Tuesday, October 22, 2013

Chinese pair, Shell, Total join Brazil to win oil auction




Security forces in riot gear form a line in front of the hotel where Brazil's National Petroleum Agency auctions drilling rights to one of the world's largest offshore oil discoveries, in Rio de Janeiro on October 21, 2013 (AFP Photo/Christophe Simon)





Rio de Janeiro (AFP) - Chinese firms CNOOC and CNPC, Royal Dutch Shell and France's Total joined Brazilian state operator Petrobras in a joint bid to win Monday's auction to develop the huge Libra oilfield.

The four energy giants won 35-year concessions, with Petrobras taking a 40 percent stake. Shell and Total both earned a 20 percent stake, with CNOOC and CNPC securing 10 percent each.

Source: http://news.yahoo.com/clashes-brazil-auctions-oil-licenses-174957358.html
Related Topics: oakland raiders   2013 Emmy Winners   yom kippur   Arsenio Hall   nfl  

Colorado theater gunman coerced into incriminating statements, defense says


By Keith Coffman


CENTENNIAL, Colo. (Reuters) - Police coerced movie theater gunman James Holmes into talking about explosives found in his apartment after he shot 12 people to death, and those statements should be barred from his murder trial, defense lawyers argued in a Colorado courtroom on Monday.


Prosecutors stood by the admissibility of the statements, countering that police were merely trying to obtain information on how to safely defuse the bombs to protect law enforcement officers and the public from a potential detonation of the booby traps.


The latest legal back-and-forth in the high-profile case came in a hearing over what evidence should be allowed in the capital murder trial of the onetime neuroscience graduate student, due to start in early February.


Holmes, 25, is charged with first-degree murder and attempted murder for opening fire in a suburban Denver cinema during a midnight screening of the Batman film "The Dark Knight Rises" in July 2012.


The shooting rampage left 12 moviegoers dead and 70 others injured or wounded, some with permanent paralysis.


Holmes has pleaded not guilty by reason of insanity, and his lawyers have said their client was undergoing a psychotic episode when he sprayed the movie auditorium with gunfire before surrendering to police.


Prosecutors are seeking the death penalty for the California native if he is convicted.


Public defender Kristen Nelson said police denied Holmes' repeated requests to speak to a lawyer before he was questioned by investigators, and deceived him into thinking that the information he provided would not be used against him.


Had police allowed him to seek legal counsel immediately after his arrest, as required under the U.S. Constitution, a lawyer would have helped "protect this mentally ill man from being the instrument to his own conviction and execution," Nelson said.


Holmes, who has tended to stare straight ahead during courtroom testimony, bowed his head throughout Nelson's impassioned argument.


Prosecutor Rich Orman countered that police were unsure at the time if there was a second gunman at large and were dealing with a fluid situation.


"They could not know if setting foot in the apartment would trigger a massive conflagration," he said.


Defense lawyers also said the seizure of Holmes' bank accounts, which traced his firearms purchases, should be suppressed because there was not initially a valid, signed court order allowing the records to be released to prosecutors.


But prosecutors said they noticed what they called an oversight and informed the public defenders and the court of the error that was later rectified with a proper court order.


Arapahoe County District Judge Carlos Samour Jr. has not ruled on the suppression motions.


(Reporting by Keith Coffman; Editing by Steve Gorman and Eric Beech)

Source: http://news.yahoo.com/colorado-theater-gunman-coerced-incriminating-statements-defense-says-044658839.html
Category: banksy   Daft Punk   bradley manning   vanessa hudgens   Frank Castillo  

Mayors officiate as New Jersey legalizes gay marriage (reuters)

Share With Friends: Share on FacebookTweet ThisPost to Google-BuzzSend on GmailPost to Linked-InSubscribe to This Feed | Rss To Twitter | Politics - Top Stories News, RSS and RSS Feed via Feedzilla.
Source: http://news.feedzilla.com/en_us/stories/politics/top-stories/335373568?client_source=feed&format=rss
Category: twerking   9/11 Memorial   Beyonce Haircut  

Burton Presents RESORT [Snowboarding] Teaser



Posted by: Evan Litsios / added: 10.21.2013 / Back to What Up


Burton Snowboards puts a lot of recourses towards giving their riders pristine parks to play around on, which shows in this teaser for the fourth installment of their [Snowboarding] series, Resort. When the Burton team steps up to a big jump or hip, you can exect to see airs well over four stories high, and the kind of grabs and spins more commonly seen in video games. The full edit drops this Friday. 






Comments:



Drop A Line:



Source: http://www.frqncy.com/news/2013/10/21/burton-presents-resort-snowboarding-teaser?utm_campaign=blog_feed&utm_medium=feed&utm_source=feed_reader
Similar Articles: Malala Yousafzai   Kaepernick   detroit lions   NFL.com   lil kim  

Monday, October 21, 2013

Is iMessage secure? The good, the bad, and the complicated

Is iMessage secure? The good, the bad, and the complicated

Last week, researchers from QuarksLab gave a presentation at HITBSecConf2013 on the security of iMessage. The researchers sought to investigate claims made by Apple that nobody but the sender and receiver could read iMessage data thanks to their use of end-to-end encryption. While the researchers discovered that they were able to intercept and decrypt iMessages, Apple was quick to respond insisting iMessages infrastructure is not set up for that type of interception. So which is it? Is iMessage secure or not?

Details published on the research cover two kinds of scenarios. The first scenarios is one where a malicious attacker is able to intercept, decrypt, and manipulate iMessages between two users. The researchers properly point out, multiple times, that this attack has "strong requirements". An attacker must be able to acquire both parties private keys (in one type of scenario), impersonate two separate Apple servers, redirect the victims' traffic to those servers, and install a certificate for their own CA on the users' devices. Is this possible? Absolutely, and the researchers even published a (http://www.youtube.com/watch?v=EbqZnTKDVU0&feature=youtu.be) demonstrating the attack. It is probable? No. While the attack is reproducible in an environment where you control and have full access to the devices you're attacking, it becomes tremendously more difficult when you're talking about targeting people in the wild.

The second scenario the researchers discuss, which is slightly more worrisome, though probably not freak-out worthy, is one where Apple could intercept and decrypt iMessage between two users. With Apple, there's no need for an attacker to install their own trusted CA on a victim's device because Apple already has a CA that is trusted by iOS devices. Apple doesn't need to impersonate any servers because they're the ones running the actual servers. This also means Apple doesn't need to redirect the victims' traffic since it's already in the middle of it. Finally, Apple owns the server that assigns the encryption keys. This means that, from a cryptography standpoint, Apple possesses everything necessary to read iMessages between its users.

Apple issued a response to the research, saying that iMessage is not architected in a way that would allow such an attack to take place:

The research discussed theoretical vulnerabilities that would require Apple to re-engineer the iMessage system to exploit it, and Apple has no plans or intentions to do so.

While theoretically Apple has all the pieces necessary to intercept iMessages, their stance is that technologically their system is not set up in a way that would allow for that. While Apple could be lying about this, the damage that would be caused to their reputation if it was discovered that they were lying doesn't seem like it would be worth the risk. If Apple had a backdoor for reading iMessages, it seems more likely that they simply would have stayed quiet back in June, rather than going on record with a voluntary statement insisting they can't read iMessages. With the number of large tech companies that we now know the NSA taps into data from, Apple would have had nothing to lose by staying quiet about the whole thing, but they have a lot to lose from lying.

Moreover, whether you trust Apple or not, trust them to do what's in their own self-interest. If iMessage is proven to be exploitable in a way Apple has denied, it will harm their business. That's not in Apple's self-interest.

The research raises an interesting point though, which is that, if the NSA wanted to, from a cryptographic standpoint, there is nothing stopping them from requiring Apple go give them access to people's messages. The NSA could coerce Apple into re-engineering the iMessage system to allow for such eavesdropping. With that in mind, it would be nice to see Apple come up with a stronger key infrastructure, or perhaps as a start just sharing more information about their current system.

Another change some people have been proposing is certificate pinning. Ironically, a lack of certificate pinning is what allowed the researchers to analyze iMessage's traffic; the closed protocol which Apple has been scrutinized for not publishing more details on. If Apple had employed certificate pinning, iMessage would not have accepted the researchers' self-signed certificates that they were using on their fake iMessage servers. Certificate pinning would also prevent a malicious attacker from installing their own CA on a victims' devices, in turn preventing them from intercepting iMessage traffic. This would increase security in terms of an outside attacker, which as we already discussed, is a fairly unlikely scenario, but wouldn't change anything about Apple's potential ability to intercept messages. It could be argued that Apple should do this from a security standpoint, but still does not address the bigger concern.

For now, it really comes down to a question of whether or not you should use iMessage. The researchers gave an accurate assessment:

MITM attacks on iMessage are unpractical to the average hacker, and the privacy of iMessage is good enough for the average user.

If the informations being exchanged are sensitive to the point that you don’t want any government agencies to look into them, don’t. It's important to remember that iMessage was introduced as a replacement for SMS, which isn't encrypted at all and can be easily spoofed. The importance of security shouldn't be downplayed, but in the context of text messaging, iMessage continues to be more secure than SMS.

As users, we are left trying to find the right balance of convenience and security. iMessage offers the security of encrypting messaging, but sacrifices some security with the convenience of transparent encryption. Apple could implement a system where a sender and receiver confirm their keys with each other before beginning messaging, but of course this would reduce convenience. If you currently have a need to transmit highly sensitive information that you can't risk the NSA or other three-letter acronyms from seeing, iMessage isn't the best choice and really never was. For the other 99.9% of iOS users, iMessage remains a convenient messaging solution and there's not much need to worry about your communications becoming compromised.


    






Source: http://feedproxy.google.com/~r/TheIphoneBlog/~3/pc2gMsqxeds/story01.htm
Tags: Shana Tova   Harry Styles   Hyperloop   tony stewart   pippa middleton  

iPhone 5S, iPhone 5C head to Boost Mobile on November 8

Sprint's other prepaid provider finally gets Apple's latest smartphones. It's both the latest and one of the last carriers to offer the two devices.


Apple's iPhone 5C.

Apple's iPhone 5C.


(Credit: CNET)

Apple's iPhone 5S and iPhone 5C are finally making their way to Boost Mobile.


Boost, a unit of Sprint, said Monday that Apple's latest smartphones will be available on November 8. It's both the latest and one of the last carriers to offer the two phones.



Apple typically pushes its new iPhones to the large big-box retailers and national wireless carriers before expanding the distribution to partners focused on prepayment customers. Virgin Mobile, Sprint's other prepaid business, got the iPhone 5S and iPhone 5C last month. A smaller number of users purchase the iPhone prepaid because customers are required to pay the higher unsubsidized price.


Boost declined to provide its prices for the iPhone 5S or iPhone 5C.


Source: http://news.cnet.com/8301-1035_3-57608406-94/iphone-5s-iphone-5c-head-to-boost-mobile-on-november-8/?part=rss&tag=feed&subj=News-Apple
Related Topics: aapl   Arsenio Hall   Low Winter Sun   jimmy fallon   Best Song Ever  

Building Sand Castles Is Less Frustrating When You Let a Robot Do It

Building Sand Castles Is Less Frustrating When You Let a Robot Do It

What if there was a way to enjoy a day at the beach no matter the season or weather outside? California-born artist Jonathan Schipper may have just come up with the perfect solution: An art installation inside a gallery featuring a hot tub standing in for the ocean, and tons of salt doubling as sand.

Read more...


    






Source: http://feeds.gawker.com/~r/gizmodo/full/~3/xouKIjeR5HE/building-sand-castles-is-less-frustrating-when-you-let-1449028694
Related Topics: 49ers   Niall Horan   new york times   Elmore Leonard   Prince George