Showing posts with label exploit. Show all posts
Showing posts with label exploit. Show all posts

04 January 2018

Intel Chip 12 Class Action Flaw Lawsuits Filed 9-California 2-New York 1-Illinois Computer Chip Flaws What You Need To Do Per New York Times Linked Below Intel Chip Flaw Protect Your Windows PC / Laptop Per Cnet.com Linked Below Major Security Threat Computer Global Flaw "Meltdown" And "Spectre" Found

UPDATED to 14 January 2018

     Thursday, 4 January 2018, SAN FRANCISCO - After news leaked prematurely computer security experts have had to warn the public that two major flaws have been discovered in microprocessors used in nearly all the world's computers. The flaws "Spectre" and "Meltdown" allow hackers to steal the entire memory contents of computers including mobile devices, personal computers and cloud computer networks. The personal computers of consumers are at risk, but hackers first need to run software on their machines including by fooling them into downloading software from an email, an app store or visiting an infected website.
       "Meltdown" is said to pose a significant threat to cloud computing services where hackers could  rent space on a cloud service then use the Meltdown exploit to steal passwords and other information from other customers. Various companies offering cloud services have told customers what they have done to address the vulnerability and what customers also must do. Meltdown still is a significant threat because cloud service companies typically have many customers sharing a single machine while the exploit is able to go around security features which normally keep customers' data apart in a single machine.
       Companies and organizations have made statements about the status of patches and update directions as available and necessary to address the "Meltdown" vulnerability found in virtually all Intel microprocessors. Intel reportedly makes chips that are used in more than 90% of computer servers underpinning the internet and business operations. Customers of Microsoft which makes the Windows operating system will need to install an update to fix the problem. The worldwide community of open-source Linux coders are said already to have posted a patch to address the vulnerability in that operating system which is used by about 30% of worldwide computer users. Apple reportedly has a "partial fix" for the problem and should have an additional update coming. 
       Although neither vulnerability was thought to have been exploited by hackers yet, when news of the Meltdown vulnerability was leaked prematurely researchers on Wednesday, 3 December 2017 released papers describing the flaws.  For now computer security experts are said to be using a patch called "Kaiser" that was discovered at an Austrian university last year to deal with a separate flaw. Of severely negative significance the fixes installed so far for Meltdown have had the enormous impact of reducing the speed of all operating systems by about 30% across the board. 
        The other flaw "Spectre" affects most processors in use, although computer security experts believe that hackers will have more difficulty exploiting this flaw. But the major threat it poses is that there is no known fix for this flaw which is a fundamental problem in the way microprocessors are designed. What Intel will do in response to its discovery is not known other then so far playing down this existential threat of immense proportions ignoring for the moment that all one's data may be copied by hackers using "Spectre" but instead emphasizing the relatively small consolation that "Intel believes these exploits do not have the potential to corrupt, modify or delete data."
       Paul Kocher, the president and chief scientist at Cryptography Research, a division of Rambus, and one of a coordinating group of four at different institutions who as well as another computer scientist at Google at the same time discovered the flaw, said that "Spectre is going to live with us for decades."  He said that "[w]hereas Meltdown is an urgent crisis, Spectre affects virtually all fast microprocessors. Mr. Kocher lamented that the emphasis on speed in designing chips has left them so vulnerable as to security.
       '"We've really screwed up', Mr. Kocher said. 'There's been this desire from the industry to be as fast as possible and secure at the same time. Spectre shows you cannot have both.' A fix for Spectre may not be available until a new generation of chips hit the market. 'This will be a festering problem over hardware life cycles. It's not going to change today or tomorrow', Mr. Kocher said. 'It's going to take a while.'"

UPDATES to 14 January 2018 At least a dozen class action lawsuits as detailed further in the first article linked to below have been brought against Intel alleging damages from chip flaws with 9 reportedly filed in California 2 in New York and 1 in Illinois. Interested readers also can go to links below to "What You Need To Do Because Of Flaws In Computer Chips" From The New York Times And/Or "How to Protect Your PC Against The Intel Chip Flaw" For Windows PC or Laptop from cnet.com at the last two links below with further information in the preceding second and third links although updated more recent information should also now be available.

https://firstlinemag.com/intel-faces-dozen-class-action-lawsuits-over-chip-flaws/ 12 Intel class actions
https://www.nytimes.com/2018/01/03/business/computer-flaws.html More information on above chip flaws

Copyright 2018 Martin P. All World Rights Expressly Reserved

11 September 2014

ISIS "Threat" To U.S. National Security Vastly Overblown Or Non-Existent Senior U.S. Counterterrorism And Intelligence Officials Assert Follows Month-Long Public Terror Fueled By Incessant CNN Other Media Repetitive Coverage Exploiting Same Isolated Events Such As Deeply Sick Beheading Of Two American Journalists

        Thursday, 11 September 2014, WASHINGTON, D.C. - Welcome to the new paradigm of "news" (acronym for North, East, West, South) courtesy most obviously of CNN where seemingly every item very effectively makes viewers feel compelled to be sure to return after (or hopefully sit entranced through) incessantly repetitive advertisers' brainwashing "breaks" for morbid fear that should viewers fail to be present for what the odds should have long ago taught them almost certainly just will be yet another exactly the same word-for-word image-for-image similarly "brainwashing" piece that previously has been aired (cabled or whatever) most likely several hundred times already in the past day other than perhaps with a slightly different introduction reflecting the winning personality of the host of the hour be it Wolf Blitzer, Anderson Cooper the man present at all places at all times, Don Lemon or whomever.
       After how many hundred airings does the same segment lose the status of "Breaking News" on CNN which with its ever-growing casual interpretation of the term now seems to blaze it across the bottom of the screen constantly for most anything along with the casual convenient repetition of the term "LIVE" even for items seen days before presumably based on the unlikely argument that CNN lacks the technical capability to remove the term "LIVE" from the piece even once it becomes untrue (immediately), and now in any case failing the above CNN it would seem has resorted to more or less denoting entire news shows as "Breaking News" or at the very least "Developing News" should CNN really not be able to come up with a straight face with anything else sounding more like the commercially invaluable imminent unfolding crisis of the moment.
       In any case as touched on in the below linked article in today's New York Times apart from the apparent commercial benefit to CNN of the above tactics unfortunately for example as in the case at hand of the repetitive flooding literally thousands of times of Americans' and the world's television screens with the same images of two deeply pathologically depraved ISIS beheadings of American journalists unfortunately this has the presumed effect of serving exactly the purpose of aspiring terrorists to panic viewers into absorbing these two incidents rather than isolated as into what then become in viewers' minds rather cumulatively into virtually thousands of separate acts greatly distorting the presumed reality of at least the present American situation including unfortunately vastly inflating any immediacy of any threat to hundreds of millions of Americans such that they mistakenly perceive this scant totally incomplete information as any kind of actual proof of a infinitely powerful ISIS of unlimited reach which senior American officials increasingly have come to conclude it is not.
       Admit it or not CNN thus becomes the necessary tool of the vast dissemination of the gratification of distortions of a propaganda machine which without CNN would be essentially non-existent. Having stated this the Ninth Amendment editorial board however emphasizes it is appropriate, necessary and essential to expose such atrocities most widely to the extent that it makes a nation and its people accurately informed, rightly on guard and justly enraged at the sheer unmitigated evil which has been perpetrated against its citizens although this should not extend to the counterproductive fostering of uncontrolled terror which ultimately interferes with people's ability to adopt the most rational and lethally effective strategies in response.
       Readers in no way should interpret this as a downplaying of the significance of known horrific acts of heinous murders of Americans be it of a couple or hundreds by ISIS and most especially all kidnapping, torture and/or murder of innocent human beings who moreover as journalists have with their families and loved ones made huge personal sacrifices and risked their lives every day exercising their rights of free speech and the press in the extreme so that all of us comfortably at home in safety may stay informed of vital developments the world over that inform our opinions and help properly guide our governments' policies every day. These journalists are heroes and be it the work of special forces or whomever those who commit these abominations must be hunted down like rabid dogs and should they make it out alive be tried as the war and/or genocidal human rights criminals mass murdering terrorists that they are.
       The proof of this effect on Americans is addressed more extensively for interested readers in the New York Times article linked to below which documents the huge shift in public opinion on the threat of ISIS in the past month not only among a vulnerable population of average Americans but extending to those in serious government leadership positions as well. Most notably Secretary of Defense Chuck Hagel apparently has been caught up in the hysteria although President Obama has refrained from describing the ISIS threat to American domestic national security as "imminent".
       However on reading the article in its entirety readers may draw comfort or not depending on their assessment of the individuals involved from the fact that current and former top U.S. counterterrorism, intelligence and Homeland Security officials including those with vast Al Qaeda experience in no uncertain terms in most cases describe the present ISIS threat to U.S. national security as "non-existent" or virtually so. In fact the main concern of many now is to "tamp down" the media-manipulated "terror" of United States citizenry such that decision-makers may step back and give thoughtful and deep consideration to actions which as we long ago have learned could lead to all kinds of unintended consequences including some that are more dangerous in many complex ways ultimately to U.S. regional and national security interests than those the U.S. actually would achieve by "eradicating" ISIS. This could be expected experts say also to lay the groundwork (or rather trap) for another "yearslong" U.S. combat presence in the Middle East just at the time the U.S. finally had hoped to extricate itself from some of the remaining vestiges of the Cheney-Bush debacle which started in a matter of hours but has taken well over a decade to even come close to ending.
       Perhaps most telling an omen it has come to the attention of the Ninth Amendment's editorial board that Dick "Pigheart" Cheney whom sources frankly believed was dead (as in not just the walking kind either) has in past days made a very rare appearance before a closed-door group of House Republicans whom he urged not to walk away from the Middle East but encouraged increased involvement without specifically mentioning ISIS. Any advice comes from Dick "Pigheart" Cheney after his head spins and he emits green projectile vomit and in our humble opinion it is time to run, not walk, as far as possible from anything he recommends or anywhere he goes, especially in which he participates or offers the services of one of his latest renamed gang of mercenaries, felons and as yet unconvicted (or escaped) criminal killers and murderers from whose serious misdeeds he stands to profit whether by more atrocities and murders or just another tired scheme to rip off the United States Government from which he already has profited so handsomely. Luckily in this case the Republican group reportedly humored him with his meeting but at least publicly said they paid his words little heed indeed.

http://www.nytimes.com/2014/09/11/world/middleeast/struggling-to-gauge-isis-threat-even-as-us-prepares-to-act.html?hp&action=click&pgtype=Homepage&version=HpBlogHeadline&module=first-column-region&region=top-neaws&WT.nav=top-news&_r=w

Copyright 2014 Martin P. All World Rights Expressly Reserved

31 July 2013

Hacker Barnaby Jack Dead In Mid-30's On Eve Of Expected Major Revelation - "Hacking Humans" Implantable Medical Devices

       Wednesday, 31 July 2013, LAS VEGAS - The Associated Press has reported that the famous "hacker" Barnaby Jack the young man who just tomorrow was to deliver the headline talk "Implantable Medical Devices:  Hacking Humans" at the Black Hat conference in this once-reputed Mob gamblers' mecca cum corporate family amusement town is dead of unknown or unreported causes allegedly in San Francisco.
       According to the AP Mr. Jack gained widespread notoriety after revealing at the same Black Hat conference in 2010 that after some years spent studying methods of hacking automatic teller machines ("ATMs") he had successfully devised two distinct techniques to hack "stand-alone" teller machines and direct them to dump their entire load of cash. The first technique stemmed from his discovery according to the AP that all ATM keys made by one manufacturer came with exactly the same key to unlock a compartment in the ATM. Mr. Jack then reportedly used a USB slot to deliver a program that ordered the ATM to unload its cache of cash.
     The second technique developed by Mr. Jack reportedly took advantage of a flaw in the method by which ATM manufacturers communicate with their cash machines via the internet. Although not explicitly stated in the AP report presumably the result was the same as when the first technique described above was employed. Apparently since the time of Mr. Jack's examination of the weaknesses of ATM's he most recently had been employed by computer security firm IOActive, Inc. Both Mr. Jack's employer and the San Francisco Coroner's office were tight-lipped as to the cause of Mr. Jack's untimely death describing it only as "under investigation".
     At tomorrow's Black Hat conference in Las Vegas in Hacker Barnaby Jack's headline talk "Implantable Medical Devices: Hacking Humans" Mr. Jack presumably was prepared to reveal his more recently developed information including concerning the vulnerabilities of pacemakers and other implantable medical devices to hacking. Sources have said the time when his address was to be given will be left open to allow colleagues to "[C]ommemorate his life and work".

Copyright 2013 Big M All World Rights Expressly Reserved