This is a very thorough analysis of the security principles and usability of various Two Factor Authentication systems: wiki.shibboleth.net/confluence

people were talking about the millennium bug recently, well it turns out a lot of the fixes just delayed the problem to 2020

"Programmers wanting to avoid the Y2K bug had two broad options: entirely rewrite their code, or adopt a quick fix called “windowing”, which would treat all dates from 00 to 20, as from the 2000s, rather than the 1900s. An estimated 80 per cent of computers fixed in 1999 used the quicker, cheaper option."

"Those systems that used the quick fix have now reached the end of that window, and have rolled back to 1920. Utility company bills have reportedly been produced with the erroneous date 1920, while tens of thousands of parking meters in New York City have declined credit card transactions because of the date glitch."

newscientist.com/article/22292

#Osmocom has just released new versions of the entire 2G/3G cellular network stack: See osmocom.org/news/123 for tthe release announcement - thanks for everyone contributing to this release!

Do you backup your email? If so, how and how often?

We have computed the very first chosen-prefix collision for SHA-1. To put it in another way: all attacks that are practical on MD5 are now also practical on SHA-1.

We have reduced the cost of a collision attack from 2^64.7 to 2^61.2, and the cost of a chosen-prefix collision attack from 2^67.1 to 2^63.4.

Demo: The legacy branch of GnuPG (version 1.4) is vulnerable. We have created two PGP keys with different UserIDs and colliding certificates.

sha-mbles.github.io/

I decided to start the new year with some PCB Layout. Can you tell what it is? I am not sure if it is a good or a bad thing if you can recognize the footprint, but you are definitely in good company I recognize them pretty much instantly on other boards. :)

Microphones are vulnerable to laser attack - lightcommands.com/
Smarter Every Day demonstrates controlling devices via laser, even through a window. youtube.com/watch?v=ozIKwGt38L

Setup is summarized at osmocom.org/projects/retro-bbs - feel free to connect yourself with analog or ISDN lines to the patch panel (its labelled) in my absence.

0.5.2 is released!

Roughly 40 or so additional devices (or whole device series) supported, improved USB HID support via HIDAPI, Bluetooth/BLE support (Linux-only for now, via BlueZ), and tons of improvements and bugfixes.

sigrok.org/blog/libsigrok-052-

wanted! I'm looking for video editing software for Linux. Does anyone have experience with this?

"Zuckerberg won't speak to the Guardian, so they built a bot trained on hundreds of thousands of his words and interviewed that instead. The result is golden." theguardian.com/technology/201

(RT @allytibbitt@twitter.com)

@uint8_t "because of decisions made in the 1930s", HDMI and EDID are worse than you can imagine: mjg59.dreamwidth.org/8705.html

now supports the MASTECH MS6514 2-channel, USB-based thermometer.

It supports K,J,T,E,R,S,N thermocouple types.

Full teardown and protocol docs available in the wiki.

sigrok.org/blog/mastech-ms6514

recently gained and support.

Currently only a based, ( only) backend is implemented. Contributions for other OSes welcome!

Supported devices so far: 121GW, , some DMMs with Bluetooth cables.

sigrok.org/blog/bluetooth-and-

0.5.3 is released!

New decoders: lin, x2444m, ds2408, cc1101, enc28j60, pca9571, seven_segment, amulet_ascii, tdm_audio, signature, nes_gamepad, flexray, ir_rc6, ieee488, hdcp.

Total PDs supported in this release: 109.

sigrok.org/blog/libsigrokdecod

The sale of the .ORG registry to Ethos Capital would erode the safeguards nonprofits and NGOs have against arbitrary censorship and price gouging. Sign on to the petition to #SaveDotOrg. eff.org/deeplinks/2019/12/we-n

Show more
Fosstodon

Fosstodon is an English speaking Mastodon instance that is open to anyone who is interested in technology; particularly free & open source software.