Showing posts with label TECHWORM. Show all posts
Showing posts with label TECHWORM. Show all posts

Tuesday, August 16, 2016

Indian engineering student builds a real-life walking Iron Man suit for just $750

Real-life Iron Man suit built for just $750 by this Indian student

Ever fancied getting into the iron suit of Tony Stark from the Hollywood blockbluster movie ‘Iron Man’? Well, if you didn’t, this Indian student certainly did.
Vimal Govin Manikandan, an engineering student has gone ahead and built a real-life Iron Man suit using exoskeleton technology. While it doesn’t fly and can hardly walk, Manikandan and his team developed a novel way to control a walking robot suit.

Manikandan says the suit was inspired by action movies especially the Hollywood blockbuster Avatar that featured machines designed for use by the military.
The exoskeleton made by Manikandan weighs 220 pounds, and can roughly lift 330 pounds. However, it is unclear if that includes the exoskeleton and human inside.The exoskeleton cost Manikandan just $750 (approx £578) to make, which is quite impressive. However, on the downside, as the suit weighs 220 pounds, it makes it difficult to walk or run while someone’s wearing it. Also, since it is powered by batteries, the chance that it lasts long is unlikely.
It’s not the first exoskeleton that Manikandan has built. Previously, he had made a mechanically powered Iron Man suit (see video below). Manikandan wants the military to use his technology, he told Al Jazeera.
SOURCES: TECHWORM

Tuesday, August 9, 2016

IBM’s Watson Artificial Intelligence discovered a rare illness in a woman suffering from leukaemia

Japanese Doctors Use AI To Detect Rare Leukaemia

Artificial Intelligence (AI), which is looked upon as a threat to humans, as they are rumoured to take place of humans in factories, industries, etc. in the coming years turned saviour for a patient suffering from leukaemia. Yes, you heard it right!
A team of Japanese doctors turned to IBM’s AI system, Watson for help after the treatment for an 60-year-old woman suffering from leukaemia proved unsuccessful. The AI was successfully able to find out that she actually suffered from a different, rare form of leukaemia, as the disease had gone undetected using conventional methods by the doctors.
Arinobu Tojo, a member of the medical team, told Efe news on Friday that the University of Tokyo’s Institute of Medical Science has successfully used the new method of diagnosis, which includes a computer programme capable of studying a huge volume of medical data.
Watson, which has been jointly developed by the US’ IBM and other firms, looked at the woman’s genetic information and compared it to 20 million clinical oncology studies. It later determined that the patient had an exceedingly rare form of leukaemia and recommended a different treatment which was successful.
Originally, the woman had been diagnosed with, and treated for, acute myeloid leukaemia; however, she failed to respond to the traditional treatment methods, which confounded doctors.
The conventional method of diagnosis for different types of leukaemia is based on an evaluation by a team of medical specialists after studying the genetic information of patients as well as the clinical studies available; an enormous task owing to the huge amount of data to be gone through.
Satoru Miyano, a Professor at the University of Tokyo’s Institute of Medical Science, points out that this is proof enough of the ability that AI likely has in the coming years, “to change the world.”
This is the nation’s first case of an AI saving someone’s life, emphasizing that this is “the most practical application in the field of medical and health care for artificial intelligence,” added Seiji Yamada, of the National Institute of Informatics and chairman of the Japanese Society for Artificial Intelligence.
What was remarkable was that the AI was able to diagnose the condition in just 10 minutes. Whether we would be able to see AI as a regular feature in the hospital in the coming years only time will tell.
SOURCES: TECHWORM

Microsoft won’t fix Windows flaw that lets hackers steal your username and password

The flaw, which allows a malicious website to extract user passwords, is made worse if a user is logged in with a Microsoft account.

A previously disclosed flaw in Windows can allow an attacker to steal usernames and passwords of any signed-in user — simply by tricking a user into visiting a malicious website.
But now a new proof-of-exploit shows just how easy it is to steal someone’s credentials.
The flaw is widely known, and it’s said to be almost 20 years old. It was allegedly found in 1997 by Aaron Spangler and was most recently resurfaced by researchers in 2015 at Black Hat, an annual security and hacking conference in Las Vegas.
The flaw wasn’t considered a major issue until Windows 8 began allowing users to sign into their Microsoft accounts — which links their Xbox, Hotmail and Outlook, Office, and Skype accounts, among others.
Overnight, the attack got larger in scope, and now it allows an attacker to conduct a full takeover of a Microsoft account.
Source: Zdnet
SOURCES: TECHWORM

Saturday, August 6, 2016

The Jungle Book and other iconic 16-bit Disney games are now available on PCs

Nostalgia reloaded: 16-bit classic Disney games now available on PC and Mac


For all those Disney game lovers out there, it’s time to get nostalgic. Digital distribution site GOG.com in a surprise announcement yesterday disclosed that three classic, 16-bit retro Disney games from the ’90s are going to be available in their store. In other words, you can now play these games on your Windows PC and Mac.
The three Disney’s classic 16-bit platformers are Aladdin, The Lion King and The Jungle Book, which have been updated for modern computers and re-released exclusively on GOG.com.
“All three titles have been meticulously updated to be compatible with modern operating systems while preserving the original graphics, sound and gameplay,” GOG.com’s press release reads.
In order to bring popular Disney characters to life in the gaming world, all the three timeless classics were developed using Digicel technology. The technology, which was unmatched at that time and even today looks quite impressive produced vibrant colors and visuals.
GOG.com explains the games’ history as follows:
“Developed during the golden age of platformers, Disney Aladdin, Disney The Lion King, and Disney The Jungle Book established themselves as hallmarks of the genre, earning the praise of fans and critics alike for over two decades. That was due in no small part to their groundbreaking visuals. With the advent of Digicel technology, hand-drawn cels from Disney’s animation team brought the characters to life with a level of vibrancy that was unparalleled at the time, and remains impressive today. Just look at how adorable little Simba looks when he roars at his enemies!”
All three games are playable on Windows PC, Mac and Linux. The retailer for video games and films is selling the 16-bit Aladdin, The Lion King and The Jungle Book platformers for $9.99 each or as part of a bundle for $19.99 until August 8. However, GOG.com is offering a 10 percent discount, reducing the price to $8.99 for the launch.
GOG.com has also previously teamed up with Disney in 2014 to re-release the digital versions of two Star Wars classics from the early ’90s, Star Wars: X-Wing and Star Wars: TIE Fighter. Since then, the retailer has released more than two dozen Disney-owned titles, including The Secret of Monkey Island: Special Edition and LucasArts’ The Dig.
SOURCES: TECHWORM

Friday, August 5, 2016

Torrentz.eu follows KickassTorrents, shuts down

Torrentz.eu, the Mega Torrents Search Engine Shuts Down



2016 is a bad year for torrent websites and the torrents community as a whole. Just weeks after one of the most popular torrents website, KickassTorrents was shut down, another Torrents community icon, Torrentz.Eu has mysteriously shut shop.
It has been exactly sixteen days since US Department of Justice announced the arrest of Kickass Torrents’ admin in Poland and seizure of KickassTorrents domains like Kat.cr. Now, Torrentz.eu, the Internet’s biggest BitTorrent meta-search engine, has shut down, according to messages displayed its home page.
At the time of writing, the Torrentz.eu displays a message that reads “Torrentz was a free, fast and powerful meta-search engine combining results from dozens of search engines.”
Trying to run a search, or clicking any link on the site changes that message to “Torrentz will always love you. Farewell.”
Its not just the most popular Torrentz.eu domain, in fact, all Torrentz domains feature the same page. This includes the Torrentz backups .ME, .CH, and .IN. The site’s HTTPS version features the same messages.
Torrentz.eu was never a torrents website but a very popular mega torrent search engine. It was so popular that we had listed it in our most popular torrents websites for 2016 and before its abrupt shutdown, Torrentz.eu had #186 Alexa rank.
The site was launched in July 2003 by an individual named Flippy. The site’s purpose was to index torrents from several large portals and aggregate all the different trackers. This allowed users to download torrent files with multiple trackers in their source, speeding up downloads and preventing dead links in case servers went down.
SOURCES: TECHWORM

Facebook deploys a new anti-clickbait algorithm for News Feed

Facebook’s new anti-clickbait algorithm will further remove bogus headlines


In an effort to reduce the number of clickbait stories that show up in users’ feeds and to keep posts relevant, Facebook has once again gone ahead and tweaked its algorithm that controls its News Feed. In the past too, Facebook has made changes to the news algorithm many number of times.
User Experience Researcher, Kristin Hendrix and Research Scientist, Alex Peysakhovich at Facebook explain clickbait stories as those with headlines that deliberately leave out important information or else try to mislead readers and get them to click their story.
For instance, the new Facebook algorithm can identify headlines like “What she saw at this moment will SHOCK YOU!” or “You won’t believe what will happen next” or “He Put Garlic In His Shoes Before Going To Bed And What Happens Next Is Hard To Believe” or “The Dog Barked At The Deliveryman And His Reaction Was Priceless.” and it doesn’t assign only a binary like “Yes, clickbait” or “not clickbait”, but it gives each story a score. The algorithm mainly looks for phrases often used in clickbait headlines but not in genuine headlines, similar to email spam filters.
The system classifies posts that are clickbait and which Pages and web domains these posts come from. Links posted from or shared from Pages or domains that constantly post clickbait headlines will appear lower in News Feed. If a Page stops posting clickbait headlines, their posts will stop being affected by this change, which in turn would lead to improvement in News Feed over period of time. This new update will have a huge impact on your page, if you are a spammer.
The change supports Facebook’s recently announced “News Feed Values”, which concentrates on “Friends and Family Come First” that resulted in last month’s feed change to de-emphasize news publishers.
Facebook has published a guide for bloggers, news agencies, and anybody else on how to avoid clickbait titles. Facebook advises that publishers avoid omission of important information to fool users into clicking, like “You’ll Never Believe Who Tripped and Fell on the Red Carpet…” Instead, Facebook recommends calls to action and text prompts. It also suggests avoiding exaggeration like “This Pen Never Ever Runs Out of Ink! Get It While It Lasts!”
“Pages should avoid headlines that withhold information required to understand what the content of the article is and headlines that exaggerate the article to create misleading expectations,” Facebook explained in its page. “We don’t post clickbait and we always appreciate a new like on our page on Facebook. We rely on people like you.” Facebook added.
Click here to read more on Facebook’s clickbait.
SOURCES: TECHWORM

Mathematical formula that solves the mystery why and when headphones tangle

Know the mystery behind entangled headphones

Had a bad day at college or work? Want to just rush home and listen to some music to calm yourself? However, when you take out the headphones from your bag, you realize that they have somehow tangled themselves into a tight knot. You have not touched them all day or taken them out; so, how did they manage to entangle themselves?
Well, actually there is actually a mathematical formula that describes exactly how they tangle. In a paper titled “Spontaneous knotting of an agitated string” by Dorian M. Raymer and Douglas E. Smith of the University of California at San Diego Department of Physics has explained this phenomenon.
To find out why the headphones get tangled, the researchers used mathematical ‘knot theory’ to analyze the knots. They ran 3,415 trials of shaking a headphone in a box and found some interesting results. The results showed that two key factors that cause complex knots to “form within seconds”: “critical string length” and “agitation time”.
Here is what the curve looks like:

According to the paper, the chances of a string getting tangled depend on its length. If a string is shorter than 46 centimetres, then it will rarely get knotted. However, the probability of a string getting tangled increases with an increase in the length of the string. With a string up to a length of 2 meters has about a 50% chance of getting tangled; but, strings longer than 2 meters seem cramped in the box, so the probability of them getting tangled does not increase past 50% with additional length.
Raymer and Smith also noted that the Y shape of headphones increases the chance of knotting considerably, with only one end of the wire or cable having to cross another to start off the tumble-weed reaction of a spontaneous tangle.
The physicists also found that when the stray ends of the headphones are allowed to freely lay the tangling occurs. When a bag or container is shaken, these free ends tend to move around and intertwine with the loops around them, causing tangles.

Basically, a typical headphone has a length of about 120cm-160cm, so every time you put your earphones in your pocket, there is a 50% chance that you’ll be annoyed the next time you pull out your headphones for some music.
To sum it up, scientists are saying that there is nothing you can do to prevent your headphones from getting tangled up when you put them in your pocket or bag. So the fact is that whether you like it or no, you will have to face this tangling mess every time you remove your headphones.

Basically, a typical headphone has a length of about 120cm-160cm, so every time you put your earphones in your pocket, there is a 50% chance that you’ll be annoyed the next time you pull out your headphones for some music.
To sum it up, scientists are saying that there is nothing you can do to prevent your headphones from getting tangled up when you put them in your pocket or bag. So the fact is that whether you like it or no, you will have to face this tangling mess every time you remove your headphones.
Source: Business Insider, TECHWORM

Resarchers discover severe vulnerabilities in HTTP/2 protocol

HTTP/2 HAS FOUR HUGE SECURITY VULNERABILITIES


Researchers have discovered a number of security issues related to the newly approved HTTP/2 protocol which could place millions of websites at risk of attack. The highly critical vulnerabilities were reported by cybersecurity firm Imperva at Black Hat Conference being held in Las Vegas.
The report, HTTP/2: In-depth analysis of the top four flaws of the next generation web protocol (.PDF), details four main vulnerabilities and attack vectors related to HTTP/2, of which adoption is steadily increasing.
According to W3Techs, 8.7 percent of all websites — roughly 85 million — have adopted the new standard, which is meant to improve how browsers and servers communicate, speeding up the online experience.
The vulnerabilities discovered by Imperva researchers are as follows :
  • Slow Read — The attack calls on a malicious client to read responses very slowly and is identical to the well-known Slowloris DDoS attack experienced by major credit card processors in 2010. It is worth noting that despite Slow Read attacks being well-studied in the HTTP/1.x ecosystem, they are still effective – this time in the application layer of HTTP/2 implementations. The Imperva Defense Center identified variants of this vulnerability across most popular web servers, including Apache, IIS, Jetty, NGINX and nghttp2.
  • HPACK Bomb — This compression-layer attack resembles a zip bomb. The attacker crafts small and seemingly innocent messages that turn into gigabytes of data on the server. This consumes all the server memory resources and effectively makes it unavailable.
  • Dependency Cycle Attack — The attack takes advantage of the flow control mechanisms that HTTP/2 introduced for network optimization. The malicious client crafts requests that induce a dependency cycle, which forces the server into an infinite loop as it tries to process these dependencies.
  • Stream Multiplexing Abuse — The attacker uses flaws in the way servers implement the stream multiplexing functionality to crash the server. This ultimately results in a denial of service to legitimate users.
Amichai Shulman, co-founder and CTO of Imperva warns that: “As with all new technology, it is important for businesses to perform due diligence and implement safeguards to harden the extended attack surface and protect critical business and consumer data from ever-evolving cyber threats.”
SOURCES: TECHWORM

Do you know why is the keyboard not arranged in alphabetical order?

Check out why keyboard is not arranged in alphabetical order


We use keyboard every day, be it our desktop, or laptop, or tablet or smartphone. But have you ever wondered as to why the keyboard is not arranged in alphabetical order?
The reason goes back to the time of manual typewriters. These typewriters in earlier days did have the keys arranged in alphabetical order. However, it was later discovered that the people typed so fast that the mechanical character keys got jammed very easily with this arrangement.
To prevent this, the keys were randomly positioned so that the weaker fingers were needed more frequently. This meant that people typed at a speed which the machine could handle. As a result, the ‘QWERTY’ keyboard came into existence that we find and use today.
The QWERTY keyboard layout was devised and created in the 1860s by the creator of the first modern typewriter, Christopher Sholes, a newspaper editor who lived in Milwaukee. Originally, the characters on the typewriters he invented were arranged alphabetically, set on the end of a metal bar which struck the paper when its key was pressed. However, once an operator had learned to type at speed, the bars attached to letters that lay close together on the keyboard became entangled with one another, compelling the typist to manually unstick the typebars, and also regularly blotting the document. A business associate of Sholes, James Densmore, suggested splitting up keys for letters commonly used together to speed up typing by preventing common pairs of typebars from striking the platen at the same time and sticking together.
There are varied opinions on this rearrangement of letters in the keyboard. The logic of the QWERTY layout was based on letter usage in English rather than positioning of letter in the alphabet. However, some sources assert that the QWERTY layout was designed to slow down typing speed to further reduce jamming. Also, the QWERTY keyboards were made so one could type using keys from the top row of the keyboard. On the other hand, there are sources who assert the rearrangement worked by separating common sequences of letters in English. Apparently, the hammers that were likely to be used in quick succession were less likely to hinder with each other. This random arrangement eventually became standard in computers later followed by the devices made after that.
SOURCES: TECHWORM

Your device’s battery status can be used to track you online

Security experts say smartphones can track you using little-known battery life loophole to give away details of their owners’ online movements


A team from Princeton University found that websites could use battery information to monitor people as they surf the web. Your battery status may now provide a way for websites to track you online. Originally intended to allow websites to serve you a “low power” version when your battery is low, researchers now say it’s being used for more.
HTML5 added functionality that takes information of your battery life percentage and time to discharge, as well as how long it would take to charge your phone, usable by website developers. Security researchers warned last year that it could also be used to write code to track your online activity, and now a Princeton University research team was able to confirm that this is actually happening.
Steve Engelhard and Arvind Narayanan – academics from Stanford University, found two instances where code used the combination of the above information to track users across the site where it was found. Now we should mention that HTML5 is not sending a unique identifier with the information it’s sending about your battery, however the unique combinations of the numbers would give websites a way to match your battery information with your IP with fairly good certainty.
The worst part of this attack is that it’s hard to mitigate against it. You can’t deal with it as easily as you would wipe your browser cookies. VPNs and AdBlockers won’t help either. The only option is to plug the device into the mains.
While there isn’t an easy way to disable the Battery Status feature right now (unless you use FireFox), there are rumors that browser vendors are looking to introduce features that will allow them to disable this, as they have with HTML5’s notifications and location features.
SOURCES: TECHWORM

Wednesday, August 3, 2016

What would happen if there was no Google?

Ever imagined what’d happen if Google was not there?



In just a short time, Google has become a seamless part of our lives, ranking somewhere between Jesus and bacon in importance. The brand has joined the ranks of Kleenex and Xerox (and if you’re in the South, Coke), with its name becoming synonymous with its product and somewhat generic as we “Google” this or that. Most of the world can’t use a smartphone without using a Google product. Some people can’t even travel across their own city without using Maps. It’s hard to fathom a life without it. Google Reader users, however, got a small taste of life would be like without the Big G in our lives.
It is very difficult to say exactly how the entire world would be able to work without Google – which is the most frequently visited website in the world. Google is a huge company which employs more than 30,000 people. There are a wide range of applications offered by Google and many of them are completely free. Users have the flexibility of using e-mail or Gmail and Google Docs for the purpose of sharing different types of documents. Google offers maps for the purpose of navigation, Calendar for organizing different activities during the week. Apart from this, Google offers Analytics for the purpose of tracking statistics about a website and Blogger for setting up an attractive blog for professional as well as personal purposes. Lineup of services offered by Google also includes Google PatentsScholarFinanceGroupsand Google+ for social networking. You also get the Image search option which enables you to get hold of the best images that you would like to use. Not to mention, Google search engine which has completely revolutionized the whole procedure of getting useful information on the internet. There are a lot of things offered by Google for accomplishing a number of tasks without putting in much effort and also without spending much money.
The use of library card catalogs would increase because people would actually visit libraries for getting required information on different topics. Carrying out a research on a particular topic would take a long time because researchers would not get the flexibility of carrying out their researches from home. This actually means that you would have to make good efforts in trying to find an answer for even some of your minutest queries. You can use other search engines but you would not get the results as fast and as accurate as Google. It would be a financial implosion for people who work for Google and the companies who carry out their advertising campaigns of Google. Almost all the websites or online stores promoting and selling their products and services online would lose web presence.
Having lost the power to find everything on search engine, people would need to talk to each other more. Forums will start to be bombarded with small queries. People would often meet up in big groups to discuss things as there was no Google to tell them stuff. Instead of Googling everything whenever they wanted, people would try and remember more stuff. As is the case with phone book in mobiles, we no longer remember phone numbers of our family or friends. Same is with Google. We don’t even make an effort to remember stuff because we know we can Google it any time we want.
But we are glad that Larry Page invented Google.
Can you think of other fun things that might happen if there was no Google? Tell us in the comments below.
SOURCES: TECHWORM

Hackers could have drained your Venmo account in minutes, thanks to Siri

Venmo’s flaw could have allowed anyone to use Siri on a locked iPhone to empty your account [Video]


Martin Vigo, a product security engineer for SalesForce recently discovered that by just using Siri, anyone could empty a Venmo account on a locked iPhone in less than two minutes, stealing as much as the weekly limit of $2999.99.
Venmo is a PayPal-owned money payment service app that allows users to transfer money between one another using a mobile phone or web interface. The users can link their bank accounts, debit cards, or credit cards to their Venmo account and use it to pay bills, friends with just a few taps. Besides sending money, you can also request people to pay you.
One of the app’s features is that it allows one user to “charge” other users for something, which results in an SMS notification being sent to the person who was charged. When that happens, the recipient can reply to the SMS with a six-digit code that was sent in the original message, which completes the payment.
Vigo contacted and notified the payment service, who patched the design flaws in the Venmo app and iOS that allowed stealing money from other people’s Venmo accounts. They responded within 18 days of being notified by killing the SMS “reply-to-pay” functionality in order to prevent such attacks.

How did this vulnerability occur?

The vulnerabilities have to do with the way iOS allows you to perform a limited range of actions, like sending text messages and initiating phone calls, without actually having to unlock the phone with a PIN number or fingerprint. In combination with Siri commands and other methods, the flaws allow an attacker to compel a victim to make a payment through the Venmo app.

So, how does it work?

The SMS notification is not enabled by default in Venmo. To enable the Venmo SMS service, an attacker needs to tell Siri to send a text message to 86753 saying “START”. 86753 is a short code number owned by Venmo and used for all the SMS notifications. Then, the attacker has to put a request for payment to the compromised device. The maximum amount that can be requested is $299.99, with a weekly limit of $2,999.99.
The victim will be then asked by Venmo to confirm the request. It will do that by sending an SMS with a one-time payment validation code. In order for the payment to go through, the recipient has to text this back to Venmo. However, the attacker can do that by telling Siri to read the last SMS message received, making a note of the number, and then tell Siri to send a text back to the Venmo shortcode with it. And, voila it’s done. Oops, you have just been looted!!!

Below is a demo video of Vigo’s attack.


SOURCES: TECHWORM

Do You Know Why There Is a Cylinder At The End Of Your Charger?

What Is This Cylinder On Your Charger For?



While my laptop charger has never bugged me, but I always felt strange at times to see a bump in my laptop charger right after it connects to the laptop. I always use to wonder why the charger has a bump and what purpose does it serve?

You normally see these “bumps” on the mouse, keyboard and monitor cables in a typical computer system found in a home or office. You can also find them on power supply wires when a device (like a printer or scanner) uses an external transformer.

It turns out that these bumps are called ferrite bead. It may also be called blocks, core, rings, EMI (electromagnetic interference) filters, or chokes. A ferrite bead has the property of eliminating broadcast signals and prevents energy loss of the same type within the charger. This makes the charger much more effective and helps charge your computer more quickly. Their purpose is to reduce EMI and RFI (radio-frequency interference). These cylinders are responsible for stopping very large deviation of power over supply through the cable and power surges in currents that pass through the cable and prevent ‘choke’ within the wire to make it any further supply the current to the device. The blocking is most effective when it is near the source of the EMI, that’s why you will only find these ferrite beads near the end of the cables.

It also acts as a choke or inductor that blocks high frequency noise in electronic circuits. Ferrite bead employs the dissipation of high frequency currents in a ferrite ceramic to build high frequency noise suppression devices.
The bead is made up of ceramic compounds, derived from iron oxide and/or oxides of other transition metals. It helps to prevent the wire behave on over floating current like aerials. It slips over the cable when the cable is made, or it can be snapped around the cable in two pieces after the cable is made. The bead is encased in plastic — if you cut the plastic, all that you would find inside is a black metal cylinder. This metal wire can possibly serve as an antenna by absorbing or releasing any radiation while passing current around it.
The radiation released by the wires without the bead could cause interference with other electronic objects around them, which act as receivers of this radiation, for instance, causing noise in speakers. This phenomenon’s example can be seen when cell phones interfere with the signal devices such as radios and speakers, producing a recurring noise well known for electronic users.
Source: The Amazing Fact, Techworm

Sunday, July 31, 2016

Have you ever wondered why ATM PINs have 4 digit Code? Here is why!

The really interesting reason why ATM PINs have a 4 digit code


You walk into your friendly neighborhood ATM kiosk and swipe your card. You then punch in a 4 PIN code to authenticate yourself and proceed to withdraw money. You may have been doing this mechanically since the day ATM was introduced but have you given a thought why ATM PINs have a 4 digit code?  No! Then read on..

Automated Teller Machines (ATM) were first introduced in 1967 and now have emerged as a best option to disburse cash. Instead of visiting your bank and waiting in a long queue to withdraw money, you just have to swipe your ATM card, punch in your secret 4 digit PIN and take away the money you require.

But if someone was to find or steal your card, the only barrier protecting your money is your 4-digit ATM PIN. Ever wondered why most PINs have only 4 digits? Given that an ATM dishes out money wouldnt the manufacturers of ATMS have been wiser to introduce a longish PIN say six digit or eight digit one. Isn’t that why our email passwords are also expected to be 6 letters or more?

You see there is a bit of story behind it. ATM was invented by a wellknown Scottish inventor John Adrian Shepherd-Barron, the man who pioneered the development of the ATM machine. Barron was born in Shillong and was son to a Wimbledon ladies doubles champion, Dorothy Barron. When testing out his invention, Barron had also proposed a 6-digit PIN.

However, the first person to use his invention was his wife, Caroline. We all know that behind every successful man is a woman, and Caroline apparently rejected the idea of using a six code PIN for her husband’s invention because she could only remember the numbers up to four.

When Barron came up with the idea when he realised that he could remember his six-figure army number. But he decided to check that with his wife, Caroline.

“Over the kitchen table, she said she could only remember four figures, so because of her, four figures became the world standard,” he laughs.
Reportedly, 6 numbers stringed together were too much information for her to recall.

Although, there are many banks nowadays that offer 6 digit PINs for security purposes, shouldn’t those of us using 4 digit PINs be thanking Caroline? It gets tough to recall those 4 digits at times, imagine what 6 or more would do to us?

SOURCE: TECHWORM

Thursday, July 28, 2016

Hackers can crash your Chrome and Firefox browser remotely using search suggestions

Researchers discover a way to crash Chrome and Firefox browsers on Linux PCs and Android smartphones


Imagine you are searching for a keyword on Google search using Chrome browser on your Android smartphone. The Chrome browser will immediately return the most plausible suggestions matching your search. Click on one of these search suggestions and suddenly you will find your Chrome browser has crashed.
This is due to a bug found out by security researchers from Nightwatch CybersecurityThe researchers discovered that they can manipulate the search suggestions in a way to send big files to the browser and crash it. Their method relies on using the search suggestions feature that these browsers support. The researchers noted that the issue is not a software bug, but a design implementation that allows their attack to be executed.
Almost all of the current browsers have a search field or allow users to search via the URL address bar. Based on the search engines supported inside the browser, search suggestions can be shown as the user types their query. Nightwatch security researchers say that if the browser’s search engine provider doesn’t protect these search suggestions via an encrypted HTTPS channel, an attacker on the local network can intercept search suggestions queries and answer before the search provider.

PoC

Because browsers include multiple non-HTTPS search engines with insecure search suggestions endpoints, it would be possible for an attacker on the network level to intercept the traffic flowing between the browser and the search engine endpoints, and substitute their own. If a very large response is returned (2+ GBs), the browser can run out of memory and crash. This is due to the fact that browsers do not check for sizes in the search suggestions responses. Obviously, this is more of an issue for mobile devices which have lower memory than desktops.
For Android AOSP browser and Chromium, this issue appears to be directly tied to the processing code of search engine responses. For FireFox, this is a more generic issue around large XMLHTTPRequest responses, which is what the browser is using internally for search suggestions. Our bug reports with the vendors provide more details on which code is causing this. This re-enforces the fact network traffic SHOULD NEVER be trusted.

No malware

The researchers stated that though they could crash the browsers using the above method, they were unable to execute any malicious payload using this method. This means that the bug is more of a nuisance value than a threat.

Test results

The researchers tested their PoC on various devices using Chrome and Firefox and the results are give below :
  • Android AOSP stock browser on Android (v4.4) – application crashes
  • Chrome v51 on Android (v6.01) – application crashes
  • Chrome v51 on desktop Linux (Ubuntu v16.04) – the entire computer freezes requires a reboot (this maybe to due to swapping being disabled with an SSD drive)
  • FireFox v47 on desktop Linux (Ubuntu v16.04) and Android (v6.01) – application crashes
The researchers found that their exploit doesn’t affect Apple’s Safari v9.1 browser or Microsoft’s Edge and Internet Explorer 11.
The bug can be exploited in the wild providing a potential hacker has the following at his/her service
  • The attacker must have control over DNS and the network traffic of the victim machine. This is most likely in cases of a rogue WiFi hotspot or a hacked router.
  • Most browsers have rather short timeout for search engine suggestions response, not allowing sufficient time for the large response packet to be transferred over network
  • Due to the very large response size needed to trigger this issue, it is only exploitable over broadband or local networks such as rogue WiFi hotspot
The researchers informed the respective browser developers about the flaw. However, the Android, Chrome, and Firefox security teams declined to classify this bug as a security issue.
SOURCE : TECHWORM