Forgot your password?
typodupeerror

Submission + - Cops Can Bypass iPhoneâ(TM)s Automatic Reboot to Get Into Locked Phones (404media.co)

alternative_right writes: Apple quietly introduced a new feature in iOS that automatically reboots an iPhone that has not been unlocked for 72 hours. The idea behind this so-called âoeinactivity rebootâ is to revert the phone to a state that makes it harder for police to break into the device, and thus extract sensitive data from it with forensics technology.

The new technology to get around inactivity reboot was developed by Magnet Forensics, the company behind GrayKey, a popular tool sold to law enforcement agencies that allows them to unlock and access data stored in iPhones and Android smartphones. Magnet has developed a new device called GrayKey Preserve and a feature for its regular GrayKey devices called Evidence Preservation Mode, according to the video.

Submission + - California scientist emerges as possible Tylenol murders suspect (sfgate.com)

schwit1 writes: A man found dead in a church halfway across the country may have suddenly unlocked the key — quite literally — to one of America’s most famous unsolved crimes.

But although he had a successful career, working at one point for Lockheed Martin on a NASA-related project in New Mexico, Betkouski had a reputation for making unsettling comments. Former coworkers told Cooper that Betkouski spoke of how to commit a “perfect crime,” had a “history of volatility" and referenced cyanide as an ideal way to kill without detection. He also mentioned putting poison in over-the-counter medication, an especially worrisome comment coming from someone who had worked in multiple drugstores.

“It was said that Dr. Betkouski attempted to obtain some type of pills or capsules from a pharmacy in the Las Cruces area,” Cooper said at a press conference last week. “He said this would be for an experiment. For reasons not fully understood, Dr. Betkouski created a disturbance at the location and the police were summoned.”

Less than three months before Betkouski killed himself, a national terror was unfolding in Chicago. In late September 1982, seven people took over-the-counter Tylenol for their usual aches and pains. The capsules had been opened and filled with potassium cyanide, killing the people who took them.

Submission + - California rushes to prepare for massive 'Kelvin' wave (theguardian.com)

fjo3 writes: Communities across California are rushing to prepare for the imminent arrival of the so-called “Kelvin wave”, a massive underwater band of warm water threatening to inundate swaths of the vast North American shoreline.

The wave is nearing southern California and expected to reach the San Francisco Bay Area by early October, as it crawls toward Alaska. Waters could rise by a foot along the California coast, according to scientists, who have warned that this could dramatically double the 8-12in rise in sea levels already caused by climate change over the last century.

Submission + - The night sky is getting 10% brighter every year (theguardian.com)

fjo3 writes: Every year, the night sky is becoming 10% brighter. Eighty per cent of people live under light-polluted skies. And while the UN declared a healthy environment – clean air, clean water – to be a human right, I believe we also all have a right to darkness as well.

Submission + - Virus Stole a Human Gene and Won't Let Go of It (nytimes.com)

joshuark writes: In a new twist on the phrase "going viral" or stealing code, the NYT reports a virus has "stolen" a human gene, and will not let it go. In the article "This Virus Stole a Human Gene and Won’t Let Go of It" reports that scientists have found a human gene lurking in a virus that causes skin infections. Thus using our own DNA to infect us.

The molluscum contagiosum virus, which causes sores on skin, swiped a gene from humans about 100,000 years ago according to a new study.

The way that viruses replicate makes them particularly good at thieving DNA. The viruses infect a cell, then co-opt its machinery by injecting their own genes. Sometimes this process goes awry, and a stretch of the host’s DNA gets bundled into the new viral genes. This molecular error can pose a threat to human health.

Submission + - The Nature of War has just changed forever (telegraph.co.uk)

MrBrklyn writes: Ukrainiaan land robots have been deployed in combat, killing thousands of Russian troops and changing the face of warfare forever. Leaders accross the globe are sitting up in the seats and paying attention as what started as a localized Russian agression has now turned into a world altering and historic war which the Russians seemingly have no means to win.

https://ancillary-proxy.atarimworker.io?url=https%3A%2F%2Fwww.telegraph.co.uk%2Fwo...

Submission + - Mozilla Appears to Sweep Their Telemetary-Droppings Privacy-Bugs Aside 4

BrendaEM writes: Myself and others have noticed that Firefox is leaving behind archived and other telemetry data--even when data reporting is turned off. The apparent fact that Mozilla, seems to have marked the bug resolved--when it is not, and offer a nebulous fix date, would suggest that they aren't taking the issue seriously.

I have at least 1,279 telemetry droppings files, in one archive folder alone, it bears to mind that SSD drive prices have gone up substantially, noting that even a small write will affect: one of the 1,000 to 10,000 MLC cycles, one of the 3,000 TLC Cycles, or one of the paltry 1,000 QLC cycles (Ref: Wikipedia: https://ancillary-proxy.atarimworker.io?url=https%3A%2F%2Fen.wikipedia.org%2Fwiki%2F...).

The existence of telemetry alone is unsettling for a browser that claims " Your privacy always comes first."
https://ancillary-proxy.atarimworker.io?url=https%3A%2F%2Fbugzilla.mozilla.org%2Fs...
https://ancillary-proxy.atarimworker.io?url=https%3A%2F%2Fbugzilla.mozilla.org%2Fs...

Submission + - Researchers Found a New Way to Break RSA that Doesn't Require Factoring the Key (cybersecuritynews.com)

An anonymous reader writes: Security researchers have demonstrated a faster way to undermine certain RSA deployments without factoring the public modulus, challenging the assumption that RSA’s practical strength always tracks the cost of integer factorization.

The attack converts temporary access to a raw, unpadded RSA signing or decryption service into a lasting capability to forge signatures or decrypt chosen ciphertexts offline.

Laura Shea, Miro Haller, Adam Suhl, Nadia Heninger and Emmanuel Thomé implemented the technique against a 1,024-bit RSA key. Their computation consumed 1,380 CPU core-years over five months and required 232 oracle queries. By comparison, factoring a 1,024-bit RSA modulus is estimated to require roughly 500,000 to one million core-years.

The method, called eNFS by the researchers, belongs to the number field sieve family. Instead of the general number field sieve used to factor RSA moduli, it approaches the faster “special” number field sieve complexity by replacing part of the usual mathematical work with answers from the signing oracle. Crucially, it never recovers the prime factors or RSA private key.

The attack unfolds in stages. An approximately 1,200-core-year precomputation depends only on the public modulus and exponent. The attacker then submits selected values to the raw RSA oracle. Once those responses are collected, access can disappear: forging any chosen signature or decrypting a target takes about another 180 core-years and can be repeated offline.

The underlying algorithm is not new. Antoine Joux, David Naccache and Emmanuel Thomé introduced it in 2007, but the new work provides its first implementation and large-scale 1,024-bit demonstration. The code builds heavily on CADO-NFS while adding the engineering needed for polynomial selection, sieving, linear algebra, root extraction, and descent at this scale.

This is not a universal RSA break. The attacker needs temporary access to a raw exponentiation oracle, a capability that conventional RSA signatures using PKCS#1 v1.5 or RSA-PSS padding normally do not expose. More plausible targets include HSM interfaces permitting raw PKCS#11 RSA operations and blind-signature protocols such as Privacy Pass, where blinded requests can provide the required oracle behavior.

The researchers estimate 2^{90} work and 2^{43} oracle queries against 2,048-bit RSA in this model, versus the commonly assigned 112-bit factoring strength. They project roughly 2^{119} work for 4,096-bit RSA, leaving it short of a modern 128-bit security target. Those costs remain beyond attackers, but could matter to well-resourced adversaries and protocols with long-lived public keys.

Organizations do not need to abandon correctly padded RSA immediately. Operators should disable unnecessary raw RSA mechanisms, audit HSM policies, limit oracle exposure, and rotate vulnerable blind-signature keys more frequently.

Protocol designers can investigate zero-knowledge proofs of well-formed requests, while longer-term migration should favor modern signature schemes and post-quantum cryptography rather than treating larger RSA keys as a permanent solution.

Submission + - Ruby on Rails Creator Abandons Ruby During Keynote Speech (youtube.com) 1

Grady Martin writes: David Heinemeier Hansson, creator of Ruby on Rails, announced during a keynote speech at Rails World 2026 on Wednesday that his current project, HEY, has begun migrating from Ruby to a vibe-coded rewrite in Rust. His speech also touched on human productivity and the importance of optimization, noting that agentic developers can “do whatever the fuck [they] want” to achieve the latter. He closed the hour with a Malcom in the Middle meme and commanded the audience: “Don't be a loser”.

Submission + - AI Finds So Many Linux Bugs That Canonical changes Ubuntu Security Update (nerds.xyz)

BrianFagioli writes: Canonical is changing how Ubuntu kernel security updates are delivered as the number of reported Linux vulnerabilities continues to grow. The company says AI tools including large language models and specialized agents are helping researchers discover bugs faster. The Linux kernel becoming a CVE Numbering Authority has also increased the number of assigned CVEs.

Ubuntu is moving from separate four week regular and two week security kernel update cycles to overlapping two week cycles. The result will be a kernel release every week. Canonical says it will retain hardware certification and regression testing while organizations willing to test release candidates themselves can access fixes earlier through the proposed pocket.

The shift highlights an interesting consequence of AI assisted security research. Finding vulnerabilities faster also puts pressure on Linux distributions to fix and deliver patches faster.

Submission + - No Warrant, No Suspicion, No Problem (reason.com)

fjo3 writes: Part of the bedrock of American civil liberties is the Fourth Amendment's prohibition against unreasonable searches. There is no right to privacy, and no due process in the justice system, without that. But immigration authorities, cops, and courts keep deciding that, for some reason, the Fourth Amendment just doesn't apply where new technology is concerned.

Slashdot Top Deals

Memory fault -- brain fried

Working...