Firefox Zero-Day Can Be Used To Unmask Tor Browser Users

An anonymous reader quotes a report from Computerworld: A Firefox zero-day being used in the wild to target Tor users is using code that is nearly identical to what the FBI used in 2013 to unmask Tor-users. A Tor browser user notified the Tor mailing list of the newly discovered exploit, posting the exploit code to the mailing list via a Sigaint darknet email address. A short time later, Roger Dingledine, co-founder of the Tor Project Team, confirmed that the Firefox team had been notified, had “found the bug” and were “working on a patch.” On Monday, Mozilla released a security update to close off a different critical vulnerability in Firefox. Dan Guido, CEO of TrailofBits, noted on Twitter, that “it’s a garden variety use-after-free, not a heap overflow” and it’s “not an advanced exploit.” He added that the vulnerability is also present on the Mac OS, “but the exploit does not include support for targeting any operating system but Windows.” Security researcher Joshua Yabut told Ars Technica that the exploit code is “100% effective for remote code execution on Windows systems.” “The shellcode used is almost exactly the shellcode of the 2013 one,” tweeted a security researcher going by TheWack0lian. He added, “When I first noticed the old shellcode was so similar, I had to double-check the dates to make sure I wasn’t looking at a 3-year-old post.” He’s referring to the 2013 payload used by the FBI to deanonymize Tor-users visiting a child porn site. The attack allowed the FBI to tag Tor browser users who believed they were anonymous while visiting a “hidden” child porn site on Freedom Hosting; the exploit code forced the browser to send information such as MAC address, hostname and IP address to a third-party server with a public IP address; the feds could use that data to obtain users’ identities via their ISPs.

Read more of this story at Slashdot.



Source: Slashdot – Firefox Zero-Day Can Be Used To Unmask Tor Browser Users

FDA’s OK on trial opens possibility of prescription ecstasy in five years

Enlarge / Girl with an ecstasy tablet on her tongue, smiley faced pill, UK 2004 (Photo by Universal Images Group via Getty Images) (credit: Getty | UniversalImagesGroup)

The Food and Drug Administration on Tuesday approved the first large-scale, phase 3 clinical trial of ecstasy in patients suffering from post-traumatic stress disorder (PTSD), the New York Times reported.

The regulatory green-light follows six smaller-scale trials that showed remarkable success using the drug. In fact, some of the 130 PTSD patients involved in those trials say ecstasy—or 3,4-Methylenedioxymethamphetamine (MDMA)—saved them from the devastating impacts of PTSD after more than a decade of seeing no improvement with the other treatment options available.

Currently, the best of those established treatment options can only improve symptoms in 60 to 70 percent of PTSD patients, one expert noted. However, after one of the early MDMA studies, the drug had completely erased all traces of symptoms in two-thirds of PTSD patients.

Read 8 remaining paragraphs | Comments



Source: Ars Technica – FDA’s OK on trial opens possibility of prescription ecstasy in five years

Marinate Tough Greens in Oil (and Use It for Dressing) for Tastier Salads

Tough greens, like kale and collard greens, can take some work to make them suitable for salad but if you marinate them in oil for a bit first, you’ll tenderize them, make your salad even tastier, and start a light dressing all at the same time.

Read more…



Source: LifeHacker – Marinate Tough Greens in Oil (and Use It for Dressing) for Tastier Salads

Showtime Is Now Selling Official Twin Peaks Merchandise, Including David Lynch Artwork

There’s been no shortage of ways for Twin Peaks faithful to showcase their fandom over the years—a quick Etsy search will yield literally thousands of items inspired by the show. But with the show’s 2017 return to the airwaves, Showtime has opened its own Twin Peaks storefront, with some exclusive wares.

Read more…



Source: io9 – Showtime Is Now Selling Official Twin Peaks Merchandise, Including David Lynch Artwork

The Sheer Terror Of Introducing A Friend To Your Favorite Game

A few days ago, I was hanging out at some friends’ house. One of them, Ian, decided to buy a new PS4 game. “Get The Witcher 3!” I yapped, briefly outdoing his tiny dog, who looked on with a mix of curiosity and some other dog emotion. “Get it, get it, get it!” It was only then that I realized I’d made a grave mistake.

Read more…



Source: Kotaku – The Sheer Terror Of Introducing A Friend To Your Favorite Game

Trump Appoints Third Net Neutrality Critic To FCC Advisory Team

Last week, President-elect Donald Trump appointed two new advisers to his transition team that will oversee his FCC and telecommunications policy agenda. Trump has added a third adviser today who, like the other two advisers, is a staunch opponent of net neutrality regulations. DSLReports adds: The incoming President chose Roslyn Layton, a visiting fellow at the broadband-industry-funded American Enterprise Institute, to help select the new FCC boss and guide the Trump administration on telecom policy. Layton joins Jeffrey Eisenach, a former Verizon consultant and vocal net neutrality critic, and Mark Jamison, a former Sprint lobbyist that has also fought tooth and nail against net neutrality; recently going so far as to argue he doesn’t think telecom monopolies exist. Like Eisenach and Jamison, Layton has made a career out of fighting relentlessly against most of the FCC’s more consumer-focused efforts, including net neutrality, consumer privacy rules, and increased competition in the residential broadband space. Back in October, Layton posted an article to the AEI blog proclaiming that the FCC’s new privacy rules, which give consumers greater control over how their data is collected and sold, were somehow part of a “partisan endgame of corporate favoritism” that weren’t necessary and only confused customers. Layton also has made it abundantly clear she supports zero rating, the practice of letting ISPs give their own (or high paying partners’) content cap-exemption and therefore a competitive advantage in the market. She has similarly, again like Eisenach and Jamison, supported rolling back the FCC’s classification of ISPs as common carriers under Title II, which would kill the existing net neutrality rules and greatly weaken the FCC’s ability to protect consumers.

Read more of this story at Slashdot.



Source: Slashdot – Trump Appoints Third Net Neutrality Critic To FCC Advisory Team

Remains of the Day: Uber Wants to Track Your Location Even When You're Not Using It

Uber recently started asking permission to collect your location data even when you aren’t using the app, and some people are understandably concerned. Uber says that they won’t literally track you everywhere you go; they just need a little more data about your pick-up and drop-off.

Read more…



Source: LifeHacker – Remains of the Day: Uber Wants to Track Your Location Even When You’re Not Using It

Construction Finally Begins on Chinese Titanic Replica That Simulates the Disaster

A few years ago, plans were announced for a life-size replica of the Titanic, the luxury ship whose sinking inspired a very expensive movie and some great blogs. On Wednesday, construction of the large fake boat finally began.

Read more…



Source: Gizmodo – Construction Finally Begins on Chinese Titanic Replica That Simulates the Disaster

CORSAIR Celebrates 10 Years Of PSUs Limited RM1000i Special Edition

CORSAIR®, a world leader in enthusiast memory, high-performance gaming hardware and PC components, today reached two new milestones, celebrating ten years since first entering the PSU market and the sale of the ten millionth CORSAIR PSU. Over the past decade, CORSAIR has revolutionized the enthusiast PSU industry with an unrelenting commitment to product quality and innovation that has seen the PSU evolve from an after-thought into the high-quality heart of a modern PC. CORSAIR has championed a range of key features to push PC power supplies to new levels of performance, functionality and customization. Modular PSUs have made building PCs easier, Zero RPM fan mode allows the PSU’s fan to switch off entirely under low loads and with digitally controlled power and CORSAIR LINK PSU monitoring, users can find out exactly how their PSU is performing in an instant.


To commemorate this achievement, CORSAIR is proud to announce the extremely limited CORSAIR RM1000i Special Edition. Individually numbered, finished in striking arctic white and equipped with both a white LED-lit cooling fan and new individually sleeved white cables, only 100 of these PSUs will be built, giving enthusiasts a chance to own a unique piece of CORSAIR history.

Comments

Just a reminder that we are giving one of these extremely limited CORSAIR RM1000i Special Edition PSUs away right HERE.

Source: [H]ardOCP – CORSAIR Celebrates 10 Years Of PSUs Limited RM1000i Special Edition

Reddit To Crack Down On Abuse By Punishing Hundreds of 'Toxic Users'

An anonymous reader quotes a report from Reuters: Social media website Reddit, known for its commitment to free speech, will crack down on online harassment by banning or suspending users who target others, starting with those who have directed abuse at Chief Executive Steve Huffman. Huffman said in an interview with Reuters that Reddit’s content policy prohibits harassment, but that it had not been adequately enforced. “Personal message harassment is the most cut and dry,” he said. “Right now we are in an interesting position where my inbox is full of them, it’s easy to start with me.” As well as combing through Huffman’s inbox, Reddit will monitor user reports, add greater filtering capacity, and take a more proactive role in policing its platform rather than relying on community moderators. Reddit said it had identified hundreds of the “most toxic users” and will warn, ban or suspend them. It also plans to increase staff on its “trust and safety” team. On Reddit, a channel supporting the U.S. Republican party’s presidential candidate Donald Trump, called r/The_Donald, featured racist and misogynistic comments, fake news and conspiracy theories about his Democratic challenger Hillary Clinton, along with more mainstream expressions of support for Trump. Many of those supporting Trump were very active, voting up the r/The_Donald conversations so that they became prominent across Reddit, which is the 7th-most-visited U.S. internet site, according to web data firm Alexa. Last week, Reddit banned Pizzagate, a community devoted to a conspiracy theory, with no evidence to back it up, that links Clinton to a pedophile ring at a Washington, D.C. pizza parlor, after it posted personal information in violation of Reddit policy. Huffman then used his administrative privileges to redirect abuse he was receiving on a thread on r/The_Donald to the community’s moderators — making it look as if it was intended for them. Huffman said it was a prank, and that many Reddit users, including some Trump supporters, told him they thought it was funny, but it inflamed the situation.

Read more of this story at Slashdot.



Source: Slashdot – Reddit To Crack Down On Abuse By Punishing Hundreds of ‘Toxic Users’

When The Vandals Took North Africa, They Had Their Way With The Roman Empire 

North Africa was one of the heartlands of the Roman Empire. It produced most of the grain that fed Rome, the olive oil that burned in lamps from Sicily to Spain, the pottery that sat on every dinner table from Britain to Greece, and the tax revenue that kept the Roman government flush.

Read more…



Source: Gizmodo – When The Vandals Took North Africa, They Had Their Way With The Roman Empire