Skip to Content

Exclusive: Rock Band Unplugged Track List
AOL Tech

security posts

Axxis fingerprint door lock invites hacker wannabes to burgle your premises


Biometric security might sound cool, but relying on fingerprint recognition alone for securing anything more serious than your Windows password typically results in the rapid hacking, whether through flesh or software, of that protection. Well, Axxis is trying to address this problem with a new dual-factor security lock -- requiring a PIN alongside fingerprint identification -- which allows you to customize access times for each registered user and also spy on their comings and goings. Retailing for $699 per lock, alongside an entirely-not-optional $299 accessory, this is hardly a bargain bin item -- with a price like that, a burglar might be inclined to steal the locks instead of your treasured possessions.

Apple patching nasty iPhone SMS vulnerability


Given the hype surrounding Apple's iPhone, we're actually surprised that we haven't seen more holes to plug over the years. In fact, the last major iPhone exploit to take the world by storm happened right around this time two years ago, and now -- thanks to OS X security expert Charlie Miller -- we're seeing yet another come to light. Over at the SyScan conference in Singapore, Mr. Miller disclosed a hole that would let attackers "run software code on the phone that is sent by SMS over a mobile operator's network in order to monitor the location of the phone using GPS, turn on the phone's microphone to eavesdrop on conversations, or make the phone join a distributed denial of service attack or a botnet." Charlie's planning to detail the vulnerability in full at the upcoming Black Hat conference, but Apple's hoping to have it all patched up by the end of this month.

[Via HotHardware]

Clear shuffles through its last upstanding citizen, tells the rest to fall in line


Let's face it: no one digs long security lines at airports. But if you reckoned a healthy amount of folks would be willing to pay $128 per year in order to bypass said lines at only a few airports in the world, you'd be wrong. After launching with high hopes back in 2005, Clear has quietly folded after failing to "negotiate an agreement with its senior creditor to continue operations." There's no word on what'll happen to existing paying customers, but we get the feeling they'll be directed towards a somewhat unpleasant creek sans a paddle. Or, you know, that poorly staffed lane to the left with 384 (give or take) cantankerous, shoeless travelers.

[Image courtesy of Airliners]

White House, Pentagon announce plans for new cybersecurity positions


It's just been a few short months since a proposed bill called for the creation of a National Cybersecurity Advisor, but it looks like there's now not one but two new positions in the offing, with both the Pentagon and President Obama himself announcing plans for some newly elevated offices charged with keeping the nation's networks secure. While a specific "Cybersecurity Czar" hasn't yet been named, the White House position will apparently be a member of both the National Security Council and National Economic Council and, in addition to coordinating U.S. response in the event of a major attack, the office will also be tasked with protecting privacy and civil liberties. Details on the new Pentagon office, on the other hand, are expectedly even less specific although, according to The New York Times, it'll be a military command that will work to coordinate efforts now scattered across the four armed services, and will apparently serve as complement to the civilian office in the White House.

Read - Reuters, "Obama to name White House cybersecurity czar"
Read - The New York Times, "Pentagon Plans New Arm to Wage Cyberspace Wars"

[Thanks, Ryan]

Wearable ECG uses patient's posture for encryption, transmits data over Body Area Network


Though its fun to think of the Body Area Network as another way for cheap employers to get out of paying for properly wiring your workspace, the most obvious uses for this technology would seem to be in the realm of health care. To this end, the National Institute of Information and Communications Technology (NICT) in Japan has developed an ECG that can be worn 24 hours a day, wirelessly transmitting electrocardiographic data as well as measuring changes in body surface temperature and posture. The data can even be transmitted securely using cryptographic keys dynamically generated by the patient's posture and biological data (which are unique to each user). We'll let you guys ponder the cypherpunk ramifications of this technology in the comments -- and be sure to check out the additional pic we have for you after the break.

Study finds that Lockheed Martin needs to stop disposing of hard drives with top secret data intact


With all of those crazy defense contracts Lockheed Martin has goin' on, you'd think the company would have its act together as far as the need to hold down its data goes -- but according to The Daily Mail, this may not be the case. Researchers at BT's Security Research Center have found an overwhelming amount of sensitive data on hard drives purchased through computer fairs and auctions as a part of a recent study, including: bank account details, medical records, and confidential business and financial data. Although many organizations were found to be at fault, the most troubling (sensational) instance included test launch procedures for Lockheed Martin's THAAD (Terminal High Altitude Area Defense) missile defense system, found on hardware purchased from eBay. Also on the same disk were security policies, blueprints, and employees' personal info. When asked for a comment, a spokesman for the company stated that "Until Lockheed Martin can evaluate the hard drive in question, it is not possible to comment further on its potential contents or source." It looks like we're not getting to the bottom of this one any time soon, but in the meantime: if any defense contractors have any questions on the subject, we'll be happy to help.

[Via Slashdot]

Phoenix Freeze turns your Bluetooth phone into a proximity lock


It may not be the ideal solution for those in need of some military-grade security, but those simply looking to keep their co-workers from snooping on their laptop may want to consider Phoenix's new Freeze application, which promises to turn any old Bluetooth-enabled cellphone into a proximity lock. What's more, you can apparently even use one phone to control multiple laptops, and configure the application to switch the laptop into a power-saving mode when the phone moves outside the proximity zone (which can also be configured to suit your needs). Best of all, the application is available as a free download right now (Windows XP and Vista only, unfortunately), and Phoenix seems to have some even grander plans for the future, with it now apparently busily courting computer manufactures in the hope of getting it offered as a standard option on new laptops.

Quantum cryptography: now ready for space travel

It's been awhile since we've heard of any major advancements in the world of quantum cryptography, but at long last the silence is being broken by a squad of jubilant Austrian physicists. As the story goes, a team from Austria's Institute for Quantum Optics and Quantum Information (IQOQI) managed to send "entangled photons" 90 miles between the Spanish islands of Las Palmas and the Balearics. Calling the ephemeral test successful, the crew has boldly asserted that it's now feasible to send "this kind of unbreakable encrypted communication through space using satellites." Funny -- last we remember, quantum cryptography still had a few kinks to work through here beneath the stratosphere.

Air Force now using super-secure version of Windows XP


Windows 7 might be getting all the attention lately, but Windows XP is having a quiet little renaissance of its own -- not only have sales of the venerable OS been extended until 2010, Microsoft is selling an ultra-secure version to the Air Force. The custom build ships with over 600 settings bolted down, and a security patch turnaround of just 72 hours compared to the standard edition's 57 days -- all because Steve Ballmer personally stepped in and approved the project at the Air Force's request. The effort's to standardize and preconfigure the OS has paid off: 85 percent of previous known exploits have been blocked, support call volume has dropped 40 percent, and the USAF has saved some $100 million in costs. Nice -- but don't get your hopes up, since it doesn't seem like Microsoft has any intention of selling this version to the public.

[Via Slashdot]

Axxana Phoenix backup system promises to withstand earthquakes and other disasters


It's not exactly for everybody, but those looking to spare no expense when it comes to protecting their data may want to strongly consider adding Axxana's elaborate Phoenix backup system to their shopping list (just below the Bond villain hideout and above the robot army). At the heart of the system is the Phoenix Black Box pictured above, which houses an SSD array that stores your essential data, and packs both WiFi and 3G connectivity to let you retrieve it even if the box itself is inaccessible -- which it may well be, considering that it's designed to withstand earthquakes, floods, and other disasters (including shocks up to 40 Gs and temperatures up to 2,000 degrees Fahrenheit). Of course, the system also gets paired with a remote backup service for an added layer of protection, and you'll have access to a full range of management tools to keep an eye on your data at all times.

[Via OhGizmo]

Navy shells out for development of missile-killing free-electron laser


You may think that the Navy's just the baby brother to the two other US Armed Forces, but its weapon development record definitely shows otherwise. Just over two years after building an 8-Megajoule railgun, the branch has penned two $7 million checks to defense contractors Boeing and Raytheon for the design and development of a free-electron laser (FEL). For what it's worth, such a device has been yearned for since a day after the dawn of time, as unlike chemical-based lasers, the FEL would be 100 percent electric and easier to move. For those unaware,this stormy petrel of a weapon would be used to blast down missiles in mid-flight, all while putting on a pretty impressive light show. 'Course, the Navy must also figure out how to build a massive energy generating ship in order to use it, but let's not get too far ahead of ourselves here, okay?

[Image courtesy of AIP]

New Windows 7 hack purports to be "unfixable"


A hack that's "unfixable" is a pretty bold claim, but that's just what researchers Vipin Kumar and Nitin Kumar have announced at the now-happening Hack in the Box security conference, and they seem ready to back it up. Apparently, they've devised a means to gain control of a Windows 7 computer during the boot up process though the use of a tiny 3KB program dubbed VBootkit 2.0 (a follow-up to a similar Vista hack), which loads itself into the system memory and bypasses the hard drive altogether, making it extremely difficult to detect. Once loaded, an ill-intentioned individual could potentially change passwords, access protected files, or do just about anything else and then leave without a trace. The one fairly big drawback to the hack, however, and upside for most users, is that it can't be performed remotely, so it'll likely only be a significant concern for businesses or other folks using computers in public places -- unless, of course, Microsoft finds a way to fix the "unfixable."

[Via Electronista]

Fujitsu's secure USB tech keeps your data from wandering off (or just plain deletes it)


With corporate espionage on the rise, you just cannot be too careful, right? We've all heard the horror stories: Someone takes a spreadsheet home to do a little number crunching on his personal PC and, next thing you know, some ne'er-do-wells in Tehran have the specs for the President's personal helicopter. Well, the brain trust at Fujitsu Labs has put its collective heads together and come up with a pair of new technologies aimed at preventing sensitive information from getting into the wrong hands. First, the "secure USB memory device" is a thumb drive containing a processor and a battery. Data security policies can be set to delete data after a specific period of time or if the drive is accessed by an unauthorized computer -- handy if the thing gets lost or misplaced. Second, the company's "file redirect technology" restricts the data to the USB memory device itself, or to a specified server. The company is currently conducting internal trials of the technology, but we'll let you know as soon as we see one of these bad boys in the wild.

[Via Akihabara News]

Fujitsu's PalmSecure takes high-speed, contact free biometric readings


This next item should be music to the ears of security professionals, fans of biometric devices, and germophobes alike. Fujitsu has just announced a new palm vein authentication device -- one that's being touted as the world's fastest, and the first that works without the user actually touching the device. Unlike past implementations of this technology, which moved at a comparative snail's pace, PalmSecure works in as little as one millisecond. We can think of a number of places where this sort of thing could be particularly useful, from top secret lairs housing doomsday devices to anyplace where people might not be washing their hands as often as they should be (we really hate that). Despite its speed, Fujitsu insists that this bad boy performs with the same level of accuracy as its slow moving brethren. More pics after the break.

[Via Akihabara News]

Samsung comes clean with self-encrypting SSDs


It seems that Dell jumped the gun a wee bit by shedding some light on Samsung's forthcoming self-encrypting SSDs, but now Sammy is providing us with all the missing details... er, most of them, anyway. In conjunction with Wave Systems, Samsung is launching what it calls an industry first with its new line of solid state drives. Said devices are able to automatically encrypt information as it's saved to the drive, and they each come bundled with Wave's EMBASSY management software. At least initially, these super secure SSDs will ship in 64GB, 128GB and 256GB flavors, and while we're told that the whole lot is available now "through at least one major OEM," there's no specific mention of price. Shocker, we know. The full release is after the break.
Follow us on Twitter
Engadget Video


AOL News

Joystiq

Download Squad

TUAW

BloggingStocks

Asylum

Autoblog

Switched.com

FanHouse

Autoblog Green