Archive

Category Archives for "Networking"

Witcher dev, XBOX 360 ISO & PSP ISO forums hacked: Over 4.4 million accounts exposed

Well it’s bad news for some gamers and modders, about 4.5 million of them, as three different forums were hacked. If you are looking for the silver lining in the dark breach cloud, then none of the hacks were recent; the flipside? The email addresses, usernames and passwords have been “out there” since as far back as September 2015.The Witcher fans started receiving breach notifications from Have I Been Pwned, but the CD Projekt Red forum was compromised in March 2016. Have I Been Pwned Nearly 1.9 million CD Projekt Red accounts were exposed; Have I Been Pwned numbered the burned accounts at 1,871,373.To read this article in full or to leave a comment, please click here

Witcher dev, XBOX 360 ISO & PSP ISO forums hacked: Over 4.4 million accounts exposed

Well it’s bad news for some gamers and modders, about 4.5 million of them, as three different forums were hacked. If you are looking for the silver lining in the dark breach cloud, then none of the hacks were recent; the flipside? The email addresses, usernames and passwords have been “out there” since as far back as September 2015.The Witcher fans started receiving breach notifications from Have I Been Pwned, but the CD Projekt Red forum was compromised in March 2016. Have I Been Pwned Nearly 1.9 million CD Projekt Red accounts were exposed; Have I Been Pwned numbered the burned accounts at 1,871,373.To read this article in full or to leave a comment, please click here

IPv6 Q&A For The Home Network Nerd

I was a guest on the Daily Tech News Show, episode 2957A. We chatted about the news of the day, then had an IPv6 discussion aimed at folks who are curious, but haven’t had a chance to work with v6 yet. My goal was to dispel FUD and spread the gospel of IPv6 to the nerdy public.

For those of you that listened to the show, here’s the text I’d prepped. We didn’t get to all of this when recording, so you might find more information here to inspire your IPv6-related Google-fu.

What are the benefits to me as a general consumer of IPv6? (beyond having fifteen bajillion addresses)

In a certain sense, there is little tangible benefit for consumers. Addressing is largely transparent to general consumers. I think many consumers don’t know or care about the IPv4 address assigned to their gear. They care whether or not they can access the Internet resource they are trying to access.

For the more tech savvy, IPv6 does indeed bring fifteen bajillion addresses, so to speak. And while that doesn’t seem like a big deal, it is. For example, most of us at home have gear obscured by NAT. This makes us feel more secure Continue reading

TLS 1.3 explained by the Cloudflare Crypto Team at 33c3

Nick Sullivan and I gave a talk about TLS 1.3 at 33c3, the latest Chaos Communication Congress. The congress, attended by more that 13,000 hackers in Hamburg, has been one of the hallmark events of the security community for more than 30 years.

You can watch the recording below, or download it in multiple formats and languages on the CCC website.

The talk introduces TLS 1.3 and explains how it works in technical detail, why it is faster and more secure, and touches on its history and current status.

The slide deck is also online.

This was an expanded and updated version of the internal talk previously transcribed on this blog.

TLS 1.3 hits Chrome and Firefox Stable

In related news, TLS 1.3 is reaching a percentage of Chrome and Firefox users this week, so websites with the Cloudflare TLS 1.3 beta enabled will load faster and more securely for all those new users.

The last few days

You can enable the TLS 1.3 beta from the Crypto section of your control panel.

TLS 1.3 toggle

Nominations Open for the Next Class of Internet Hall of Fame Inductees

Do you know someone who has played a significant role in the development and advancement of the open, global Internet?  Organizations and individuals from around the world are invited to submit nominations to the Internet Hall of Fame.

2017 marks a significant milestone for the Internet Society as we celebrate 25 years of dedication to an open, secure Internet that benefits all people throughout the world.  The Internet has come a long way since its earliest days, and the Internet Hall of Fame honors a select group of visionaries and innovators who were instrumental in the Internet’s development and advancement along the way.

Ms. Kathryn Brown

Six runtime threat detection and response tips for container security

This vendor-written tech primer has been edited by Network World to eliminate product promotion, but readers should note it will likely favor the submitter’s approach. Security for containers has evolved quite substantially over the past year, but there is still a lot of education that needs to be done. The key point being that the biggest difference in this new paradigm is that everything is based on continuously delivered, micro-service based, applications. The fact that the technology enabler for that paradigm is containers is really less of an issue. When it comes to containerized applications, everyone seems to be in agreement - statically analyzing what an application can do inside a container and rejecting non-security compliant images and/or vulnerable images is a must. However, no matter how good a job you do with vulnerability scanning and container hardening, there are unknown bugs and vulnerabilities that may manifest in the runtime and cause intrusions or compromises. That is why it’s so important to outfit your system with real-time threat detection and incident response capabilities.To read this article in full or to leave a comment, please click here

Six runtime threat detection and response tips for container security

This vendor-written tech primer has been edited by Network World to eliminate product promotion, but readers should note it will likely favor the submitter’s approach.

Security for containers has evolved quite substantially over the past year, but there is still a lot of education that needs to be done. The key point being that the biggest difference in this new paradigm is that everything is based on continuously delivered, micro-service based, applications. The fact that the technology enabler for that paradigm is containers is really less of an issue.

When it comes to containerized applications, everyone seems to be in agreement - statically analyzing what an application can do inside a container and rejecting non-security compliant images and/or vulnerable images is a must. However, no matter how good a job you do with vulnerability scanning and container hardening, there are unknown bugs and vulnerabilities that may manifest in the runtime and cause intrusions or compromises. That is why it’s so important to outfit your system with real-time threat detection and incident response capabilities.

To read this article in full or to leave a comment, please click here

IDG Contributor Network: IoT is all business

IoT—Internet of Things: Talk about a broad term. It’s like air—it’s everywhere, and everyone knows it’s important, but there’s no consistent way to discuss it.Bill Cosby, back when he was associated with comedy, poked fun at the different perspectives of air. He said philosophy majors ponder why air exists, but physical education majors know that air exists to fill volleyballs, basketballs and footballs.Clearly, it’s a matter of perspective, so let me attempt to organize the IoT opportunity into three containers: consumer, government and enterprise.+ Also on Network World: IoT is the ‘new industrial revolution,’ says Vodafone + The consumer stuff is going to be big, but dull. Yes, there will be some big developments in products such as thermostats and toothbrushes. I may even buy a few. But that’s not what excites me about IoT. The consumer sector will be limited for two reasons.To read this article in full or to leave a comment, please click here

Review: Amped Wireless ALLY Plus

The latest “whole home coverage” system to cross paths with the Cool Tools testing team is from Amped Wireless. The ALLY Plus system includes a router and extender unit that looks a bit like a wireless mesh system (since both units have somewhat the same design), but in fact is more in line with a traditional router/extender offering. However, like those wireless mesh systems, the ALLY Plus is installed via mobile app that makes setup go quicker for those non-techie types. In addition, features such as in-depth parental controls and a security partnership with AVG means device protection for all clients connecting through the router.To read this article in full or to leave a comment, please click here

IDG Contributor Network: Avi Networks shows you don’t need special hardware to load balance

A trend that has grown over the past decade or so to become pretty much the default view of infrastructure is to “software-ize” functionality that was formerly the domain of specialist hardware.It all started (arguably) with the idea of virtualization. Instead of needing a physical server for every task, software would allow numerous virtual servers to run on a piece of physical kit. The upshot of virtualization of servers was that far greater efficiencies could be generated, and utilization rates went from being dismal to almost absolute. All good outcomes if you’re worried about the economics of technology.+ Also on Network World: Is infrastructure relevant in a software-defined world? + But it wasn’t just compute that got this dose of software goodness. Next came storage, then networking. And seemingly the sky is the limit as to what parts of infrastructure can be made virtual. (And in the next realm of innovation, we have serverless computing where, in effect, stuff happens without even having to think about servers—physical or virtual. But that’s another story.)To read this article in full or to leave a comment, please click here

Tap DANZing for Visible Cloud Networking

Networking is running blind. It is akin to driving a car in the fog at night without street lights, signs or a navigation system. Simply put, it’s a scary visibility problem, and it impacts the security and availability of the network. When coupled with massive shifts to virtualization, containerization, cloud-native applications and unstructured data, the insatiable telemetry demand is exponential. Every architect is looking for modern analytical methods of networking to gain visibility for millions of devices, data or events efficiently and consistently.

Connecting SMBs The Easy Way With Aerohive Connect

Aerohive

Wireless is hard. When you’re putting together large deployments of access points in challenging environments with tons of security on top of it all you realize the difficulty. That’s why most major wireless deployments require a lot of time, planning, and documentation to pull off correctly. But what if things are on the small side?

A Small World Without Wires

The average small business (SMB) is stuck in a wireless limbo. They have requirements that far exceed the performance profile of standard consumer wireless devices. Most SMBs have more than three or four devices connecting at a time. They have reliability issues that need to be dealt with. And they need it all in a package that doesn’t need constant minding to work appropriately.

When you look at the market for consumer wireless today, the real push is to get rid of any configuration at all. Even the old Apple Airport, which was simplistic in its day, is too “complicate” for modern users. Solutions like Google Wifi aim to be the kind of solution that just requires a cable plugged in. No additional configuration beyond that. Which works wonders if you’re a consumer at home that needs to enable some Continue reading

Apple missed deadline to pay €13 billion in Irish back taxes

Apple is behind with its taxes, but the tax inspector doesn't mind.Last August, the European Commission closed a three-year investigation of Apple's tax affairs with an order to the Irish government that it should recover about €13 billion (US$14.5 billion) in taxes that it believed Apple had underpaid over the last decade.Ireland has missed the deadline for recovering the billions, but Competition Commissioner Margrethe Vestager, who gave the Irish government four months to collect the taxes, is proving very understanding about the delay.To read this article in full or to leave a comment, please click here

Apple’s Q1: iPhone 7 slays in a record-setting $78.4 billion quarter

One year ago, in the first quarter of 2016, Apple reported a record-breaking profit: $18.4 billion on $75.9 billion in revenue. That was great news, but setting the bar so high was a mixed blessing—Apple’s huge uptick in growth ended there, with declining iPhone sales and profits in the three quarters since.But the company turned that around with the iPhone 7 and 7 Plus, Apple CEO Tim Cook said in Apple’s Q1 earnings report on Tuesday. The company broke its own record with $78.4 billion in revenue for the quarter ending December 31—and $54.3 billion of that came from iPhones, of which Apple sold 78.3 million. That’s another record, in case you were wondering.To read this article in full or to leave a comment, please click here

5 of the most anticipated tablets of 2017

Tablet might be struggling to find a place amongst hybrids, but there are still plenty of devices to get excited about in the coming year. These five tablets are slated to be some of the most exciting devices of 2017, and each offers a traditional tablet experience. iPad Air 3 Apple Apple typically announced iPads in the fall, but last spring it surprised everyone by announcing the 9.7-inch iPad Pro. But come fall, Apple was mum on a third generation iPad Air. That has some speculating that Apple will ditch the Air lineup, instead offering a third, entry-level iPad Pro. However, NeuroGadget reports it's likely Apple will release a 16GB iPad Air 3, with a thinner, water-resistant design, for $600. Either way, sources are confident that Apple plans to announce three tablets - a 9.7, 10.5 and 12.9-inch model - in Spring of this year. NeuroGadget also reports that, to compete with the Microsoft Surface, the iPad Air 3 is expected to ship with the Apple Pencil. Galaxy Tab S3 Samsung The Samsung Galaxy Tab S2 took a strong swing at the Apple iPad Air 2, offering a similar design and level of performance. It became Continue reading

Tested: The truth behind the MacBook Pro’s ‘terrible’ battery life

Read professional reviews of Apple’s new MacBook Pro lineup, and you’ll come away thinking the new laptops have great battery life.Dive into a customer forum, though, and the upshot will be exactly the opposite: The new MacBook Pros have “piss poor” battery life.That characterization came from user yillbs on MacRumors.com. “I don’t think anyone can convince me that this thing isn’t just flat out the worst battery life ever on a MacBook,” yillbs wrote, clearly frustrated. “I’ve been defending it like mad, but at this point... how can you? 4.42 hours is just bad.” To read this article in full or to leave a comment, please click here

Are Apple-specific threats on the rise?

Macs are really no more secure than a PC, but for many years there just weren’t as many out there because of the expense of the hardware and other issues. They've historically been a much less popular choice among both consumers, enterprises, and hackers alike.The PC attack surface is much wider; therefore, criminals develop malware that works on PCs because the payout is much higher. James Plouffe, lead solutions architect at mobile-security company MobileIron, said there are, however, a couple of oft-overlooked things that also protect Macs.First, Plouffe said, "MacOS is actually BSD Unix derivative. Granted, it's heavily customized but this meant that, unlike Windows (which had a long tail of viruses reaching back to the days of MS-DOS), bad actors had a lot more heavy lifting to do to be able to attack macOS."To read this article in full or to leave a comment, please click here

Are Apple-specific threats on the rise?

Macs are really no more secure than a PC, but for many years there just weren’t as many out there because of the expense of the hardware and other issues. They've historically been a much less popular choice among both consumers, enterprises, and hackers alike.The PC attack surface is much wider; therefore, criminals develop malware that works on PCs because the payout is much higher. James Plouffe, lead solutions architect at mobile-security company MobileIron, said there are, however, a couple of oft-overlooked things that also protect Macs.First, Plouffe said, "MacOS is actually BSD Unix derivative. Granted, it's heavily customized but this meant that, unlike Windows (which had a long tail of viruses reaching back to the days of MS-DOS), bad actors had a lot more heavy lifting to do to be able to attack macOS."To read this article in full or to leave a comment, please click here

What IT security pros are earning in 2017

Continued high demand following a record year of breachesImage by ThinkstockLast year was a record one for data breaches, with some 1,093 breaches reported. That represented a 40 percent increase over the prior year, according to the Identity Theft Resource Center. It is no wonder that information security remains one of the most top-of-mind issues for CIOs, CISOs, and CEOs. The result is continued high demand for IT security pros. “The market for IT security professionals is poised for another strong year,” notes CompTIA Senior Vice President Tim Herbert. “The security job category was one of the faster growing IT occupations during 2016. During the last 90 days, U.S. employers posted nearly 25,000 job openings for security positions.”To read this article in full or to leave a comment, please click here(Insider Story)