Archive for February, 2015

Gemalto Confirms It Was Hacked But Insists the NSA Didnt Get Its Crypto Keys

Gemalto, the Dutch maker of billions of mobile phone SIM cards, confirmed this morning that it was the target of attacks in 2010 and 2011attacks likely perpetrated by the NSA and British spy agency GCHQ. But even as the the company confirmed the hacks, it downplayed their significance, insisting that the attackers failed to get inside the network where cryptographic keys are stored that protect mobile communications.

Gemalto came to this conclusion after just a weeklong investigation following a news report that the NSA and GCHQ had hacked into the firms network in 2011. The news was reported by The Intercept last week, which said the agencies had gained access to huge cache of the cryptographic keys used with its SIM cards.

The investigation into the intrusion methods described in the document and the sophisticated attacks that Gemalto detected in 2010 and 2011 give us reasonable grounds to believe that an operation by NSA and GCHQ probably happened, Gemalto wrote in a press release on Wednesday. But, the company said, The attacks against Gemalto only breached its office networks and could not have resulted in a massive theft of SIM encryption keys.

Many in the information security community ridiculed Gemalto for asserting this after such a short investigation, particularly since the NSA has been known to deploy malware and techniques capable of completely erasing any signs of an intrusion after the fact to thwart forensic discovery of a breach.

Very impressive, Gemalto had no idea of any attacks in 2010, one week ago. Now they know exactly what happened, French developer and security researcher Matt Suiche wrote on Twitter.

Chris Soghoian, chief technologist for the American Civil Liberties Union had the same reaction.

Gemalto, a company that operates in 85 countries, has figured out how to do a thorough security audit of their systems in 6 days. Remarkable, he tweeted.

The Intercept alleged in its story that the spy agencies had targeted employees of the Dutch firm, reading their siphoned emails and scouring their Facebook posts to obtain information that would let them hack employee machines. Once on Gemaltos network, The Intecept reported, the spy agencies planted backdoors and other tools to give them a persistent foothold. We believe we have their entire network, boasted the author of a government PowerPoint slide that was leaked by Snowden to journalist Glenn Greenwald.

If true, this would be a damning breach. Gemalto is one of the leading makers of SIM cards; its cards are used in part to help secure the communications of billions of customers phones around the world on AT&T, T-Mobile, Verizon, Sprint and more than 400 other wireless carriers in 85 countries. Stealing the crypto keys would allow the spy agencies to wiretap and decipher encrypted phone communications between mobile handsets and cell towers without the assistance of telecom carriers or the oversight of a court or government.

Edward Snowden criticized the agencies for the hack in an Ask Me Anything session for Reddit on Monday. When the NSA and GCHQ compromised the security of potentially billions of phones (3g/4g encryption relies on the shared secret resident on the sim), Snowden wrote, they not only screwed the manufacturer, they screwed all of us, because the only way to address the security compromise is to recall and replace every SIM sold by Gemalto.

See the original post:
Gemalto Confirms It Was Hacked But Insists the NSA Didnt Get Its Crypto Keys

8 free IRS tax tools

Forget the idea that a 1040EZ form is the only simple way to file taxes. The Internal Revenue Service (IRS) and participating tax agencies have a virtual smorgasbord of free tools and programs available to help you get your taxes filed in a timely, efficient manner without having to pay hundreds of dollars for a tax professional to do it for you.

Weve compiled a list of eight free resources that can offer you support this tax season.

1. Taxpayer-advocate service

This service is free of charge and offers tips for filing your taxes, making payment plans, interacting with the IRS, amending a return and more. It also provides guidelines to help ensure you dont make a costly mistake. There is at least one Local Taxpayer Advocate in each state, and if you qualify to receive an advocates help, one will assist you with your taxing needs.

2. Free file

If your income was less than $60,000 in 2014, you can file your taxes online for free by using Free File. The free software walks you through each line of a return, helps you find tax breaks and electronically files your federal return. It can be a useful resource for those filing their taxes for the first time. You can still file for free if you earned more than $60,000, but in this case you will be using Free File Fillable Forms instead. It gives you electronic forms to fill out and doesnt walk you through each step like the former program does.

3. Get transcript

If you want to view information regarding the items from your tax return or your tax-account transactions, you can use the Get Transcript feature on the IRS website and receive a transcript via mail or directly online. A Tax Return Transcript will let you see most line items from your tax return, and a Tax Account Transcript gives you details on what type of return you filed, how much in taxes were paid and more.

4. Wheres my refund?

Once you filed your taxes and the IRS received your electronically filed tax return or paper return, you can check the status of your refund by accessing this feature via the IRS website or the mobile app, IRS2Go. For a electronically filed return, check the refund status within 24 hours after the IRS receives it. If you filed a paper tax return, wait about four weeks. The IRS generally issues refunds within 21 days, and the site that tracks your refunds status only updates once every 24 hours.

Continued here:
8 free IRS tax tools

Synopsys' embARC Open Software Platform Accelerates Development of ARC-based Embedded Systems for the Internet of Things

MOUNTAIN VIEW, Calif., Feb. 26, 2015 /PRNewswire/ --

Highlights:

Synopsys, Inc. (Nasdaq: SNPS) today launched the embARC Open Software Platform to help accelerate the development of DesignWare ARC processor-based embedded systems. The new embARC platform gives ARC software developers online access to a comprehensive suite of free and open-source software that eases the development of code for the IoT and other embedded applications. Device drivers, operating systems and middleware ported to and optimized for ARC processors are available for download without cost from the embARC.org website. The website also provides access to software development tools and documentation as well as user forums to facilitate the sharing of information and expertise among the ARC-based design community.

"We are pleased to see that the embARC Open Software Platform supports the use of the popular open-source FreeRTOS," said Andrew Longhurst, business development manager at Wittenstein High Integrity Systems. "We offer OPENRTOS, the only commercially licensed and supported version of FreeRTOS, thus allowing designers using embARC to move to an RTOS with professional support, maintenance and updates, if needed."

Drivers, Operating Systems and MiddlewarePre-ported drivers for the GPIO, UART, SPI, I2C and other peripherals as well as leading real-time operating systems (RTOS), including FreeRTOS and Contiki OS, give developers a choice of industry-standard software environments for their ARC-based systems. FreeRTOS is a scalable, compact and reliable operating system that is popular among embedded software developers. The Contiki OS is specifically designed for networked, memory-constrained systems such as low-power, wireless IoT applications.

The embARC platform provides a choice of middleware components and a robust starting point for the development of IoT-related devices. The components available for use with FreeRTOS include the TCP/IP stack lwIP, file system fatfs, and MQTT and libcoap IoT protocols. The Contiki OS includes a middleware package with an integrated IoT protocol stack including MQTT, a publish/subscribe messaging protocol for lightweight machine-to-machine communications, and the CoAP application layer protocol for resource-constrained IoT applications.

"FreeRTOS is professionally developed, supported and yet completely free for developers to embed in their commercial products without any requirement to expose their proprietary source code," said Richard Barry, director at Real Time Engineers Ltd. "As the leading RTOS for embedded applications, we are really pleased that Synopsys is making FreeRTOS available as part of their new embARC Platform. ARC users now have a simplified path to join the hundreds of thousands of developers worldwide who already benefit from the ease of use and proven reliability of FreeRTOS."

embARC.orgembARC.org is a dedicated website that provides developers centralized access to free and open-source software, drivers, operating systems and middleware supporting the embARC Open Software Platform. The website also provides documentation and a forum-based community where developers can share their resources, expertise and code to help speed deployment of ARC-processor based embedded systems.

Free and Premium Software Development ToolsFree software development tools built on the open-source Eclipse IDE and GNU toolchain are available for use with the embARC Open Software Platform. This gives developers a flexible software environment with an IDE, compiler, debugger and utilities that are familiar to embedded developers. The embARC software is also supported by the commercially-available Synopsys ARC MetaWare Development Toolkit, giving developers the option to use a highly optimized toolchain for maximum code density and performance.

The embARC Open Software Platform has been ported to Synopsys' ARC EM Starter Kit, a low-cost software development board consisting of pre-installed FPGA images of ARC EM Processors with peripherals and a software package. The Starter Kit enables rapid software development, code porting, software debugging and profiling for the EM4, EM6, EM5D and EM7D processor cores.

See the rest here:
Synopsys' embARC Open Software Platform Accelerates Development of ARC-based Embedded Systems for the Internet of Things

Mocavo

By Molly McLaughlin

For budding genealogists, using a free program is a great wayto get your feet wet. Mocavo offers a generous free plan (Mocavo Basic) that includes access to thousands of integrated public records. Itspaid plans, Mocavo Silver ($7 per month) and Mocavo Gold ($9 per month), offer a free seven-day trial and a few extras to simplify your research process. In general, Mocavooffers a fun, simple interface and a good feature set, even with the free plan. The only thing missing is a publishing option. Despite some shortcomings, Mocavo is our Editors' Choice for free genealogy software.

Setup and InterfaceTo get a good sense of the service, I signed up for a free trial of Mocavo Gold, which offers a central database for conducting your research, email alerts about possible ancestors, and live webcasts with their chief genealogist. Only Mocavo Gold members can export their family tree as a GEDCOM file, though. After the trial, which requires a credit card, you can pay month to month or annually, for a discounted price ($80 for Silver, $100 for Gold).

When you sign in for the first time, a windowopens that asks if you want to perform a surname search on up to three names. If you do, you're automatically signed up with surname groups. In those groups, you can see all the data related to thesurnames from a range of sources, including the social security death index, state death records, census records, court, land and tax records, family and personal histories, immigration and travel, and more.

Mocavo'sinterface is well designed, and I like its light tone when it comes to communications, alerts, and other content on the site. For example, when I connected my account with Facebook, a message appeared that said, "Double-check your relationships to the people below before we add them to your family tree. We understand that some friends are 'basically sisters,' but let's keep it genealogical here."

Building Family TreesAs is par for the genealogy course, you can create your family tree from scratch or upload a GEDCOM file, but in Mocavo,you can also connect to your Facebook profile. It only works if you've added the Family Members feature to your profile, however. I uploaded a small GEDCOM file (about 3KB) from OneGreatFamily, and it was accurately processed in about a minute.

You can add a photo to relative's profiles in addition to life events and notes. After I added one of my relatives, I accidentally hit the save button a few times and ended up create multiple entries. To fix it, I had to delete the duplicates one by one, which was annoying since I couldn't think of a reason anyone would want to create duplicate entries in the first place.

Public records are free no matter the plan. When you find a matching record, you can attach it to aspecific family member, save it in your shoebox (avirtual catchall for info you want to save, but you're not sure where it goes), or hide it forever if it's not relevant. Next time you search, any results that you've connected to a family member are marked as such, so you don't do double work. I love that the research is integrated so you don't have to copy and paste which can lead to errors. Mocavo shares this excellent feature with the PCMag Editors' Choice award-winning Ancestry and Arviches.

Your family tree can be dragged all around the page, so you can easily access specific family members. You'll appreciate this functionif you need to add children to a relative near the bottom of the page, as the drop-down menu may get cut off. It took me a few minutes to get the hang of it, but it was generally easy to use and responsive.

There aren't any formal publishing options. You can print blank trees, diagrams and charts, but if you want to create anything fancy, you'll have to go elsewhere. There is an option to edit the blank PDFs, but that's just double work.

See original here:
Mocavo

New bill, new implications for Stand Your Ground law

RENO, Nev. -- The Nevada Senate Judiciary Committee is looking at a proposed bill that could change what qualifies as a place in which the Silver State's 'Stand Your Ground' law applies.

If this bill becomes law, an "occupied motor vehicle" could be added to the list of places a Nevadan can defend themselves.

The Senate Judiciary Committee heard statements today on whether or not it is lawful for a person to shoot a perceived aggressor if he or she "uses force" to break into the person's car or cause harm.

Senator Michael Roberson is a co-author of Senate Bill 175; it also includes verbiage protecting domestic violence victims in Nevada.

However, the majority of today's hour-and-a-half long meeting revolved around the occupied car section of the bill.

Supporters of the bill say this is not an extension of Nevada's current Stand Your Ground law, but the bill's opponents say it absolutely is.

"The primary concern we have with this is that we're talking about what's supposed to be a domestic violence bill; and there is an embedded presumption that allows someone to shoot first, ask questions later. It's more than just terminology, it's actual substance in this bill that presents a humongous problem for a large constituency of this state," says Sen. Aaron Ford. New bill, new implications for Stand Your Ground law

Visit link:
New bill, new implications for Stand Your Ground law