Slashdot Mirror


User: Kodack

Kodack's activity in the archive.

Stories
0
Comments
157
First seen
Last seen
Profile
(view on slashdot.org)

Comments · 157

  1. Don't let wookies shoot at your droid! on Droid X Self-Destructs If You Try To Mod · · Score: 1

    If you find yourself facing down the droid, don't let your wookie use it for target practice and it will not self destruct!

  2. This is not a 'vulnerability' (10 yr GSM veteran) on AT&T Breach May Be Worse Than Initially Thought · · Score: 1

    I have worked on GSM networks for a living for over a decade and I am calling BS on this yellow editorial.

    What the author is suggesting is the wireless equivalent of hacking by Physical Level Access. No OS in the world can be 'secure' if you gain physical access to the machine it's running on. The idea that somebody can deduce your name and address, drive to your residence and get your mobile to attach to their pico cell for purposes of mining your data is ludicrous.

    1. IMSI is nothing special. It is nothing more than the entry the Home Location Register (HLR) uses to store information about your profile. Information like which Visitor Location Register (VLR) you are attached to, if you're roaming, what your phone number (MSISDN) is etc.

    It does NOT contain any information about you, your name, your home address, your billing etc.
    In order to view the IMSI profile in the HLR you would have to hack into ATT, Tmobile etc cellular network, know where to find the HLR's IP, how to log into it, and what commands to run to query the subscriber profile. Even if you did all that all you'd get out of it is a phone number......

    There are MULTIPLE levels of security to secure the cellular network from unauthorized users gaining access to the switching equipment.
    Firewall, VPN, Sitekey, multiple levels of logins and passwords requiring passing through multiple un NAT/PAT subnets.

    If you had that kind of access you could do far more than look up somebody's phone number.

    2. Even if someone had your IMSI, and knew where you lived, and set up a pico cell to try to trick your phone..... Your phone would not authenticate to the pico cell without a proper KI value. The KI is not something you can just look up and copy. Even having your IMSI, they can't get around the fact that GSM is encrypted and they don't have the key.

    They would also not be able to make your mobile hand over to their pico cell because there is no handover to that non existant BTS in the Base Station Controller or BSC. Phones don't just attach willy nilly to any old radio signal.

    3. If a person wanted to go through that much trouble to find out info about you they might as well break into your home and replace your Iphone with one that has spyware preinstalled, it would be FAR EASIER than trying to hack/spoof the network.

    And lastly your IMSI, MSISDN, SIM, KI, CCID, IMEI, any of that stuff does not link to your name, home address, or your account. That information is on the customers billing network, usually handled by a 3rd party vendor. Gaining any of that information would require hacking yet another set of computer systems.

    In summary.

    1. Your IMSI is not a secret someone can use to come after you.
    2. The HLR doesn't have any personal identifiable information about you.
    3. Someone can't sit out side your house and sniff all your secrets by tricking your phone.
    4. There are much easier ways to do these things if they really wanted your information. You are much more likely to be keylogged and exposed by using trojan software.

  3. Why would anybody want to buy a mobile carrier? on iPad Bait and Switch — No More Unlimited Data Plan · · Score: 1

    1. Phone carriers carry huge costs associated with their infrastructure.

    ATT is not just a handset, it is a network, a series of hundreds of switching centers, hundreds of thousands of radio sites, support infrastructure etc etc. One does not simply "buy them out".

    2. Say you had several billion dollars and convinced ATT to walk away from their cash cow, Do you then have any idea how much money it costs to operate that infrastructure?

    Mobile carriers have small margins. The only real profit they make is from value added services like data and various subscriber options. It's a thin margin business unless you do it in high enough volume and with an existing infrastructure.

    ATT doesn't want to spend money expanding their networks to support more data, it's not going to get them new customers or make the existing ones pay more. So they get to profit by squeezing as many mobiles on as they can and make the consumers use less bandwidth by charging them an arm and a leg for doing more than checking email.

    Think of it like this. If ATT were an airliner, it wouldn't save them money to fly faster jets. The best way they could make money would be to sit people 2 to a seat and make you contractually obligated to fly every month for 2 years with them.

    Apple is smarter than that. They are in a high margin business right now selling iphones that cost $100 to make for $300-$600. They don't even have to eat the MFG costs, they just outsource it to China. Apple is lean and mean, they design, others build, you buy, they laugh all the way to the bank. Why would they WANT ATT?

  4. Re:help on New Research Suggests G-Spot Doesn't Exist · · Score: 1

    You will not be able to reach it yourself, your wrist just doesn't bend far enough to give you the leverage you need. Your best bet is to get a product from an adult store that is custom made for the job. It will have the angle you need to reach it yourself. Good luck.

  5. There definately IS a female G-Spot on New Research Suggests G-Spot Doesn't Exist · · Score: 1

    When I read about a study like this it really makes me wonder about the people who formed these conclusions. There was a similar debate in the recent past about the female orgasm being fake as well.

    I'm going to be frank and if you are easily offended stop reading now.

    I'm not a doctor or a sex therapist but I have a girlfriend and together we both have first hand experience with the g-spot. I am not going to debate whether it is a separate nerve bundle or the physiology or lack there of. My argument in favor of it existing is one of experience. Without getting graphic, there are several ways for a woman to reach orgasm, and dependent upon how she is stimulated, it will result in different types of orgasm. Both in intensity, and physical and biological responses such as increased secretions and the color and texture of them.

    When the gspot is stimulated and induces an orgasm, the excretions that result are unlike those obtained from any other stimulation. The color is different, and it comes from a different place in the vagina. The smoking gun is that it can not be replicated by stimulating her in any other way than that spot.

    My opinion is that there is a nerve bundle that stimulates a woman similar to the prostate on a man, the result of which is a thick white fluid, almost like paste being excreted. Clitoral and vaginal orgasms do not result in this type of excretion.

    I'm not arguing the mechanics of the g-spot, only the results. If it were non-existant then the orgasm would be as well, since the orgasm is real the spot must be as well.

  6. If people have issues with the Gestapo why haven't on AU Senator Calls Scientology a "Criminal Organization" · · Score: 1

    You got to love their stance "If people had problems with the church why didn't they take it up with church officials? We have a dedicated department...."

    It's like an SS officer saying "If people have problems with the Gestapo why haven't they taken them up with us? We have a dedicated group of individuals that deal with people like them. And by deal I mean assassinate"

    Like anybody who's suffered torture is going to complain to their torturers.....

    disingenuous

  7. I sense butt hurt on Verizon Doubles Early Termination Fee and More · · Score: 0

    Get a cushion?

  8. 3G 64kbps channel? on How To DDoS a Federal Wiretap · · Score: 1

    That's an analog landline convention. They are talking about 3G which isn't getting to the world the same way a voice call would so there are no channels like there would be for say an analog call at 64kbps trunking and SS7 sent via a signaling link.

    I think if you sent so much information you saturated your available bandwidth that any messages not picked up by CALEA also would fail to be delivered. I don't know what 'device' they picked up to do this testing since CALEA is a standard not a box. But I'm guessing that they found a flaw with it, not with the CALEA standard.

  9. Re:Buffering... on How To DDoS a Federal Wiretap · · Score: 1

    PS, and I can tell you from experience it's not uncommon for the voice portion of a call to go to multiple recipients and for an intercept to send data to more than one agency. And at each step of the way it is stored if unable to be sent, and in the last leg before it gets to the agency it's actually archived.

    You would need somebody inside of the telco's network with very specific knowledge in order to interrupt an intercept. I think the paper exposes a flaw more with that device than with CALEA.

  10. Re:Buffering... on How To DDoS a Federal Wiretap · · Score: 1

    DMS is just an acronym for a message switch. Ericsson, Lucent, Alcatel, Nokia, Nortel, doesn't matter who makes it, the standards are the same.

  11. CALEA is bomb proof on How To DDoS a Federal Wiretap · · Score: 1

    Chillax broham.

    I believe they are talking about VOIP using the 3g side of their sprint phones. IE making a skype call over their wireless data. Assuming for a moment that Skype and other service providers don't have a CALEA setup (they are legally required to as they offer telecomm services and must comply with bench warrants), the fact is that any warrant on the targeted mobile would also capture all data. If one device were overloaded it would buffer until it was able to be sent.

    CALEA is bomb proof in the way that your billing is bombproof. Companies don't like to loose $$$ by loosing billing records. Well a billing record is just a glorified CDR (call data record) which is all that CALEA is sending data wise, it's sending in bandwidth data, and out of band signalling as call data records.

    Think about all the failsafes ma bell has to keep her billing streams intact and then double them for the government that wants to ensure law and order are kept.

    And CALEA is just a standard that all devices must comply to for delivering voice and data. So they can inter operate with others products. You must remember that there are dozens of ways to intercept a phone call legally, from your mobile to the base station, from the base station to the DMS, etc etc. If they want to wiretap you, it's going to happen, CALEA or not, it just makes it easier.

    The only way to avoid intercepts is to make a bug proof room, have a stranger buy prepaid phones with cash, and throw them away after every call. Criminals are stupid, thankfully.

  12. Re:Buffering... on How To DDoS a Federal Wiretap · · Score: 1

    Yes the data is buffered in several places but the voice is sent out to PSTN via a 3way calling feature of the DMS. Interrupting the voice portion of the call is possible just like war dialing to overload a phone number is possible. But that assumes they know the LEA's number to call, that they have enough skype bots to do it, and that the intercept target is only going to 1 phone number.

    A typical intercept involves several agencies and sometimes voice is sent to an agents cellphone as well. You can't be sure how many places the voice portion of the intercept is going but the SS7 telephony side of the house is much more hardened and difficult to gain access to than the IP side of it. Good luck getting your own STP to hide your criminal activity.

  13. I work on CALEA and DDOS is not possible on How To DDoS a Federal Wiretap · · Score: 5, Informative

    The fact that these researchers worked off of the standard for delivery compliance aka CALEA, has given them the false impression that all they need to do prevent a wiretap is to overload the connection between the agency and the DMS (the switch your call goes through).

    What the J standard does not go into is the fact that at every step of the way there are checks to determine if data can be sent. If it cannot then it is stored until it is able to be sent. It is not uncommon for connections in the IP realm to come up and down so the system can buffer them both at the DMS, as well as at several points inbetween through the various offboard devices in the chain. Typically the data makes 2 stops between the DMS and the LEA.

    This is strictly for the data portion of the call, IE dialed digits, in the wirless world it would include MMS/SMS, GPRS, etc.

    The voice portion of the call is trunked from the DMS to the PSTN via a 3 way calling feature with 1 way audio. It basically dials the LEA's recording equipment every time the target makes a call, their equipment will record automatically when it answers the phone, like an answering machine. However the voice portion doesn't always have to go to a LEA. It can be configured to go to several phone numbers such as an agents mobile phone, a recording device, or other 3rd party.

    Now you could overload the agencies recording equipment if you knew what number to dial using a war dialer type of attack, but that would lead authorities to your door and it would not prevent other agencies and other monitoring centers from receiving that same data. Most bench warrants will have several involved agencies each receiving intercepts from a single target.

    Suffice to say that if you have a tap on your phone, it's going to get to the LEA and there isn't much you can do about it.

  14. Why is Mars getting warmer too? on North Pole Ice On Track To Melt By September? · · Score: 1

    Ok, if everything going on right now is our fault, why are other planetary and satellite bodies in our solar system seeing unprecedented warming?

  15. A reactor cannot detonate. PERIOD on Higher Oil Prices Are Starting To Bring Jobs Home · · Score: 2

    I can't believe that the energy policy in this country is written by people who don't have the slightest FN clue how it all works. And it's a popular stance to take because of ignorant masses that similarly know next to nothing outside of TV movies and hearsay.

    Nuclear bomb
    1. Take a tiny amount of highly reactive fissile material.
    2. Define it's shape for maximum compression to within hundredths of a mm
    3. Find a way to precisely add just enough more material to go critical WHILE compressing the entire mass equally in a hundredth of a second.
    4. Boooom.

    Nuclear Reactor
    1. Take a large amount of low to mid fissile material
    2. Extend place it in a configuration to maximize surface area while preventing uncontrolled reactions. IE fail safe, reaction cannot occur without neutron moderators.
    3. Find a way to extract heat from the reaction in a closed loop system and use it to turn a turbine
    4. Almost limitless energy.

    To suggest that a reactor could some how trigger an atomic explosion is like saying that pouring jet fuel on a box of parts could some how spontaneously create a jet engine. The tolerances, timing, and materials that go into a bomb are so critical that if any one of them is off it will not detonate. It is realistically impossible for any given amount of material to cause a nuclear explosion.

    The biggest danger would be an un controllable reaction which would lead to a fire and the far more dangerous condition of releasing fuel into the atmosphere.

    You want to know why energy prices are soaring, pollution is up, and CO2 is fuggin with the climate? Because a few scares in Nuclear Power's infancy stopped the development and deployment of any new plants for the last 20 years. A few pounds of Uranium pellets puts out the equivalent of TONS of coal and hundreds of gallons of fuel's worth of energy. And we have abundant sources of fuel.

    You want to save the world? Tear up the nuclear weapons, build new reactors, ditch coal burning power plants, and build electric cars to use the abundant free energy in the power grid. Problem solved.

  16. Lets face it, you can't Torquemada anything on How To Frame a Printer For Copyright Infringement · · Score: 1

    Torquemada do not beg him for mercy!
    Torquemada do not ask him for forgiveness!
    Let's face it, you can't Torquemada anything!

  17. Re:logical progression on UK Proposes Banning Computer Generated Abuse · · Score: 0, Troll

    You are a retard. You are comparing a lifestyle that involves consenting adults to one that exploits children. That is a worse comparison than apples and oranges. That is more like comparing apples to atomic bombs. The people who do this to children are sick in the same way that people who go after animals are sick. It's a mental illness that should be treated. Even this isn't enough to hold anybody with that illness guiltless. You can't say "I'm sick in the head I couldn't help myself". It's not an insanity defense or get out of jail free card. It simply means that it is abnormal, unhealthy, and requires rehabilitation not just punishment. Homosexuality is completely different in that an adult can consent to enter into a relationship with another adult. The difference between rape and sex is whether there is consent. Children, animals, whatever, can't give consent therefor it is always considered a rape. Get a clue you ignoramus.

  18. Re:There is no firewall on Game Journalist May Have Been Fired Over Negative Review · · Score: 5, Insightful

    What can we do?

    Avoid Gamespot like the FN plague. Do what we all have the right to do, go somewhere else.

  19. So we should just give up? I don't think so.... on US Official Urges Americans To Reconsider Privacy · · Score: 1

    "Protecting anonymity isn't a fight that can be won" This is typical psychological manipulation. Present someone with limited options that support your own desirable outcome.

    Technically speaking "staying alive" isn't a fight that can be won either, we will all die some day. Does that mean we should seek death?

    The nature of our relations with each other and the way we gather and share information are changing rapidly and it is difficult for people to keep up. That does not mean that we should just give up and let someone tag you and track you your entire life. We will find a way to balance information and privacy with the need to have information on each other and on everything else.

    This is just your government wanting to step in and do what advertisers and spammers already do, track people and use that information for power and profit.

    We need a smaller government, MUCH smaller government, that serves when needed, and fades into the woodwork when it is not. The powers that be are fighting to justify themselves and trick people into thinking we need them. We do need leadership but we don't need big brother to run every aspect of our lives. I for one would rather be free and make my own decisions than have some authoritative and conniving master make them for me.

    Don't believe the hype, they are lying.

  20. So spoof IP of botnet IRC server and it suicides on Storm Worm Strikes Back at Security Pros · · Score: 1

    If it's DDOS whatever IP the detections come from, then anybody who can get to the control network need only spoof the IP of the control networks IRC server, or the IP of someone they want to see kicked off line and they get to launch their own DDOS guilt free because somebody elses bot net is doing it.

  21. The whole thing was a yellow journalism set up. on Getting Gouged by Geeks · · Score: 1

    Reloading windows is indeed a much over used and rather damaging hammer that people who don't know what they are doing employ before considering other options.

    I have never reloaded windows to fix a bluescreen or software error. I take a sadistic joy in tracking down exactly what within windows has broken, and forcing it to do my bidding.

    In any case that whole news story was bogus. The reporter exploited peoples distrust of computers and the notorious difficulty in troubleshooting some of their components, and turned it into a special report on geeks get rich quick schemes.

    Except for hard drive guy (who was a complete moron pulling a diag out of his ass), the others guessed motherboard, which given the symptoms was not that much of a stretch.

    Yeah they "just disabled the ram", but small cheap things can have drastic consequences and sometimes cost a lot of time and effort to find and fix. Ever got water build up in your gas tank? Had a bad wheel bearing that only caused problems at exactly 45mph?

    Something doesn't have to be catostrophic to be a pain in the but to troubleshoot.

    I mean using their logic they could have just marked the disk partition as inactive, or deleted the boot sector and gotten the same results.

    These reporters aren't trying to protect the public, they are trying to get viewers with wonderful gotchas like "What you don't know about peanuts COULD KILL YOU, story at 11" etc. They scare their viewers into watching.

    Now mis-diagnosment is a common problem in PC support and to be honest if you expect PC techs to be as highly trained as auto mechanics then you should expect them to charge more for their services as well. Do you really want to spend as much on your PC as you do on your car for yearly repairs?

    Most of those techs were not trying to make a buck or rip anybody off, they made their best guess and lacked some skills in troubleshooting, but that is a far cry from purposeful deceit. Not everybody knows that if the system has no beep codes you can guess

    no speaker
    bad cpu
    bad motherboard
    shorted ram

    and test by

    is speaker connected? - yes
    is CPU fully seated? - yes
    does pulling all ram out result in beep code? - Yes
    does putting ram back in remove beep code? - yes

    bad ram.

    The first thing a good troubleshooter does with a system is starts pulling everything off of it and then adds it back one by one until it breaks, whatever broke it can then be replaced.

  22. There are no "simple" ram failures on Getting Gouged by Geeks · · Score: 1

    Diagnosing bad ram is one of the most time consuming and troublesome things you can do as a pc tech. I'm not talking about dead sticks, I'm talking about intermittent failures which cause HD corruption, blue screens, sudden lock ups, reboots, and software errors.

  23. Newscientist is heavily biased yellow journalism on 26 Common Climate Myths Debunked · · Score: 1

    They publish their interpretations of other peoples science, and then have the nerve to dismiss arguments from scientists because they are "retired" or "not specializing in climatology". They don't even bother listing an author of the various articles.

    You should really take the time to drop what you are doing and read some of the climate articles they have put up. Look at how they consider evidence and facts when it supports their position, and then how they consider facts and evidence when it doesn't support their position.

    It's not balanced, it's not journalistic, it is heavily biased, yellow journalism. They pump the alarm bells, people read, they get more advertisers, they make more $$.

  24. Re:Well amount of Energy != Green on Hummer Greener Than Prius? · · Score: 1

    It doesn't really matter if the cyclist has cargo or not. All that matters is that under equal conditions, a person can go farther on a calorie load than an internal combustion engine.

    Even the most fuel efficient mopeds and motorcycles come nowhere near 200mpg much less 620, proving beyond a shadow of a doubt that human beings are more efficient than motors.

    Talking about weight is just splitting hairs. If the two numbers were remotely close you might have an argument but they are 10 fold or more in favor of the human cyclist.

  25. Re:Well amount of Energy != Green on Hummer Greener Than Prius? · · Score: 1

    Not only is your reply defensive, it is a mean spirited quip. I guess I hit a nerve.

    You name me one vehicle on earth that gets 620 miles to the gallon.

    Your defense that internal combustion engines are more efficient than people shows an ignorance that is staggering. I don't argue with fools so believe what you will.