DRAM bitflipping exploits that hijack computers just got easier

Approach relies on already installed code, including widely used glibc library.

(credit: An-d)

New research into the "Rowhammer" bug that resides in certain types of DDR memory chips raises a troubling new prospect: attacks that use Web applications or booby-trapped videos and documents to trigger so-called bitflipping exploits that allow hackers to take control of vulnerable computers.

The scenario is based on a finding that the Rowhammer vulnerability can be triggered by what's known as non-temporal code instructions. That opens vulnerable machines to several types of exploits that haven't been discussed in previous research papers. For instance, malicious Web applications could use non-temporal code to cause code to break out of browser security sandboxes and access sensitive parts of an operating system. Another example: attackers could take advantage of media players, file readers, file compression utilities, or other apps already installed on Rowhammer-susceptible machines and cause the apps to trigger the attacks.

As Ars has previously reported, Rowhammer exploits physical weaknesses in certain types of DDR memory chips to reverse the individual bits of data they store. By repeatedly accessing small regions of memory many times per second, code can change zeroes to ones and vice versa in adjacent regions. These changes occur even though the exploit code doesn't access, and doesn't have access rights to, the adjacent regions. The bug took on the name Rowhammer, because when the code figuratively clobbers one or more rows of memory cells, it causes bitflips in a neighboring cell.

Read 9 remaining paragraphs | Comments

Researchers may have observed sources of gravitational waves, cosmic neutrinos

Observatories may identify the sources of our new discoveries.

High energy neutrinos may be shot out of the barrel of a black hole. (credit: NASA)

Over the last few years, we've witnessed the start of two radically new ways of doing astronomy. For all of human history, everything we've learned about the cosmos has come from observing photons, from high-energy gamma rays down to the cosmic microwave background. But since the opening of the IceCube observatory at the South Pole, we've been able to track ultra-high-energy cosmic neutrinos. And earlier this year, the updated LIGO detector spotted gravitational waves, ushering in the ability to observe ripples in space itself.

While neutrinos and gravitational waves are a very different means of looking at the cosmos, the data that they generate has to be integrated with everything we've already learned about the Universe. In other words, when we spot the neutrinos or gravitational waves, it would be helpful to observe photons associated with whatever event is producing them. That will help us integrate the new information with things we already know about and come to grips with anything we don't know about.

This week, possible successes were announced, as people identified a likely source of cosmic neutrinos, as well as a possible detection of a gravitational-wave-generating event using more traditional astronomy.

Read 15 remaining paragraphs | Comments

Ubuntu 16.04 LTS launches April 21st

Ubuntu 16.04 LTS launches April 21st

Canonical releases a new version of its Ubuntu Linux operating system every six months, which means that sometimes it’s hard to spot the big new changes from one release to the next.

But this week the company is releasing Ubuntu 16.04 and it’s special for a few reasons. First, it’s a Long Term Support (or LTS) release, which means Canonical will continue to offer support and software updates for 5 years. And second, this is the first full version of Ubuntu to support snap packages as well as .deb packages.

Continue reading Ubuntu 16.04 LTS launches April 21st at Liliputing.

Ubuntu 16.04 LTS launches April 21st

Canonical releases a new version of its Ubuntu Linux operating system every six months, which means that sometimes it’s hard to spot the big new changes from one release to the next.

But this week the company is releasing Ubuntu 16.04 and it’s special for a few reasons. First, it’s a Long Term Support (or LTS) release, which means Canonical will continue to offer support and software updates for 5 years. And second, this is the first full version of Ubuntu to support snap packages as well as .deb packages.

Continue reading Ubuntu 16.04 LTS launches April 21st at Liliputing.

Bundesnetzagentur: Telekom wird Zugriff auf letzte Meile billiger machen

Konkurrenten, die das Netz der Deutschen Telekom anmieten, sollen weniger zahlen. “Statt selbst zu investieren, setzen die Wettbewerber lieber auf die Nutzung unseres Netzes und niedrige Vorleistungspreise”, meint dazu ein Telekom-Sprecher. (Telekom, G…

Konkurrenten, die das Netz der Deutschen Telekom anmieten, sollen weniger zahlen. "Statt selbst zu investieren, setzen die Wettbewerber lieber auf die Nutzung unseres Netzes und niedrige Vorleistungspreise", meint dazu ein Telekom-Sprecher. (Telekom, Glasfaser)

Onlineshopping: Oberklasse-Smartphone kann den Online-Einkauf teurer machen

Sind Besitzer eines Oberklasse-Smartphones besonders wohlhabend? Davon geht zumindest mancher Händler aus und lässt Kunden bei Bestellung über ein hochwertiges Smartphone unter Umständen mehr zahlen. Verbraucherschützer ermitteln zu versteckten Preisaufschlägen. (Onlineshop, Verbraucherschutz)

Sind Besitzer eines Oberklasse-Smartphones besonders wohlhabend? Davon geht zumindest mancher Händler aus und lässt Kunden bei Bestellung über ein hochwertiges Smartphone unter Umständen mehr zahlen. Verbraucherschützer ermitteln zu versteckten Preisaufschlägen. (Onlineshop, Verbraucherschutz)

“Dr. Death” pleads guilty to making, selling AR-15 rifle components

You can’t pay someone who’s unlicensed to mill a lower into a firearm.

This is a stripped (and fully-milled) AR-15 lower. (credit: Madison Scott-Clary)

A man in Sacramento, California has pleaded guilty to one count of unlawful manufacture of a firearm and one count of dealing firearms.

According to federal prosecutors, Daniel Crowninshield, known online as "Dr. Death," would sell AR-15 blanks, which customers would then pay for him to transform into fully-machined lower receivers using a computer-numerically-controlled (CNC) mill. (In October 2014, Cody Wilson, of Austin, Texas, who has pioneered 3D-printed guns, began selling a CNC mill called "Ghost Gunner," designed to work specifically on the AR-15 lower.)

"In order to create the pretext that the individual in such a scenario was building his or her own firearm, the skilled machinist would often have the individual press a button or put his or her hands on a piece of machinery so that the individual could claim that the individual, rather than the machinist, made the firearm," the government claimed in its April 14 plea agreement.

Read 11 remaining paragraphs | Comments

Optical Disc Archive G2: Sonys Disc-Stapel erreicht 3,3 TByte und braucht acht Laser

Sony hat sein Optical Disc Archive in der zweiten Generation vorgestellt. In einer ODA-Cartridge lassen sich nun 3,3 TByte an Daten speichern. Basis ist Sonys neue Archival Disc, die mit zahlreichen Lasern die Geschwindigkeit und die Leistungsaufnahme …

Sony hat sein Optical Disc Archive in der zweiten Generation vorgestellt. In einer ODA-Cartridge lassen sich nun 3,3 TByte an Daten speichern. Basis ist Sonys neue Archival Disc, die mit zahlreichen Lasern die Geschwindigkeit und die Leistungsaufnahme enorm steigert. (Backup, Sony)

Android-Wettbewerbsverfahren: Google soll marktbeherrschende Stellung missbrauchen

Das Android-Betriebssystem sei “Teil einer breiteren Strategie”, um Googles marktbeherrschende Stellung bei Suchdiensten auszubauen – so schreibt es die EU-Kommission in einem Statement an Google. Android sei zwar frei, aber … (Google, Android)

Das Android-Betriebssystem sei "Teil einer breiteren Strategie", um Googles marktbeherrschende Stellung bei Suchdiensten auszubauen - so schreibt es die EU-Kommission in einem Statement an Google. Android sei zwar frei, aber ... (Google, Android)

Razer Turret: Die Drahtlos-auf-dem-Sofa-Kombo

Klassische PC-Titel im Wohnzimmer zu spielen, ist selbst in Zeiten des Steam-Controllers schwierig. Razer sorgt mit dem Turret, einer Kombination aus Tastatur und Pad plus magnetischer Maus, für Abhilfe. Uns gefallen Ideen wie die ungewöhnlichen Gleitfüßchen. (Razer, Eingabegerät)

Klassische PC-Titel im Wohnzimmer zu spielen, ist selbst in Zeiten des Steam-Controllers schwierig. Razer sorgt mit dem Turret, einer Kombination aus Tastatur und Pad plus magnetischer Maus, für Abhilfe. Uns gefallen Ideen wie die ungewöhnlichen Gleitfüßchen. (Razer, Eingabegerät)

Industrie 4.0: Wenn die Fracht dem Frachter Vertrauliches erzählt

Kommunikation, auf die kein Geheimdienst und kein Konkurrent zugreifen kann: Wenn in der Industrie 4.0 Container ihre Zollpapiere selbst vorlegen oder einen Unfall an die Versicherung melden, darf niemand mithören. Ein Fraunhofer-Institut hat eine Lösung gefunden. (Industrie 4.0, Fraunhofer)

Kommunikation, auf die kein Geheimdienst und kein Konkurrent zugreifen kann: Wenn in der Industrie 4.0 Container ihre Zollpapiere selbst vorlegen oder einen Unfall an die Versicherung melden, darf niemand mithören. Ein Fraunhofer-Institut hat eine Lösung gefunden. (Industrie 4.0, Fraunhofer)