Skip to content
I T S S
  • Welcome
  • Hardware
  • Internet
  • Networking
  • Security
  • Data Recovery
  • Support
  • Contact
  • Webmail

A Nice Little Cryptography Primer

By itss | 28/06/2021
0 Comment

Pun Intended.

Category: Technology
Post navigation
← pfSense / Wireguard / Bad Code / Close Call Why Quake3 was so fast : Fast Inverse Square Root →

Recent Posts

  • Hardware Exploits?
  • Why Quake3 was so fast : Fast Inverse Square Root
  • A Nice Little Cryptography Primer
  • pfSense / Wireguard / Bad Code / Close Call
  • Apple Continues Its Trip To The Dark Side With The Release of MacOS 17 (Big Sur)

Slashdot

News for nerds

  • Motorola's 2027 Flagships Will Officially Support GrapheneOS
    by BeauHD on 25/08/2026 at 3:00 pm

    Motorola is working with GrapheneOS to officially support the privacy-focused Android alternative on its 2027 flagship phones, starting with a non-folding model and later expanding to the next Razr Fold and Razr Ultra. "These will ship with Motorola's normal Android skin, but you will be able to switch to GrapheneOS later if you want to," notes GSMArena.com. GrapheneOS says the devices will "meet or exceed" its hardware and update requirements, and will include seven years of "proper updates." Interestingly, Motorola will be doing much of the porting work itself. Read more of this story at Slashdot.

  • Windows Backdoor 'Sleepwalker' Hides in Memory Until Activated by a 'Magic Packet'
    by BeauHD on 25/08/2026 at 11:00 am

    "The Register has a story about a Windows backdoor that waits silently in memory for a 'magic packet' before springing into action," writes Slashdot reader fred133. "No outgoing traffic, just waiting..." From the report: Like a sleeper cell awaiting activation, a never-before-seen Windows backdoor dubbed Sleepwalker waits silently in memory for one specifically crafted network packet to wake it up and deliver commands using the malware's 23-instruction language. The commands can do everything from running code directly in memory to moving data off the computer. Malware researcher Dominik Reichel discovered the passive backdoor, which also has its own command language, and detailed Sleepwalker in a technical analysis on Monday. "What makes it worth writing up is what that packet carries: not a readable command, but a short program written in a command language of the backdoor's own design," Reichel said. "Its 23 instructions cover scheduling, several ways to move data, staged file delivery and running code directly in memory. Recovering the encryption key is not enough to understand one of these programs. The internal command language must be reverse engineered as well." In addition to having its own command language, it's also notable that the remote host can be a VMware VMCI target instead of a normal network address. "Taken as a whole, the approach here is consistent with a targeted, well-resourced operation rather than an opportunistic one," Reichel wrote. The malware, hidden inside a 64-bit Windows DLL file, impersonates Microsoft's dpapi.dll, part of Windows' data protection API for protecting sensitive data. It exports the same seven functions as the real dpapi.dll, but attempts to forward calls to a file named dpapisvc.dll, which is not a real Windows component. The file also has a forged ESET Management Agent version resource, and loads via side-loading into ERAAgent.exe, the Windows executable for ESET Management Agent. After confirming that its host process is named ERAAgent.exe, Sleepwalker goes to sleep inside the computer's memory, which also helps it remain hidden from traditional anti-virus tools. Unlike most backdoors, which call back to an attacker-controlled command-and-control (C2) server and start receiving commands, Sleepwalker lies in wait, checking every packet that passes through the network looking for a specific pattern - this is called a magic packet. Once it sniffs out a packet that matches the exact pattern, the backdoor decrypts the data and treats it as a command. "Because the backdoor never sends anything out on its own and does not open any obvious listening port by default, tools that watch for connections to known-bad domains or unusual outbound traffic will not see anything unusual," Reichel wrote. "The absence of outbound connections to known-bad infrastructure does not rule out an infection, either. A machine can be fully compromised by this backdoor while producing nothing at all for a network monitor to flag." Read more of this story at Slashdot.

  • AliExpress Leverages User Audio Systems For Fingerprinting
    by BeauHD on 25/08/2026 at 7:00 am

    A developer says AliExpress is using the browser's WebAudio API to help fingerprint users by playing inaudible audio and measuring tiny differences in how their devices process it. CyberNews reports: The developer, "laserphile," wrote on their blog that they recently ran into some weird issues with their Bluetooth headphones. They couldn't play music via their phone when, at the same time, the AliExpress website was open on their PC. The headphones, laserphile explained, support multipoint Bluetooth audio so they can be connected to the PC and phone at the same time, for instance, playing music on the phone and announcing notifications through the PC. "Shortly after loading the AliExpress homepage, audio from my phone would stop playing. Closing the AliExpress tab fixes it immediately," the developer said in the blog post. "Muting the tab/Firefox/Windows does not help, and there is no visible video, music, or other media playing on the page. This seemed suspicious enough to investigate." It turns out that Alibaba has been secretly leveraging AliExpress users' audio systems to track them and build detailed fingerprints of them. [...] The AliExpress site was using the browser's WebAudio API to run invisible sound waves at zero volume. By measuring tiny hardware differences in how each PC processed those signals, the site created a unique digital fingerprint to track devices -- without user knowledge or consent. The secret audio path froze the developer's Bluetooth connection while covertly scraping hardware memory, screen dimensions, and network data in the background. The data collection extends beyond audio. Further inspection revealed that the same scripts also measure canvas, WebGL, hardware specs, WebRTC, mouse/touch events, and automation indicators. All of these form a broad device fingerprint that is sent back to Alibaba's telemetry servers. The simplest fix is to use a privacy-focused browser such as Firefox or Brave, which can limit or block this kind of fingerprinting. Brave goes further by randomizing fingerprint data and blocking the AliExpress tracking scripts involved. Read more of this story at Slashdot.

  • World's Oceans Hit Highest Temperature On Record As El Nino Grows
    by BeauHD on 25/08/2026 at 3:30 am

    An anonymous reader quotes a report from the BBC: The world's oceans are hotter than ever recorded, new data suggests, as they suffer from human-caused climate change and the growing El Nino weather phenomenon. The average surface temperature of the planet's seas outside the polar regions hit 21.1C (70F) on Saturday, according to figures from the European Copernicus climate change service. That edges past the 21.09C recorded on three separate days in March 2024, and is far above average for the time of year. [...] The data is based on sea temperatures 10m (32ft 10in) below the surface, using measurements from buoys, ships and satellites, which are combined to produce a global estimate. While the margin of record is currently very small and any global estimate comes with uncertainties, scientists say its timing is particularly notable. Average worldwide sea temperatures tend to reach their yearly peak in March or April, which corresponds to the end of summer in the southern hemisphere -- and not in August. The southern hemisphere contains more of the planet's ocean surface than the northern hemisphere and so exerts a bigger influence on average sea temperatures. What is especially concerning to scientists is that the oceans are already so hot when the natural El Nino weather phenomenon is still some way off its expected peak. "The fact that we are already breaking records is an early indicator of how strong the El Nino is becoming," said Dr Jeremy Grist, senior research fellow at the National Oceanography Centre in Southampton. "All things being equal we might expect the ocean temperature record to be broken again in March [or] April 2027," he added. Read more of this story at Slashdot.

  • Amazon Hikes Hardware Prices By 60%, Blaming Memory Shortage
    by BeauHD on 24/08/2026 at 11:00 pm

    Amazon has raised the prices of its hardware devices by as much as 60%, blaming "significant increases in memory and storage component costs." TechCrunch reports: The price explosion impacted Fire TVs, Echos, Kindles, and Eeros. One egregious example that's been cited is that of the Echo Dot, one of Amazon's cheapest smart speakers, the price of which jumped 60% overnight, from $49.99 to $79.99. Price-tracking sites like CamelCamelCamel show the stark uptick, which has previously hovered much lower. [...] The company also said that it would continue to offer occasional promotions to customers over the course of the next year. Amazon said in a statement: "The consumer electronics industry is facing significant increases in memory and storage component costs. After absorbing these increases for as long as we could, we recently adjusted pricing across our product lines." Read more of this story at Slashdot.

  • SEC Investigating Near-Implosion of AI Hedge Fund
    by BeauHD on 24/08/2026 at 10:00 pm

    The SEC is investigating the near-collapse of AI-focused hedge fund Situational Awareness, sending subpoenas to major Wall Street banks for details about the fund's trades, borrowing, and communications with lenders. The fund, founded by former OpenAI researcher Leopold Aschenbrenner, managed over $30 billion and borrowed tens of billions more before leveraged bets unraveled, forcing it to sell most of its stock portfolio to Citadel at a discount. The New York Times reports: The subpoenas asked for details on the timing of Situational Awareness's trades and for its communications with lenders about the money it was borrowing, also known as "leverage," two of those people said. The subpoenas additionally warned the banks to preserve any information regarding the San Francisco hedge fund. The S.E.C. oversees financial markets with an eye toward protecting small investors, and has brought civil cases regularly against investment firms that produced large losses. Any investigation into Situational Awareness would be at its earliest stages, and it's no guarantee that it would lead to fines or other punishment. The hedge fund has not been accused of wrongdoing. [...] Situational Awareness had a fast rise and an even quicker retreat. Founded just two years ago by Leopold Aschenbrenner, a former researcher at OpenAI, it rode the A.I. boom to soaring investment returns. To achieve those results, however, the fund relied on heavy borrowing, as well as complicated and expensive financial instruments that magnify gains -- and losses. The latter piled up quickly last month when the stock prices of publicly traded, high-flying A.I. companies dipped. At the same time, shares in more traditional technology companies -- which the hedge fund had been betting against -- rose, compounding the problem. Situational Awareness was forced into a fire sale. It wound up selling most of its stock portfolio to a rival, Citadel, at a discount. Read more of this story at Slashdot.

Archives

  • September 2022
  • November 2021
  • June 2021
  • March 2021
  • November 2020
  • October 2020
  • September 2020
  • February 2020
  • January 2020
  • October 2019
  • August 2018
  • July 2018
  • April 2018
  • February 2018
  • January 2018
  • December 2017
  • October 2017
  • September 2017
  • August 2016
  • July 2016
  • March 2016
  • February 2016
  • August 2015
  • May 2015

Categories

  • Innovation
  • Security
  • Software
  • Technology

Tags

backdoor cisco coding json laziness patterns public information announcement security vulnerability
© 2017 IT Sales & Services Ltd
Quality IT solutions in Tanzania since 2010
Iconic One Theme | Powered by Wordpress