Security News

Boffins promise protection and perfect performance with new ZeRØ, No-FAT memory safety techniques
2021-06-23 13:27

Researchers at the Columbia University School of Engineering and Applied Science have showcased two new approaches to providing computers with memory protection without sacrificing performance - and they're being implemented in silicon by the US Air Force Research Lab. Take the Spectre and Meltdown families of vulnerabilities, for example: speculative execution frameworks added to improve performance have turned into a boon for ne'er-do-wells looking to access secrets hidden in supposedly protected memory regions.

Contract killer: Certified PDFs can be secretly tampered with during the signing process, boffins find
2021-05-26 06:46

A pair of techniques to surreptitiously alter the content of certified PDFs have been detailed by researchers in Germany. Using certified PDFs is increasingly common in business.

Google QUIC-ly left privacy behind in its quest for a speedier internet, boffins find
2021-01-30 00:10

A trio of researchers from China have found that QUIC is more vulnerable to web fingerprinting than HTTPS, a shortcoming that could make it easier for an adversary to infer which websites an individual is visiting by scrutinizing network traffic. Google developed QUIC to solve issues like these and the protocol is being worked on in parallel by the Internet Engineering Task Force as a standard.

How good are you at scoring security vulnerabilities, really? Boffins seek infosec pros to take rating skill survey
2021-01-08 09:30

By running a survey on whether infosec bods think the Common Vulnerability Scoring System is a useful tool for assessing security flaws, Dr Zinaida Benenson of Friedrich-Alexander Universität Erlangen-Nürnberg's IT Security Infrastructure Lab in Germany hopes to further the infosec world's understanding of how reliable the system really is. While the survey hopes to gain up to 300 respondents, Benenson was coy about precisely what she's hoping to prove or disprove, but she did drop The Register a hint about the current state of CVSS scoring.

Radio Frequency fingerprinting of aircraft ADS-B transmitters? Boffins reckon they've cracked it
2020-11-10 19:58

In a paper titled "Real-World ADS-B signal recognition based on Radio Frequency Fingerprinting," three Chinese researchers describe what they said was a method of identifying unique transmitters fitted to aircraft - regardless of what identity code the equipment is broadcasting. ADS-B transmitters work by broadcasting the aircraft's GPS location along with a unique identifier, issued by the registering country's authorities.

Surprise! Voting app maker roasted by computer boffins for poor security now begs US courts to limit flaw finding
2020-09-04 01:13

Voatz, the maker of a blockchain-based mobile election voting app pilloried for poor security earlier this year, has urged the US Supreme Court not to change the 1986 Computer Fraud and Abuse Act, a law that critics say inhibits security research because it's overly broad. The app maker filed an amicus brief [PDF] on Thursday in Van Buren v. United States in support of the US government, which seeks to uphold the 2017 conviction of former Georgia police officer Nathan Van Buren under the CFAA. Van Buren was convicted of violating the CFAA for conducting a computer search for a license plate number. Coincidentally, its app was slammed in February by computer scientists for a variety of security flaws.

Physical locks are less hackable than digital locks, right? Maybe not: Boffins break in with a microphone
2020-08-21 09:31

The paper presents "SpiKey, a novel attack that utilizes a smartphone microphone to capture the sound of key insertion/withdrawal to infer the shape of the key, i.e., cut depths that form the 'secret' of the key, solely by the captured acoustic signal." The researchers explained that there will be more than one "Candidate keys" rather than a single one that fits the pattern, but that in the case of the particular six-pin key analysed, "SpiKey guarantees reducing more than 94 per cent of keys to less than 10 candidate keys" with three candidates being "The most frequent case".

Foreshadow returns to the foreground: Secrets-spilling speculative-execution Intel flaw lives on, say boffins
2020-08-07 00:00

Some of the boffins who in 2018 disclosed the data-leaking speculative-execution flaws known as Spectre and Meltdown today contend that attempts to extinguish the Foreshadow variant have missed the mark. In a paper slated to be distributed through ArXiv today, Martin Schwarzl, Thomas Schuster, and Daniel Gruss with Graz University of Technology, and Michael Schwarz, with the Helmholtz Center for Information Security, reveal the computer science world has misunderstood the microarchitectural flaw that enables Foreshadow, which can be exploited by malware or a rogue user on a vulnerable system to extract data from supposedly protected areas of memory - such as Intel SGX enclaves, and operating-system kernel and hypervisor addresses.

Boffins find that over nine out of ten 'ethical' hackers are being a bit naughty when it comes to cloud services
2020-06-17 06:57

Infosec pros and hackers regularly abuse cloud service providers to conduct reconnaissance and attacks, despite efforts by cloud providers to limit such activity. Of the 75 security professionals and hackers they spoke with as a part of a larger examination of attacker psychology, more than 93 per cent admitted to abusing cloud services to create attack environments and launch attacks.

ESA missions back doing science after precautionary pandemic plug pull: We talk to space boffins about Mars Express emergency command line
2020-04-03 16:59

ESA's mission operations centre in Germany has got back to doing interplanetary science after a short stand-down due to COVID-19. At least as normal as operations get for Cluster, now over 20 years into a two-year mission, and the veteran Mars Express spacecraft.