Your Clever Password Tricks Aren’t Protecting You from Today’s Hackers

Good password-choosing advice from Lifehacker. Bottom line: if you can remember your password it isn’t good enough.

Our passwords are much less secure than they were just a few years ago, thanks to faster hardware and new techniques used by password crackers. Ars Technica explains that inexpensive graphics processors enable password-cracking programs to try billions of password combinations in a second; what would have taken years to crack now may take only months or maybe days.

Making matters much worse is hackers know a lot more about our passwords than they used to. All the recent password leaks have helped hackers identify the patterns we use when creating passwords, so hackers can now use rules and algorithms to crack passwords more quickly than they could through simple common-word attacks.

via Your Clever Password Tricks Aren't Protecting You from Today's Hackers.

Heartbleed Bug

While many news outlets were blathering on about the end of life for Windows XP, a huge hole in OpenSSL was discovered. OpenSSL secures a huge percentage of the Internet, meaning many of the sites you use have had their security compromised.

These revelations, while painful, are very much necessary to create a more secure Internet.

The Heartbleed Bug is a serious vulnerability in the popular OpenSSL cryptographic software library. This weakness allows stealing the information protected, under normal conditions, by the SSL/TLS encryption used to secure the Internet. SSL/TLS provides communication security and privacy over the Internet for applications such as web, email, instant messaging IM and some virtual private networks VPNs.The Heartbleed bug allows anyone on the Internet to read the memory of the systems protected by the vulnerable versions of the OpenSSL software. This compromises the secret keys used to identify the service providers and to encrypt the traffic, the names and passwords of the users and the actual content. This allows attackers to eavesdrop on communications, steal data directly from the services and users and to impersonate services and users.

via Heartbleed Bug.

Bonus link: Bruce Schneier on the Heartbleed bug.

Sticky switcheroo: FDA cracks down on honey labeling – Health – Boston.com

The Food and Drug Administration is cracking down on the fake honey claims in some foods. Looks like I got my wish!

Have you been duped by a honey poser?

Companies have been selling sugary, sticky honey blends on grocery store shelves for years, adding syrups or sweeteners not made naturally by bees, but hiding their fraud on the packaging under the label “honey.” This food fraud also applies to foods that list “honey” as an ingredient. You might not be getting the real thing.

The Food and Drug Administration issued new guidelines Tuesday that will require companies to label any honey that is not pure, or even food containing this honey, with “blend of sugar and honey” or “blend of honey and corn syrup,” depending on the ingredients. This policy change is the result of organizations like the American Beekeeping Federation and other honey associations petitioning against the common food industry practice of misrepresenting “pure honey.”

via Sticky switcheroo: FDA cracks down on honey labeling – Health – Boston.com.

Saffron Technology moving headquarters to Silicon Valley after raising $7 million | Technology | NewsObserver.com

As if to prove my earlier point, the N&O reports local startup Saffron Technology is packing up for the West Coast – not for more favorable taxes but for the West Coast’s “wealth of talent.”

Wrong again, governor.

Saffron Technology, a homegrown big data analytics software company, plans to shift its headquarters from Cary to the Silicon Valley after raising $7 million in new funding.

Despite the move, CEO Gayle Sheppard said she expects the company’s 12-person Cary office to double in size by the end of the year. That would keep pace with the growth of the overall company, which she anticipates swelling from 20 to 40 employees in 2014 thanks to the new round of funding.

“We should not think of this as leaving Cary behind by any means,” Sheppard said. “I see that operation as an important part of our future. Terrific talent there.”

Nonetheless, Sheppard said that moving Saffron’s headquarters to Silicon Valley was designed to help it recruit the “wealth of talent” on the West Coast.

via Saffron Technology moving headquarters to Silicon Valley after raising $7 million | Technology | NewsObserver.com.

Physicists, Generals And CEOs Agree: Ditch The PowerPoint : All Tech Considered : NPR

NPR discusses organizations which have banned PowerPoint presentations. Here’s a pro tip: if your audience is tuning out your presentation, you’re doing it wrong. (Here’s how to do it right.)

About six months ago, a group of physicists in the U.S. working on the Large Hadron Collider addressed a problem they’ve been having for a while: Whenever they had meetings, everyone stuck to the prepared slides and couldn’t really answer questions that weren’t immediately relevant to what was on the screen.The point of the forum is to start discussions, so the physicists — from then on, they could only use a board and a marker.

"The use of the PowerPoint slides was acting as a straitjacket to discussion," says Andrew Askew, an assistant professor of physics at Florida State University and one of the organizers of the forum at the Fermi National Accelerator Laboratory in Illinois.He says it was as if "we removed the PowerPoint slide, and like a big glass barrier was removed between the speaker and the audience."

The communication became a lot more two-way instead of just the speaker speaking at length for 15, 20 minutes. The audience really started to come alive, to look up from their laptop computers and actually start participating in the discussion, which is what we were really trying to foster."

via Physicists, Generals And CEOs Agree: Ditch The PowerPoint : All Tech Considered : NPR.

Nothing spotted by planes searching remote patch of Indian Ocean for missing Malaysian jet | CTV News

The continuing search for signs of Malaysian flight MH370 remind us of two things: it’s a big ocean out there and there is plenty of debris in that ocean.

Search planes scoured a remote patch of the Indian Ocean but came back empty-handed Friday after a 10-hour mission looking for any sign of the missing Malaysia Airlines jet, another disappointing day in one of the world’s biggest aviation mysteries.

Australian officials pledged to continue the search for two large objects spotted by a satellite earlier this week, which had raised hopes that the two-week hunt for the Boeing 777 that disappeared March 8 with 239 people on board was nearing a breakthrough.

But Australia’s acting prime minister, Warren Truss, tamped down expectations.

“Something that was floating on the sea that long ago may no longer be floating — it may have slipped to the bottom,” he said. “It’s also certain that any debris or other material would have moved a significant distance over that time, potentially hundreds of kilometres.”

via Nothing spotted by planes searching remote patch of Indian Ocean for missing Malaysian jet | CTV News.

NSA targets system administrators

The Intercept describes the NSA’s efforts to undermine networks by targeting the system administrators who job it is to keep them secure. If this doesn’t make system administrators angry there’s something seriously wrong.

Across the world, people who work as system administrators keep computer networks in order – and this has turned them into unwitting targets of the National Security Agency for simply doing their jobs. According to a secret document provided by NSA whistleblower Edward Snowden, the agency tracks down the private email and Facebook accounts of system administrators or sys admins, as they are often called, before hacking their computers to gain access to the networks they control.

The document consists of several posts – one of them is titled “I hunt sys admins” – that were published in 2012 on an internal discussion board hosted on the agency’s classified servers. They were written by an NSA official involved in the agency’s effort to break into foreign network routers, the devices that connect computer networks and transport data across the Internet. By infiltrating the computers of system administrators who work for foreign phone and Internet companies, the NSA can gain access to the calls and emails that flow over their networks.

The classified posts reveal how the NSA official aspired to create a database that would function as an international hit list of sys admins to potentially target. Yet the document makes clear that the admins are not suspected of any criminal activity – they are targeted only because they control access to networks the agency wants to infiltrate. “Who better to target than the person that already has the ‘keys to the kingdom’?” one of the posts says.

via Inside the NSA’s Secret Efforts to Hunt and Hack System Administrators – The Intercept.

McCrory thinks taxes stifle startups

Gov. McCrory just came back from Silicon Valley with supposed tips about how to foster startups.

Says the Governor:

“Our tax code is not conducive to the first-round investors for venture capital, for high-risk, first-round investors,” he says. “If they make an investment, they often move (the startup) to a no-tax state, with the profits. That means we lose that money and we lose that sweat equity. We want that money to be reinvested in North Carolina.”

Oh really? Venture capitalists are seriously going to uproot the founders of their investments and risk losing them just so they can save a few bucks on their taxes? I have been deeply involved in startups for over 20 years and I have never heard of this happening to a North Carolina startup.
Continue reading

We Got A Badass Over Here: Doctor Neil deGrasse Tyson, Science and Social Responsibility | Geekquality.com

Here’s a great bio of Dr. Neil deGrasse Tyson. I’ve requested his memoir from the Wake County Public Library but this will hold me over until it arrives.

In the latter half of 1958, two events occurred that would have a profound effect on the science of astrophysics: one was the signing of the National Aeronautics and Space Act by President Dwight D. Eisenhower, which authorized the creation of NASA as a civilian space agency; the other, much more humble of the two, was the birth in the West Bronx of Neil deGrasse Tyson.

Oh, and we got tickets!

via We Got A Badass Over Here: Doctor Neil deGrasse Tyson, Science and Social Responsibility | Geekquality.com.

Open government study: Secrecy up – Associated Press – POLITICO.com

Now, let me get this straight. The federal government has warrantless access to every single piece of information on every single American – all in instantly-searchable databases, but when it’s time to provide legally-required documents under the Freedom of Information Act, the government can’t cough them up? What’s wrong with this picture?

Obama’s failure to keep his transparency promise has been a huge disappointment to me.

WASHINGTON — The Obama administration more often than ever censored government files or outright denied access to them last year under the U.S. Freedom of Information Act, according to a new analysis of federal data by The Associated Press.

The administration cited more legal exceptions it said justified withholding materials and refused a record number of times to turn over files quickly that might be especially newsworthy. Most agencies also took longer to answer records requests, the analysis found.

The government’s own figures from 99 federal agencies covering six years show that half way through its second term, the administration has made few meaningful improvements in the way it releases records despite its promises from Day 1 to become the most transparent administration in history.

In category after category — except for reducing numbers of old requests and a slight increase in how often it waived copying fees — the government’s efforts to be more open about its activities last year were their worst since President Barack Obama took office.

via Open government study: Secrecy up – Associated Press – POLITICO.com.