| Andrew Cooke | Contents | Latest | RSS | Twitter | Previous | Next

C[omp]ute

Welcome to my blog, which was once a mailing list of the same name and is still generated by mail. Please reply via the "comment" links.

Always interested in offers/projects/new ideas. Eclectic experience in fields like: numerical computing; Python web; Java enterprise; functional languages; GPGPU; SQL databases; etc. Based in Santiago, Chile; telecommute worldwide. CV; email.

Personal Projects

Lepl parser for Python.

Colorless Green.

Photography around Santiago.

SVG experiment.

Professional Portfolio

Calibration of seismometers.

Data access via web services.

Cache rewrite.

Extending OpenSSH.

C-ORM: docs, API.

Last 100 entries

Maths for Physicists; How I Am 8; 1000 Word Philosophy; Cyberpunk Reading List; Detailed Discussion of Message Dispatch in ParserCombinator Library for Julia; FizzBuzz in Julia w Dependent Types; kokko - Design Shop in Osaka; Summary of Greece, Currently; LLVM and GPUs; See Also; Schoolgirl Groyps (Maths); Japanese Lit; Another Example - Modular Arithmetic; Music from United; Read Agatha Christie for the Plot; A Constructive Look at TempleOS; Music Thread w Many Recommendations; Fixed Version; A Useful Julia Macro To Define Equality And Hash; k3b cdrom access, OpenSuse 13.1; Week 2; From outside, the UK looks less than stellar; Huge Fonts in VirtualBox; Keen - Complex Emergencies; The Fallen of World War II; Some Spanish Fiction; Calling C From Fortran 95; Bjork DJ Set; Z3 Example With Python; Week 1; Useful Guide To Starting With IJulia; UK Election + Media; Review: Reinventing Organizations; Inline Assembly With Julia / LLVM; Against the definition of types; Dumb Crypto Paper; The Search For Quasi-Periodicity...; Is There An Alternative To Processing?; CARDIAC (CARDboard Illustrative Aid to Computation); The Bolivian Case Against Chile At The Hague; Clear, Cogent Economic Arguments For Immigration; A Program To Say If I Am Working; Decent Cards For Ill People; New Photo; Luksic And Barrick Gold; President Bachelet's Speech; Baltimore Primer; libxml2 Parsing Stream; configure.ac Recipe For Library Path; The Davalos Affair For Idiots; Not The Onion: Google Fireside Chat w Kissinger; Bicycle Wheels, Inertia, and Energy; Another Tax Fraud; Google's Borg; A Verion That Redirects To Local HTTP Server; Spanish Accents For Idiots; Aluminium Cans; Advice on Spray Painting; Female View of Online Chat From a Male; UX Reading List; S4 Subgroups - Geometric Interpretation; Fucking Email; The SQM Affair For Idiots; Using Kolmogorov Complexity; Oblique Strategies in bash; Curses Tools; Markov Chain Monte Carlo Without all the Bullshit; Email Para Matias Godoy Mercado; The Penta Affair For Idiots; Example Code To Create numpy Array in C; Good Article on Bias in Graphic Design (NYTimes); Do You Backup github?; Data Mining Books; SimpleDateFormat should be synchronized; British Words; Chinese Govt Intercepts External Web To DDOS github; Numbering Permutations; Teenage Engineering - Low Price Synths; GCHQ Can Do Whatever It Wants; Dublinesque; A Cryptographic SAT Solver; Security Challenges; Word Lists for Crosswords; 3D Printing and Speaker Design; Searchable Snowden Archive; XCode Backdoored; Derived Apps Have Malware (CIA); Rowhammer - Hacking Software Via Hardware (DRAM) Bugs; Immutable SQL Database (Kinda); Tor GPS Tracker; That PyCon Dongle Mess...; ASCII Fluid Dynamics; Brandalism; Table of Shifter, Cassette and Derailleur Compatability; Lenovo Demonstrates How Bad HTTPS Is; Telegraph Owned by HSBC; Smaptop - Sunrise (Music); Equation Group (NSA); UK Torture in NI; And - A Natural Extension To Regexps; This Is The Future Of Religion; The Shazam (Music Matching) Algorithm

© 2006-2015 Andrew Cooke (site) / post authors (content).

Details on the RSA Attack

From: andrew cooke <andrew@...>

Date: Sat, 2 Apr 2011 08:49:07 -0300

On 17 March 2011 RSA dissclosed that it had detected an APT (Advanced
Persistent Threat - http://en.wikipedia.org/wiki/Advanced_Persistent_Threat)
to it's SecureID tokens - http://www.rsa.com/node.aspx?id=3872

SecureID tokens are small devices that display "random" numbers that you use
to connect to secure networks (the kind of thing that many banks here in Chile
use to secure online banking).  These are used by securityand political
agencies, amongst others, and an "APT" typically means "some foreign
government", so this could be a big deal.

More information on the attack has now been released -
http://blogs.rsa.com/rivner/anatomy-of-an-attack/ .  It seems that it was
started by using a zero-day attack agains Flash embedded in a mail attachment
sent to several workers.  Once the attackers could enter the system they used
privilege escalation attacks to gain access to secure servers and then
transferred data out.

No details, that I can see, on who was responsible.

Andrew

RSA Attackers Got (and Used) SecureID Data

From: andrew cooke <andrew@...>

Date: Sat, 28 May 2011 09:45:34 -0400

http://www.reuters.com/article/2011/05/27/us-usa-defense-hackers-idUSTRE74Q6VY20110527

Andrew

Secure ID Hack Confirmed

From: andrew cooke <andrew@...>

Date: Mon, 6 Jun 2011 23:19:26 -0400

http://online.wsj.com/article/SB10001424052702304906004576369990616694366.html

"The Lockheed attack showed that it was technologically feasible to hack a
third-party using data taken from RSA, and the defense contractor may not be
the last example."

Andrew

The RSA Email

From: andrew cooke <andrew@...>

Date: Fri, 26 Aug 2011 08:12:52 -0300

http://www.f-secure.com/weblog/archives/00002226.html

Andrew

Over 760 RSA Attack Victims

From: andrew cooke <andrew@...>

Date: Fri, 28 Oct 2011 08:45:44 -0300

https://krebsonsecurity.com/2011/10/who-else-was-hit-by-the-rsa-attackers/

"a list of companies whose networks were shown to have been phoning home to
some of the same control infrastructure that was used in the attack on RSA"

Andrew

Comment on this post