Sunday, March 27, 2011

Invention 'boosts phone storage'

Scottish researchers have helped to create a device which improves memory storage for technology including MP3s, smartphones and cameras.

The device uses a tiny mechanical arm to translate data into electrical signals.

This allows faster operation and uses less energy compared with conventional memory storage products.

The Edinburgh University researchers worked with the Konkuk University and Seoul National University, in Korea.

The device records data by measuring the current passing through a carbon nanotube, and the binary value of the data is determined by an electrode that controls the flow of current.

Previous attempts to use carbon nanotube transistors for memory storage hit a stumbling block because they had low operational speed and short memory retention times.

By using a mechanical arm to charge the electrode, which operates faster than conventional memory devices, scientists have been able to overcome the problems.

'Novel approach'

Prof Eleanor Campbell, from Edinburgh University's school of chemistry, said: "This is a novel approach to designing memory storage devices.

"With this device you have much faster switching on and off which you do not have with conventional memory storage devices.

"However, one of the issues with these novel devices is how easy they can be manufactured on an industrial scale, which we are yet to see."

Prof Campbell said research was continuing with colleagues in Korea on increasing the operating speed of the device even further.

The findings were published in the journal Nature Communications.



Powered By WizardRSS.com | Full Text Feeds | Amazon PluginsHud-1

Friday, March 25, 2011

Spam kings sought after takedown

The Rustock botnet, which sent up to 30 billion spam messages per day, might have been run by two or three people.

Early analysis, following raids to knock out the spam network, suggest that it was the work of a small team.

Rustock was made up of about one million hijacked PCs and employed a series of tricks to hide itself from scrutiny for years.

Since the raids on the network's hardware, global spam levels have dropped and remain relatively low.

Net gains

"It does not look like there were more than a couple of people running it to me," said Alex Lanstein, a senior engineer at security firm FireEye, which helped with the investigation into Rustock.

Mr Lanstein based his appraisal on familiarity with Rustock gained while working to shut it down over the past few years.

He said that the character of the code inside the Rustock malware and the way the giant network was run suggested that it was operated by a small team.

That work by FireEye, Microsoft, Pfizer and others culminated on 16 February with simultaneous raids on data centres in seven US cities that seized 96 servers which had acted as the command and control (C&C) system for Rustock.

Mr Lanstein said hard drives from the servers had been handed over to a forensic firm that will scour them for clues as to the identity of the network's controllers.

His hunch that a small team was behind Rustock is partly based on how different it was to other spam networks such as Zeus.

That network, said Mr Lanstein, operates on a franchise basis and involves many different groups and cyber criminals.

By contrast, Rustock was a tightly controlled, if huge, network that brought with it many of the administration headaches suffered by any web-based business.

"They ran into a lot of problems with managing their assets and pushing updates out to a million user network," he said.

Rustock evaded capture for years because of the clever way it was controlled, he said. Victims were snared when they visited websites seeded with booby-trapped adverts and links.

Once PCs were compromised, updates were regularly pushed out to them using custom written encryption. Those downloads contained the spam engine that despatched billions of ads for fake pharmaceuticals.

Updates to PCs in Rustock were also disguised to look like comments in discussion boards, making them hard to spot by security software which typically looks for well-known signs of malware.

The servers controlling Rustock were also located within hosting centres in the US rather than overseas.

"By locating all the C&C servers in middle-America, not in major metropolitan areas, they were able to stay off the radar," said Mr Lanstein.

Hosting costs for the C&C systems ran to about $10,000 (�6,211) per month, he said.

It was hard to estimate how much money the operators of Rustock had made, said Mr Lanstein, but it was likely to be a huge figure.

Since the raids, Rustock's controllers do not seem to have tried to re-assert control of their creation. Legal steps taken by Microsoft could limit any future attempt, said Mr Lanstein, adding that he was not sure they would even try.

"When you are a programmer and you realise that you have the full force of the Microsoft legal department pointed directly at you, then you might say to yourself its time to try something else," he said.



Powered By WizardRSS.com | Full Text Feeds | Amazon PluginsHud-1

Microsoft buys old net addresses

Microsoft has offered to pay $7.5m (�4.7m) for net addresses from bankrupt telecoms firm Nortel.

The 666,624 IP version 4 (IPv4) net addresses were put up for auction as part of the sell-off of Nortel's assets.

Blocks of IPv4 are valuable because the pool of this generation of address is close to running dry.

It was predicted that a market in IPv4 would appear among companies facing a costly migration to the newer IPv6.

Details of the sale were contained in papers filed to a Delaware bankruptcy court and show that Microsoft's bid was the highest of the 80 firms asked if they wanted to make an offer for the IP addresses.

The deal is yet to be approved by that court and anyone who objects to it can file their comments before 4 April.

If it goes through, Microsoft will get hold of 470,016 of the IP addresses instantly and the remaining 196,608 will be released as former customers of Nortel are moved to other telecoms firms.

IP addresses are used to identify individual computing devices on the internet and private networks.

IPv4 allows for a maximum of approximately 4.3 billion devices.

That number seemed enough in the early 1980s when the standard was first proposed, however the rapid growth in personal computers, smartphones and other internet connected devices means that addresses have been rapidly running out.

The last big blocks of IPv4 addresses were handed out in February and all of them are expected to be used up by late 2011.

Net firms are in the process of moving to version 6 of the IP addressing scheme, which offers more than 3 undecillion individual numbers (3 with 38 noughts)

However, the migration is happening very slowly.

In the interim, it is expected that IPv4 addresses will become increasingly valuable.

It is not clear why Microsoft wants to buy Nortel's supply, however many companies are keen to avoid the cost of changing their networking systems over to IPv6 compatible equipment.

The Microsoft-Nortel deal values the IPv4 address blocks at $11.25 (�7) each, higher than the price many firms charge for a .com domain. This was indicative, said experts, that the market for IPv4 addresses was heating up.

Registries that oversee the allocation of net addresses are also working on plans for a re-circulation system that takes IPv4 addresses from firms that are using IPv6 and releases them for use by others.



Powered By WizardRSS.com | Full Text Feeds | Amazon PluginsHud-1

Thursday, March 24, 2011

Cyber summit signs training deal

A conference on cyber security has ended with a university deal to train a new generation of experts in fighting off criminal and terrorist IT attacks.

The summit in Cardiff agreed that the UK and the US would need to produce many thousands of people with this expertise over the next few years.

Delegates at the University of Wales event included the UN, the US defence department, Microsoft and IBM.

The US says government systems are under continued attack.

The US federal government recently announced plans to spend more than $13bn a year within the next five years on protecting its systems.

In the UK, cyber crime is costing the economy up to �27bn every year, it is estimated.

US officials say cyber criminals, terrorists and other nations are getting better at penetrating state and private networks, whether to spy, to steal data or damage critical infrastructure.

"Start Quote

Cyber-physical security is now considered the number one threat to national security"

End Quote Professor John Williams Geospatial Data Centre, MIT

Last week, the head of the Pentagon's cyber command said the US military lacked the people and resources to defend the country adequately from concerted cyber attacks.

The two-day summit was organised by the University of Wales Global Academy and the Geospatial Data Center of the Massachusetts Institute of Technology (MIT) in the US.

It also included professors from Harvard University, the University of Oxford, University of Memphis, Boston University and the University of Central Florida.

'Overriding issue'

The University of Wales and the Geospatial Data Centre at MIT signed an agreement to jointly develop cyber security leadership and training programmes.

University of Wales vice-chancellor Professor Marc Clement said he believed the summit was a "major coup" for Wales and the deal signed would put Wales at the forefront of cyber security defence.

He said the university hoped to "work closely with many of the participating academics to take forward the agenda identified by the summit and to advance relations between MIT and the University of Wales".

He added: "We now plan to develop a joint training programme for taking forward educational developments in the field of cyber-physical security, an area that the summit agreed was the overriding issue for government, business, and universities."

Professor John Williams, director of the Geospatial Data Centre, said: "Cyber-physical security is now considered the number one threat to national security, being deemed more critical than conventional nuclear attacks.

"Last year alone, the US logged over 300,000 virus attacks on their networks and noted that organised crime now makes more money from cyber crime than any other activity."



Powered By WizardRSS.com | Full Text Feeds | Amazon PluginsHud-1

Iran accused in 'dire' net attack

Hackers in Iran have been accused of trying to subvert one of the net's key security systems.

Analysis in the wake of the thwarted attack suggests it originated and was co-ordinated via servers in Iran.

If it had succeeded, the attackers would been able to pass themselves off as web giants Google, Yahoo, Skype, Mozilla and Microsoft.

The impersonation would have let attackers trick web users into thinking they were accessing the real service.

Fake identity

The attack was mounted on the widely used online security system known as the Secure Sockets Layer or SSL.

This acts as a guarantee of identity so users can be confident that the site they are visiting is who it claims to be. The guarantee of identity is in the form of a digital passport known as a certificate.

Analysis of the attack reveals that someone got access to the computer systems of one firm that issue certificates. This allowed them to issue bogus certificated that, if they had been used, would have let them impersonate any one of several big net firms.

It appears that the attackers targeted the SSL certificates of several specific net communication services such as Gmail and Skype as well as other popular sites such as Microsoft Live, Yahoo and the Firefox browser.

SSL certificate issuer Comodo published an analysis of the attack which was carried out via the computer systems of one of its regional affiliates.

It said the attack exhibited "clinical accuracy" and that, along with other facets of the attack led it to one conclusion: "this was likely to be a state-driven attack."

It is thought it was carried out by the Iranian authorities to step up scrutiny of opposition groups in the country that use the web to co-ordinate their activity.

The bogus certificates have now been revoked and Comodo said it was looking into ways of improving security at its affiliates.

Browsers have also been updated so anyone visiting a site whose credentials are guaranteed by the bogus certificates will be warned.

Writing on the blog of digital rights lobby group the Electronic Frontier Foundation, Peter Eckersley, said the attack posed a "dire risk to internet security".

"The incident got close to � but was not quite � an internet-wide security meltdown," he said.

"We urgently need to start reinforcing the system that is currently used to authenticate and identify secure websites and e-mail systems," said Mr Eckersley.



Powered By WizardRSS.com | Full Text Feeds | Amazon PluginsHud-1

US hacker denies fleeing justice

The American hacker who unlocked Sony's PS3 has denied fleeing the country to avoid legal action.

George Hotz, also known as Geohot, said his trip had been planned for months and added that he was still in contact with his lawyers.

Sony had raised questions about the reason for his sudden disappearance in recent legal papers that it filed in California.

The company is suing him for computer fraud and breach of copyright.

To explain his absence, Mr Hotz wrote on his blog: "Factually, it's true I'm in South America, on a vacation I've had planned and paid for since November. I mean, it is Spring break; hacking isn't my life."

He continued: "Rest assured that not a dime of legal defense money would ever go toward something like this."

The blog was written in reaction to reports of his departure which speculated that he may have paid for the trip with money donated by supporters, intended to pay for pay for his legal costs.

Serious question

His absence was brought to light in the latest court documents filed by Sony Computer Entertainment America (SCEA) to the San Francisco court where he is being sued.

They raise concerns, both about Mr Hotz whereabouts and the condition of computer equipment he was due to submit for examination.

The filing states: "SCEA learned that Hotz had deliberately removed integral components of his impounded hard drives prior to delivering them to a third party neutral and that Hotz is now in South America, an excuse for why he will not immediately provide the components of his hard drives as requested by the neutral.

"Hotz's attempts to dodge this Court's authority raise very serious questions."

Sony launched its legal action in California where its US subsidiary is headquartered. It also claims that information relating to the hack was posted on several California-based websites, including Twitter and Youtube.

However, Mr Hotz has disputed the court's jurisdiction, claiming that he is a resident of New Jersey and that the PS3 is made in Japan.

Mr Hotz developed his system for unlocking the PlayStation 3 in 2009. It makes it possible for users to play "homebrew" software and copied games, although he denies that it was his intention to enable piracy.

Sony is taking legal action against Mr Hotz and more than 100 other defendants who, it claims, downloaded the hack.

In previous hearings, George Hotz has been ordered to hand over the IP addresses of users who accessed his website.



Powered By WizardRSS.com | Full Text Feeds | Amazon PluginsHud-1

Wednesday, March 23, 2011

Games industry wins tax relief

TIGA, the trade association which represents the UK games industry has described plans to enhance R&D tax credits as a "decisive victory" for its members.

The announcement in the budget should be worth around �7 million to the video games industry, a spokesman said.

It will mean studios can invest more in research and development, as well as hiring additional staff.

But it falls short of the specific tax relief that the industry wanted.

Dr Richard Wilson, TIGA chief executive said: "The R&D tax credits will deliver 60% to 70% more value to games studios than the current tax credit regime."

But he was unhappy that the government had not gone further.

"Failure to deliver TIGA's Games Tax Relief is a dismal decision that displays a complete lack of imagination and one which will leave the UK video games industry swimming against the tide internationally," he said.

"Our key competitors have tax breaks for games production. The UK does not," he said.

Canada, for example, saw its games industry grow by 33% between 2008 and 2010, while the UK sector declined by 9%.

Plans by Labour to introduce tax cuts for the games industry were scrapped by the incoming coalition government during its 2010 emergency budget.



Powered By WizardRSS.com | Full Text Feeds | Amazon PluginsHud-1

Sudan to unleash cyber jihadists

Sudan's ruling National Congress Party has warned that its "cyber jihadists" will "crush" internet-based dissent.

It follows an increase in anti-government campaigns organised on Facebook and Twitter.

Vice-president in Khartoum state, Mandur Al-Mahdi warned opposition groups that its "cyber battalion" was leading "online defence operations".

The country saw anti-government street protests in January.

The government, which seized power in a military coup in 1989, is concerned about uprisings similar to those seen across the Middle East and North Africa.

It reacted violently to street protests organised by opposition parties, detaining many activists.

In the run-up to the January protests, supporters of the NCP posted messages on the Facebook pages of dissidents, warning them against joining in.

So far the protests, organised by groups from Sudan's Darfur region, have failed to attract mass popularity.

Despite the NCP's threat, there is little evidence regarding the size or nature of the cyber battalion, or if it even exists.

In July 2010, oil-producing South Sudan became independent of the north.

Its ruling party, the Sudan People's Liberation Movement has since accused President Omar al-Bashir of plotting to overthrow the southern government.



Powered By WizardRSS.com | Full Text Feeds | Amazon PluginsHud-1

Millions download latest Firefox

More than five million people have downloaded the latest version of Firefox since its release a day ago.

Mozilla, which makes the number two web browser, has been keeping a real-time map showing where in the world users are installing the software.

Despite the rapid uptake, downloads have been slower for version 4 than its predecessor.

Over the past year, Firefox's market share has declined slightly in the face of competition from Google's Chrome.

Firefox 4 was made available for download less than a month after Microsoft launched Internet Explorer 9, the latest version of its market-leading browser.

Both pieces of software promise users a faster, more secure online experience.

Firefox, like its rival, now makes extensive use of HTML 5, one of main the programming languages used to build websites.

Both browsers feature hardware acceleration when displaying HTML 5 pages - drawing on the power of a computer's graphics processor to improve the speed of complex visuals.

Declining share

Within its first 24 hours, more than 5.5 million users had downloaded Firefox 4. However, that falls short of the 8 million who downloaded version 3 on its release day in 2008.

The lower figure may be explained by the widespread availability of pre-release versions of Firefox 4 in the months ahead of its launch.

Firefox has enjoyed rapid growth since it first appeared in 2004. At its peak, in 2009 it held a 24% market share, according to Netmarketshare.

However, by February 2011 its slice of the browser market had fallen to 21%.

At the same time, Google's Chrome browser has grown from 1% to 10%, according to the same figures.

Internet Explorer remains the dominant platform, although its fall has been the most precipitous - from 68% in March 2009 to 56% in February 2011.

Some analysts believe that Firefox could still secure a bigger piece of the increasingly fragmented market, especially among corporate users.

"Internet Explorer 9 is only for Windows Vista and 7. Two thirds of companies are still using Windows XP," said Ovum analyst Richard Edwards.

"If you want to make the most of the HTML 5 stuff that is out there then you have to go to IE9 and a Windows 7 upgrade or switch to Firefox.

"That may be a significant opportunity for Firefox," he said.



Powered By WizardRSS.com | Full Text RSS Feed | WordPress PluginHud 1

Digital Act heads to High Court

Parts of the Digital Economy Act that deal with illegal file-sharing are being challenged in the High Court.

Internet providers BT and TalkTalk demanded the judicial review, arguing that the legislation was rushed through parliament without proper debate.

They claim that the measures unnecessarily impact users' privacy and force ISPs to police copyright infringement on the net.

If the court finds in their favour, the act would no longer be enforceable.

"It is a big deal to be judicially reviewing primary legislation but we took advice and there were very clearly were some real problems," said Simon Milner, BT's head of industry policy.

"It might find that it is all fine - I'd be surprised if it was - but we are going to court to get legal clarity," he added.

Letter campaign

"Start Quote

Peer-to-peer file-sharing is yesterday's game. People now are going off the network where they won't be detected - swapping hard-drives, and getting music via blogs and upload sites"

End Quote Mark Mulligan Forrrester Research

The courts will consider whether the act is in line with European legislation, in particular as it relates to users' privacy and the role of ISPs.

The previous government brought in the tough measures to deal with the growing issue of internet piracy.

Under the current legislation, content providers will have to monitor peer-to-peer networks for illegal activity and collate the IP addresses - the numerical code that links a particular computer network to an illegally downloaded file.

They can then apply to a court to force ISPs to surrender the real world address that is connected to that IP address.

Letters could then be sent to alleged net pirates, advising them that their computer connection has been used in illegal activity.

The creative industry is keen that the emphasis will be on education initially, although people will go on a blacklist which could in future be used to take individual infringers to court.

Other penalties, such as slowing down net connections or even cutting people off from the net entirely have not been ruled out, but would need additional legislation.

The letter-writing strategy bears similarities to the tactics of discredited law firm ACS: Law, which sent over 10,000 letters to alleged net pirates.

Unlike content providers, which will not be levying fines, ACS: Law collected some �300,000 from people - who were charged an average of �500 per infringement.

Not everyone paid up and 27 cases recently went to court in highly controversial circumstances.

Lead solicitor Andrew Crossley attempted to discontinue the cases shortly before the hearing was due and was accused of obstructing the court process.

In the middle of the case, Mr Crossley said he no longer wanted to be in the business of chasing net pirates and the cases were eventually thrown out.

But he faces an investigation for his conduct from the Solicitors' Regulation Authority and could be hit with legal costs for the cases he brought.

Yesterday's game

During the court case, doubt was cast over whether an IP address was suitable evidence of wrong-doing as it does not identify the individual user - only the location of their connection.

Consumer watchdog Which? highlighted several cases where people claimed to have been wrongly accused.

Charles Dunstone, chairman of TalkTalk, thinks the same thing will happen if the government's measures go ahead.

"Innocent broadband customers will suffer and citizens will have their privacy invaded," he said.

Jim Killock, director of the Open Rights Group, said that he is particularly worried about how the legislation will affect public wi-fi hotspots.

"We need to start again and find a new policy settlement which embraces, rather than tramples on, the exciting possibilities that the digital age offers," he said.

John McVay, chief executive of PACT (Producers Alliance for Cinema and TV), who will represent the UK's creative industries at the judicial review, defended the act.

"The Digital Economy Act is the result of many years of consultation and presents a reasonable and balanced solution," he said.

But Mark Mulligan, an analyst with Forrester Research, warned that even if the act remains intact, the measures won't work because they are already out-of-date.

"Peer-to-peer file-sharing is yesterday's game. People now are going off the network where they won't be detected - swapping hard-drives, and getting music via blogs and upload sites," he said.



Powered By WizardRSS.com | Full Text RSS Feed | WordPress PluginHud 1