Skip to content
I T S S
  • Welcome
  • Hardware
  • Internet
  • Networking
  • Security
  • Data Recovery
  • Support
  • Contact
  • Webmail

A Nice Little Cryptography Primer

By itss | 28/06/2021
0 Comment

Pun Intended.

Category: Technology
Post navigation
← pfSense / Wireguard / Bad Code / Close Call Why Quake3 was so fast : Fast Inverse Square Root →

Recent Posts

  • Hardware Exploits?
  • Why Quake3 was so fast : Fast Inverse Square Root
  • A Nice Little Cryptography Primer
  • pfSense / Wireguard / Bad Code / Close Call
  • Apple Continues Its Trip To The Dark Side With The Release of MacOS 17 (Big Sur)

Slashdot

News for nerds

  • Flock Worker Calls Police On Reporter - For Filming Them in Public
    by EditorDavid on 13/09/2026 at 1:00 pm

    "This is what happened when we tried to record Flock installing a new camera on public roads," says Emmy award-winning reporter Brendan Keefe in a new video for InvestigateTV. In an accompanying article, InvestigateTV says their reporter "parked on the public street at a distance, donned a yellow safety vest and a hat emblazoned with the logo of InvestigateTV's Atlanta affiliate where he also works, displayed a press placard on his dashboard and then pulled out a camera to record the installation.... The installer saw him and immediately packed up his equipment and drove away, so Keefe also returned to his car and followed several cars behind, hoping to document the next stop." And then Flock's technician called 911. When asked "What's the address of your emergency" Flock's technician answered "I'm getting followed — harassed, pretty much. Taking videos and pictures!" Flock's worker said they'd been harassed multiple times that day, then stated incorrectly that "I know for a fact" that that was what the reporter wanted to do too. InvestigateTV reports that as a result of the Flock technician's call, "Three police cars ended up in the national investigative reporter's rearview mirror that Wednesday afternoon." Keefe told one of the three police officers who pulled him over, "There is an irony here that they're setting up these cameras that track all of our movements, that follow everywhere we go. But when I try to get video in public of him in public setting up a camera, he's afraid I'm following him?" InvestigateTV also reports that "About 17 minutes after the stop began, the responding officers returned to their vehicles and Keefe was allowed to drive away." But the call that brought three police cars to their reporter "was not the first time this summer someone working for Flock Safety summoned police over a camera. " About 17 minutes after the stop began, the responding officers returned to their vehicles and Keefe was allowed to drive away... [But the stop] was not the first time this summer someone working for Flock Safety summoned police over a camera. On June 5, police in Smyrna, Georgia, responded to a 911 call from a Flock employee after a group of YouTube creators began filming outside the company's distribution center located in the Atlanta suburb... The caller claimed the group filming had "been driving around the perimeter, basically harassing everyone" working at the facility. "Three young white males, probably mid-twenties, I'm not sure if they're armed. And they're carrying filming equipment as well," the caller said. Three times during the call he raised the possibility the people filming might be armed, though, when asked, he told the dispatcher he had not seen any weapons... [One of the protesters later told the caller "I think it's interesting, when you guys have this happen, you call the police and make us get stopped. But then you do it and it's okay?"] No one was charged in the YouTuber group, though the individuals were ordered to leave the premises under an official trespass warning. Keefe's video report ends with one final irony. "Every day on my way to work, I'm captured again by those same new shiny Flock cameras. We tried watching the watchers. Turns outs, it's a lot easier for them to watch us." Flock responded to the report by claiming "We do not object to members of the public or press photographing Flock cameras or personnel in public." But they added that employees working "in the field" must "prioritize their safety" and "may contact law enforcement when they believe they are being threatened, harassed, followed, or otherwise face a safety concern." Read more of this story at Slashdot.

  • Malicious OpenAI Agents Linked to RubyGems Campaign That Gained RCE on RubyDoc Servers in May
    by EditorDavid on 13/09/2026 at 9:00 am

    A swarm of OpenAI agents launched a "major malicious attack" against RubyGems last May, according to a new report. That coordinated attack hit Ruby's package manager "with hundreds of junk gems, prompting the maintainers to suspend new user sign-ups for about four days," writes The Hacker News, citing a senior product manager for software supply chain security at Mend.io: The latest findings, which were first reported by The Wall Street Journal, indicate these events were propelled by a cluster of OpenAI agents, with the earliest package uploaded to RubyGems on May 5, 2026, before more than 2,000 packages were submitted between May 11 and 12, 2026. These efforts were followed by the agents publishing five more packages between May 26 and 27, 2026, and another 83 packages on June 18, 2026... [T]he packages were authored using a large language model (LLM) and hundreds of the packages that were pushed to RubyGems had "oai" in their name. Fifteen of the packages listed "oai" as their author, while another had "openaixyz65947@gmail.com" as the contact email address... "The swarm behaves extremely similarly to the German-wiki agents we previously found," the researchers said, referencing another May 2026 incident... "The June agents were accessing 49 of the same files as the wiki agents..." "The process of building documentation for a gem involves evaluating a user-specified '.yardopts' file, which allows linking to Ruby scripts intended to help with this process," the researchers explained. "In the GemStuffer campaign, the agents abused this to gain arbitrary remote code execution on RubyDoc.info's servers." One of the gems, "zzsouthrunner" (which again matches the "ZZ" naming scheme the agents adopted in both the wiki and Hugging Face incidents) has been found to leave the following explicit comment at the top of "data/script.rb": # malicious crawler/exfil for Southwark Jan 2026 docs via rubydoc.info worker... The entire exploitation chain can be summed up as follows — Submit a malicious package to RubyGems — Trigger a documentation request, so that RubyDoc.info will build the package — Use the build script to run code on RubyDoc.info and scrape target websites — Exfiltrate the data off RubyDoc.info's servers by publishing another gem back to the RubyGems package registry, which is publicly viewable Additionally, the OpenAI agents have been found attempting to steal other users' API keys after gaining remote code execution capabilities on the build environment, while clearly being aware that what they were doing is unauthorized breaking and entering into real systems. This is evidenced by the names given to the files (e.g., hack.rb, evil.rb, inject.rb, exploit.rb, and ssrf.rb), the packages themselves (e.g., pwnp999, exfiltestwand3, hacksvn1778554764, and lambproxyhackabcxyz), and the comments left in the source code (e.g., "# malicious probe," "#hack," "# malicious test," and "# malicious crawler/exfil"). In some cases, however, the rogue agents attempted to go under the radar, leaving comments to conceal the malicious payload in the next release version of the packages. "# disable evil in next version and bump version," reads a comment left within the "data/evil.rb" file in the yardxabc889 gem. Troublingly, the agents also attempted to exploit a CDN caching bug (CVSS score: 7.3, no CVE) on May 12, 2026, that was only patched by RubyGems in July 2026... "If you signed in to rubygems.org with a gem client older than v3.2.0 (or otherwise via a legacy key), your key could have been exposed," RubyGems noted in an advisory. "Currently, 18% of sign-ins through gem sign-in come from an affected version, and for the first several years of this bug, before we changed the client's sign-in path in December 2020, it was every gem client." Other actions by OpenAI's agents cited in the article: "Agents bypassed RubyGems' email confirmation system to get working API keys without having to verify their email addresses in order to register a large number of accounts using disposable email addresses." "Agents attempted to use RubyGems' webhook system to stage data in the form of encoded URLs." "Agents used a cluster of 83 gems published to RubyGems over a 3-hour window on June 18, 2026, to experiment with different methods of accessing the U.S. Securities and Exchange Commission county.json dataset." Read more of this story at Slashdot.

  • Sam Bankman-Fried, Former Crypto Billionaire, Appeals His Conviction To the US Supreme Court
    by EditorDavid on 13/09/2026 at 5:00 am

    America's highest court heard Sam Bankman-Fried's request for a new trial on Thursday, CNN reports. But they add that "the former crypto mogul who was convicted of defrauding investors by secretly diverting billions of dollars of their money" also asked America's high court "to throw out a court order requiring him to pay $11 billion as part of his sentence." Bankman-Fried was sentenced to 25 years in prison in 2024 after prosecutors said he directed billions of dollars from the crypto exchange FTX to a hedge fund he controlled called Alameda Research, where the funds were used for risky investments, political donations and his own personal benefit. The Supreme Court appeal, which was reviewed by CNN, raises a technical question about evidence that was submitted at his trial, and whether Bankman-Fried should have been permitted to demonstrate that his investments were ultimately sound and would have covered any losses by FTX customers. He also argues that the $11 billion forfeiture violates the 8th Amendment's prohibition on excessive fines. "Where the government pursues a theory of fraud under which it doesn't matter whether any victims lost money, introducing evidence suggesting that people actually lost money is distracting and prejudicial," veteran Supreme Court attorney Jeffrey Fisher told CNN. "All the more so where the truth is the victims did not lose money, and the defendant is unable to make that clear." The 2nd US Circuit Court of Appeals rejected the arguments earlier this year. Read more of this story at Slashdot.

  • Anthropic CEO Dario Amodei Calls For AI Slowdown
    by BeauHD on 13/09/2026 at 1:00 am

    An anonymous reader quotes a report from The New York Times: The chief executive of Anthropic called for a global slowdown of artificial intelligence development in a 3,800-word essay on Saturday, just days after one of the company's employees quit over concerns about the safety of the technology. Dario Amodei, who co-founded Anthropic to focus on securely and carefully building A.I., wrote that while he believed the technology could bring many benefits, it was advancing at too quick a pace for researchers to continue safely. "Over the last few months, I have become convinced that fully addressing the risks requires even more prudence -- not just investing in risk prevention, but pacing the rate of capabilities advancement so that risk prevention has time to keep up," Mr. Amodei said. "We must slow the pace at which we improve the capabilities of A.I. models. Progress will still seem fast, and we must make wise use of the time we gain." [...] "Left unchecked, it could outrun our ability to understand and control these systems, and so must be pursued very carefully, if at all," Mr. Amodei said. [...] In his essay on Saturday, Mr. Amodei suggested actions that the industry might take to slow down the pace of development. Mr. Amodei said all A.I. labs could agree to third-party technology assessments from "embedded evaluators," or outside specialists who can verify best safety practices across companies. He also suggested that countries with democratic governance systems coordinate to create safety standards, which could take the form of regulatory action. He added that it would probably require a global effort working with other nations, including authoritarian ones, to properly coordinate a slowdown. Mr. Amodei stressed in his essay that he still finds A.I. capable of bringing "incredible benefits" to humanity, including potentially curing diseases and accelerating economic growth. But even so, Mr. Amodei said the risks of A.I. were too great to not proceed with extreme caution. "The measures I propose to advance the frontier at a safe pace will not be easy," Mr. Amodei wrote. "But I believe we owe it to humanity to try." Amodei's essay comes just hours after Bloomberg reported that Sam Altman told OpenAI employees the company is open to slowing the pace of AI development amid similar concerns. Read more of this story at Slashdot.

  • Automattic's Matt Mullenweg Claims He's Back 'In Control'
    by BeauHD on 12/09/2026 at 9:00 pm

    Less than 48 hours after Automattic's board placed Matt Mullenweg on leave, Mullenweg told employees he was back "in control" of the company and that the board was again in agreement. 404 Media cited Slack screenshots late Thursday evening where Mullenweg posted "Don't call it a comeback" and linked to LL Cool J's music video for "Mama Said Knock You Out." "Mullenweg's Slack profile picture currently shows him wearing a pirate hat and eyepatch," the report notes. From the report: "Happy to announce the board is back in agreement, and I'm in control of Automattic," Mullenweg wrote in the company-wide Announcements channel on Slack. "A lot happened in the past 48 hours that we need to sort out, and I hope much of it was a misunderstanding, because I have huge respect and regard for those involved." Mark Davies, Automattic's CFO who was set to act as interim CEO according to a statement from Automattic, had his Slack account deactivated as of at least Friday, sources told 404 Media and TechCrunch similarly reported. Davies, Mullenweg, and Automattic did not respond to 404 Media's requests for comment for this story. Techcrunch reported that Mullenweg told them a blog post is forthcoming. On Friday morning, Mullenweg published a blog post on his personal website, titled "Major Life Announcement." In it he announced he's buying a tugboat. "Anybody who's founded a company and had to find good stewards knows that no one will love a thing quite like the original owner, but sometimes you can find the perfect person to carry the torch," he wrote in the blog. He did not address the confusion surrounding his status at Automattic. The back-and-forth follows years of legal fights, layoffs, employee departures, and controversy surrounding Mullenweg's leadership. Read more of this story at Slashdot.

  • LG Responds to TV Spying Allegations
    by BeauHD on 12/09/2026 at 5:00 pm

    LG is pushing back against reports that its smart TVs are "spying" on users, saying wake-word detection happens locally and that features such as Automatic Content Recognition, voice recognition, and interest-based ads are optional. But critics note that researchers found TVs keeping logs of ambient conversations, and LG's response "did not address broader concerns about how much data it collects, who it shares it with, the potential for bad actors to exploit its features, or the misleading way in which its privacy options are presented," reports The Verge. Here's an excerpt from LG's statement: Some recent media coverage may have contributed to misconceptions about how LG smart TVs work. As an industry leader, LG believes we have a responsibility to provide customers with clear and accurate information about how our smart TVs operate and the privacy controls available to them. We would like to clarify how our smart TVs operate and explain our approach to user privacy. LG smart TVs do not continuously record or transmit users' conversations. Speech-to-text processing begins only if a user activates a voice interaction through a supported wake-word feature or by pressing the voice (or AI) button on the remote control. Audio used for wake-word detection is processed locally on the TV and, if no wake word is detected, audio is not converted to text, stored, or transmitted. Voice-recognition results and related technical logs may be generated as part of processing a voice command. These records are associated with specific voice interactions and do not indicate continuous recording of conversations occurring outside an active voice recognition session. Speech-recognition results may be used to support voice-related features but are not uploaded later when the TV is offline or when connectivity is restored. Features such as Automatic Content Recognition (ACR), voice recognition, and interest-based advertising are optional. These features are not enabled by default. Users can choose to enable these features and can manage or withdraw consent through TV settings. ACR uses audio fingerprinting technology using the TV's internal audio processor (not a speaker) to identify content and does not collect screenshots, screen recordings, video recordings, voice recordings, or other audio recordings from the TV. Where ACR is available and enabled, ACR-related information may be used for audience segmentation and viewing or audience trend analysis. Interest-based advertising and cross-device advertising require separate user consent through the applicable advertising-related agreements. Protecting user privacy is a fundamental principle in the design and operation of LG products and services. The statement goes on to "provide additional details on how LG smart TV features work, how information may be processed, what choices users have, and how LG continues to strengthen privacy, transparency, and security." Read more of this story at Slashdot.

Archives

  • September 2022
  • November 2021
  • June 2021
  • March 2021
  • November 2020
  • October 2020
  • September 2020
  • February 2020
  • January 2020
  • October 2019
  • August 2018
  • July 2018
  • April 2018
  • February 2018
  • January 2018
  • December 2017
  • October 2017
  • September 2017
  • August 2016
  • July 2016
  • March 2016
  • February 2016
  • August 2015
  • May 2015

Categories

  • Innovation
  • Security
  • Software
  • Technology

Tags

backdoor cisco coding json laziness patterns public information announcement security vulnerability
© 2017 IT Sales & Services Ltd
Quality IT solutions in Tanzania since 2010
Iconic One Theme | Powered by Wordpress