and it is recommended to review.
 
For those that think, well that won't happen to me or "Who cares, DDoS attacks have been happening since 1999" this year has already shown an excessive number of public attacks using NTP, creating a devastating flood of traffic to anyone without top notch mitigation* measures lined up. And we're only in February.
 
Brian Krebs's web site, a reporter that write about cyber security stories,  was hit by a 200Gbps of NTP traffic over the last week [4]. Brian reports how and by whom launched the attack in a detail story that's well worth a read. It's not just small targets; since the start of 2014, as reported here, many online gaming websites have been targeted through these reflection-type attacks with the attackers taking to Twitter to announce the upcoming attack and later bask in the glory. The latest Arbor report [5] talks about this in further detail, mentions attacks of up to 309Gbps and names the relevant Twitter IDs tweeting about DDOS. Cloudflare indicated that the attack they saw earlier this week was 400Gbps. The sheer size of these attacks mean that they just don’t break the target but significant areas of the Internet, i.e. large collateral damage.
 
If you see NTP reflection attacks being targeted towards you, the standard best practice follows – 
 
• Apply ACLs to your perimeter network and as far possible upstream 
 
• Work with your ISP(s) to do the same [6]
 
• Lock down your own NTP servers and other UDP-listening servers 
 
• If you detect open ntp servers, report them to the Open NTP project [7]
 
For those that are looking for a handy DDoS quick reference guide explaining the different DDoS attack http://www.us-cert.gov/sites/default/files/publications/DDoS%20Quick%20Guide.pdf
 
* For the majority of businesses DDoS mitigation has a financial cost associated with it that increases upward for increased protection
 
[1] https://isc.sans.edu/diary/NTP+reflection+attack/17300
[2] https://www.us-cert.gov/ncas/alerts/TA14-013A
[3] https://www.us-cert.gov/ncas/alerts/TA14-017A 
[4] http://krebsonsecurity.com/2014/02/the-new-normal-200-400-gbps-ddos-attacks/
[5] http://www.arbornetworks.com/asert/2014/02/ntp-attacks-welcome-to-the-hockey-stick-era/
[6] http://www.ietf.org/rfc/rfc3704.txt 
[7] http://openntpproject.org/
 

Chris Mohan --- Internet Storm Center Handler on Duty

(c) SANS Internet Storm Center. http://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.
Exploring Your Mac’s Restarts via the Command Line TidBITS(cached at February 17, 2014, 11:02 pm)

Want to know how often you restart your Mac? Josh Centers explains a quick Terminal command that will do the job.

 

Read the full article at TidBITS, the oldest continuously published technology publication on the Internet. To get a full-text RSS feed, help support our work and become a TidBITS member! Members also enjoy an ad-free version of our Web site, email delivery of individual articles, the ability to make long comments with live links, and discounts on Take Control orders and other Apple-related products.

Museibesökare kraschade miljonvas SvD Utrikes(cached at February 17, 2014, 11:02 pm)

Polisen i USA grep på söndagen en museibesökare i Miami som anklagas för att medvetet ha slagit sönder en vas som värderas till 6,5 miljoner kronor.
New Encryption Scheme Could Protect Your Genome Slashdotby samzenpus on medicine at January 1, 1970, 1:00 am (cached at February 17, 2014, 11:02 pm)

sciencehabit writes "As the cost of genetic sequencing plummets, experts believe our genomes will help doctors detect diseases and save lives. But not all of us are comfortable releasing our biological blueprints into the world. Now cryptologists are perfecting a new privacy tool that turns genetic information into a secure yet functional format. Called homomorphic encryption, the method could help keep genomes private even as genetic testing shifts to cheap online cloud services."

Read more of this story at Slashdot.








Netflix and the serial discussion problem Scripting News(cached at February 17, 2014, 11:01 pm)

One thing you hear a lot when the subject of Netflix series comes up is that unlike other popular series, such as True Detective and Game of Thrones, is that there's no long-lasting online discussion of binge-watched series because of spoilers and because everyone progresses through the series at a different rate and at different times. For example, I just binged my way through Orange is the New Black many months after the series premiered. There's no online place for me to discuss these shows.

It occurs to me that the one entity that could neatly solve this problem is Netflix itself. They know where you're at in the series, and what would be a spoiler or not. So they could offer, at the end of an episode, to whisk you off to an a place where you could read commentary that was current up to exactly that point in the show, and no further. No spoilers. You get the sequential-ness that people get from non-binge-watched shows. A perfect feature that Netflix could offer that really no one else is as well-positioned to offer.

PS: Who's your favorite Orange is the New Black character? Mine is Alex. Makes me wish I could be a lesbian and have a girlfriend like her.

Tio döda i sydkoreanskt takras SvD Utrikes(cached at February 17, 2014, 10:33 pm)

Minst tio människor dog, 73 skadades och tiotals befarades ha fastnat när taket till ett auditorium rasade in i Gyeongju i sydöstra Sydkorea på måndagskvällen lokal tid, uppger räddningstjänsten. Bland offren ska minst 15 vara allvarligt skadade.
Fem till sjukhus efter krock SvD Inrikes(cached at February 17, 2014, 10:32 pm)

Fem personer fick föras till sjukhus efter en krock mellan en personbil och en mindre lastbil vid 21-tiden på måndagskvällen i Hjällbo i nordöstra Göteborg.
Elev stoppade kränkande skoldebatt SvD Inrikes(cached at February 17, 2014, 10:32 pm)

Förra veckan fick flera av Sollefteås gymnasieklasser i uppgift att skriva en argumenterande uppsats i engelska. Ett av ämnena var om det var rätt eller fel att låta homosexuella få adoptera - en rättighet som är lagstadgad i Sverige sedan 2003.
CVE-2011-2500 (Natl. Vulnerability Database) SANS ISC SecNewsFeed(cached at February 17, 2014, 10:30 pm)

South Korean Credit Card Firms Punished for Data Leak (SecurityWeek) SANS ISC SecNewsFeed(cached at February 17, 2014, 10:30 pm)

iPad Versus MacBook for the Mobile Writer TidBITS(cached at February 17, 2014, 10:03 pm)

In the first of a short series of articles looking at perhaps unexpected hardware choices for those in the Apple world, Julio Ojeda-Zapata, reporter for the St. Paul Pioneer Press, explains why the iPad Air is the perfect tool for his trade.

 

Read the full article at TidBITS, the oldest continuously published technology publication on the Internet. To get a full-text RSS feed, help support our work and become a TidBITS member! Members also enjoy an ad-free version of our Web site, email delivery of individual articles, the ability to make long comments with live links, and discounts on Take Control orders and other Apple-related products.

Nakenhet retar politiker SvD Utrikes(cached at February 17, 2014, 10:03 pm)

Serieteckningar av nakna människor har oväntat orsakat skandal i Frankrike. – Jag vill inte att våra små barn påtvingas nakenhet, ryter oppositionsledaren Jean-François Copé som går till attack mot skolboken ”Alla nakna”.