Thursday, January 28, 2016
Hot Potato - Windows: the most dangerous OS in the world
Breen released exploit code for his attack dubbed Hot Potato following his talk at the Shmoocon conference in Washington over the weekend. "Hot Potato takes advantage of known issues in Windows to gain local privilege escalation in default configurations, namely NTLM relay -\- specifically HTTP-SMB relay - and NBNS spoofing," Breen says.
"Using this technique, we can elevate our privilege on a Windows workstation from the lowest levels to NT Authority/System – the highest level of privilege available on a Windows machine. "This is important because many organisations unfortunately rely on Windows account privileges to protect their corporate network."
http://theregister.co.uk/2016/01/20/hot/
Wednesday, January 27, 2016
Tails 2 Is Out!
* GNOME Shell, with lots of changes in the desktop environment.
* Debian 8 (Jessie), which upgrades most included software and improves many things under the hood.
This release fixes [many security issues](https://tails.boum.
# Changes
## New features
* Tails now uses the GNOME Shell desktop environment, in its Classic mode. GNOME Shell provides a modern, simple, and actively developed desktop environment. The Classic mode keeps the traditional Applications, Places menu, and windows list. Accessibility and non-Latin input sources are also better integrated.
To find your way around, [read our introduction to GNOME and the Tails desktop.](https://tails.boum.
The desktop and Applications menu
:
* Add Japanese support.
* Remove the Windows camouflage which is currently broken in GNOME Shell. We started working on [adding it back](https://labs.riseup.net/
* Change to `systemd` as init system and use it to:
* Sandbox many services using Linux namespaces and make them harder to exploit.
* Make the launching of Tor and the memory wipe on shutdown more robust.
* Sanitize our code base by replacing many custom scripts.
* Update most firmware packages which might improve hardware compatibility.
* Notify the user if Tails is running from a non-free virtualization software.
* Remove Claws Mail, replaced by [Icedove](https://tails.boum.
## Fixed problems
* HiDPI displays are better supported. ([#8659](https://labs.riseup.
* Remove the option to open a download with an external application in Tor Browser as this is usually impossible due to the AppArmor confinement. ([#9285](https://labs.riseup.
* Close Vidalia before restarting Tor.
* Allow Videos to access the DVD drive. ([#10455](https://labs.riseup.
* Allow configuring printers without administration password. ([#8443](https://labs.riseup.
# Known issues
* Tor Browser 5.5 introduces [protection against fingerprinting](https://trac.
See the current list of [known issues](https://tails.boum.
# Installing
We also redesigned completely our download and installation instructions to make it easier to get started with Tails.
For example, you can now verify the ISO image automatically from Firefox using a special add-on.
You can also install or upgrade Tails directly from Debian or Ubuntu using the `tails-installer` package.
[Try our new installation assistant.](https://tails.
 has built a map of the entire world via the communication links of all email, chat, and financial transactions? This map tells a story to them about all of us. It knows who we know. It knows who our activist allies and relationships are.
And, as if that wasn’t crappy enough, the NSA is trying to undermine the security of the internet as a whole by putting in back-doors and weakening encryption standards so that they can spy better. They spend $250,000,000 USD per year on this. This makes the entire internet less secure, and makes it easier for people, governments, and corporations to exploit, scam, and spy on each other.
While the NSA claims they are targeting terrorism, they have been targeting foreign politicians and companies, with evidence that this is happening particularly in Brazil and Mexico. This is plain old espionage and corporate spying. Terrorism is merely the justification for astounding encroachments on our civil liberties.
Last, we have to assume this is all the tip of an iceberg. We have to assume there are other spy agencies across the globe doing similar spy work that we don’t know about (yet).
Saturday, November 7, 2015
Quick Guide: Scanner Apps for Your Smartphone or Tablet
For iOS there’s Readdle’s Scanner Pro, capable of easily handling anything you throw its way. Take a picture of whatever you want to scan. The program then makes whatever is in the pic “look” scanned. Especially useful is the function that allows you to upload scanned images to Dropbox, Evernote, Google Drive, and other cloud-based storage services. Or email it to you or someone else simply by pushing the “Send” button. This one is $2.99.
Android fans will want to consider Mobile Doc Scanner 3 + OCR. Transform everything from receipts and invoices to white boards and magazine articles with the app also known as MDScan. Just take a picture, let the program do its thing, and you have a file that looks like every other scan you’ve ever made. Best of all, you can take a bunch of pictures on the fly and let the software process them later. Also allows for upload to cloud-based services. The price at the Google Play store is $4.99.
If you’re looking for a free option (iOS, Android, Windows), there’s Genius Scan from The Grizzly Labs. Works like the others – take a pic and the software makes whatever is in the pic look scanned. Genius Scan gives a ton of great options like fingerprint security, the ability to assign a password to a specific scan so that no one can snoop on you, and the ability to send scans to the cloud.
Creating Strong Passwords: 101
And throw in some punctuation
for good measure.
You are now a graduate!