Ed Brandon, long time weatherman for Channel 13 in Houston.
Obit watch: August 23, 2018.
August 23rd, 2018TMQ Watch: August 21, 2018.
August 23rd, 2018Like those truck stop enchiladas you had for dinner last night, Tuesday Morning Quarterback is back on The Weekly Standard.
And like the Genesee Cream Ale you washed those enchiladas down with, so is TMQ Watch: albeit a little late this week.
After the jump, this week’s TMQ…
Obit watch: August 22, 2018.
August 22nd, 2018I wasn’t originally going to post this one, but there’s a story here that’s too good to pass up.
Don Cherry, noted singer and noted amateur golfer. He actually passed away April 4th, but his death was not widely reported until recently.
He was also the voice of Mr. Clean at one point.
Because of his dual pursuits, he nearly sabotaged himself on the eve of his inaugural Masters, in 1953.
The owner of a local nightclub hired him to sing each night of the tournament. When Clifford Roberts, a founder of the Masters and chairman of Augusta National Golf Club in Georgia, where the tournament is held, learned of the sideshow, he called Mr. Cherry in for a talk.
“We never had anyone play in the Masters and sing at a local nightclub at the same time,” Mr. Roberts said, as Mr. Cherry recalled in his memoir.
“My reply, without being disrespectful and with a little Texas naïveté, was ‘Mr. Roberts, I have looked at the people playing in this tournament and can’t see anyone else who can sing.’ ”
Quote of the day.
August 21st, 2018I can't wait to become the sysadmin for my fridge.
— Dan Selman (@danielselman) August 21, 2018
(This whole thread is gold, Jerry, comedy gold.)
Obit watch: August 21, 2018.
August 21st, 2018David Rothenberg died on July 15th at the age of 42. His death was not widely reported until late last week.
He worked as a visual artist under the name “Dave Dave” in Las Vegas:
Mr. Rothenberg became a close friend of Michael Jackson, who encouraged him to pursue a career in art. Through brightly colored 1960s-style Pop Art paintings and drawings, he sought to promote positivity, he wrote on his website, particularly through a series called “Lifted.”
“There is a lot that happens in people’s lives, but that doesn’t define them as a human being, it makes them stronger,” Mr. Rothenberg told The Las Vegas Review-Journal in 2016.
Here’s the rest of the story:
He was 6 in 1983 when his father gave him a sleeping pill in a motel room in Buena Park, Calif., near Disneyland, and then doused his bed with kerosene and set it on fire. The attack left burns on more than 90 percent of David’s body. His father, who was said to be in a bitter custody fight with his wife, Marie, then fled.
“He was working at a restaurant in New York, and he had saved $10,000 for this trip to California,” Mr. Rothenberg told The Review-Journal. “On the trip, he was planning to kill me.”
I swear that I’ve written about his father, Charles, previously, but I can’t find that blog entry now. Charles Rothenberg spent seven years in prison for attempted murder before being paroled. He went on to commit other crimes: I recall them being mostly financial. He’s currently serving a 25 to life sentence in California under the three strikes law.
For the historical record: Kofi Annan.
Obit watch: August 16, 2018.
August 16th, 2018The cause was advanced pancreatic cancer, her publicist, Gwendolyn Quinn, said.
Also among the dead: Morgana King, who was somewhat famous as a jazz singer. She was better known, however, as Mama Corleone in the “Godfather” movies.
Herbert Sperling died in early July at a federal prison hospital near Boston. He’d been in prison since 1973.
He also had a reputation for violence.
In 1977, he was indicted on charges of hiring three fellow inmates at the federal penitentiary in Atlanta to murder Mr. [Vincent C.] Papa, whom he suspected of turning police informant. Mr. Sperling was acquitted in the conspiracy, but two other defendants were convicted of fatally stabbing Mr. Papa in the back and chest at least eight times in a prison courtyard.
Mr. Papa had been convicted of choreographing the audacious theft by rogue police officers of tens of millions of dollars worth of drugs from the New York Police Department’s evidence room in Lower Manhattan in the early 1970s and replacing it with bags of flour and cornstarch. The crimes kick-started a consequential corruption investigation of the police.
Much of the heroin had been seized in 1962 in the Bronx from the car in which it had been shipped from the French port city Marseille. The successful investigation in the case inspired the Oscar-winning 1971 movie “The French Connection.”
Mr. Sperling was also suspected in the death of Louis J. Mileto, whom police identified as a courier for the Sperling heroin ring. Mr. Mileto’s frozen, headless and limbless torso was found in 1972 in the trunk of a gutted car in the Hudson Valley. He was identified by his teeth, which were found in his stomach. Investigators said he had swallowed them during a vicious beating.
There’s your telling detail, right there.
More Black Hat/DEFCON 26 updates.
August 15th, 2018- Slides for “A Dive in to Hyper-V Architecture & Vulnerabilities” with Joe Bialek and Nicolas Joly can be found here. (The link on the Black Hat site is still borked.)
- This isn’t an actual DEFCON 26 presentation, but it’s referenced in Vincent Tan’s “Hacking BLE Bicycle Locks for Fun and a Small Profit”, and I want to bookmark it for later: “Blue Picking: Hacking Bluetooth Smart Locks” by Slawomir Jasek.
- Slides for “Ring 0/-2 Rookits: Compromising Defenses” with Alexandre Borges are here.
- Also not a DEFCON presentation, but picked up by way of an Ars Technica story: “Fear the Reaper: Characterization and Fast Detection of Card Skimmers” by Nolen Scaife, Christian Peeters, and Patrick Traynor. In which the authors analyze a bunch of skimmers confiscated by NYPD…and then build a device that can detect skimmers, based on nothing more than the physical properties of how card readers work. Quote of the day: “Security solutions requiring significant behavioral changes are unlikely to be successful.”
- Content for “All your math are belong to us” with sghctoma is here: slides, white paper, and exploit code.
Headline of the day.
August 15th, 2018Your loser update: pre-NFL edition.
August 15th, 2018Actually, this sits at the weird intersection of a couple of things:
You’ve stood by us through it all. We love you for it, and so does @budlight.
These special fridges will unlock celebratory beers when we get our first regular season “W”.#VictoryFridge pic.twitter.com/LgsGNabMpt
— Cleveland Browns (@Browns) August 14, 2018
Which do you suppose is going to happen first: a Browns win, or someone hacks the fridges? My money is on the latter.
Cleveland hackers, you’ve got at least 25 days to prove me right.
More from the Entertainment and Sports Programming Network.
And how about a little musical interlude? We haven’t had one in a while.
DEFCON 26/Black Hat updates: August 14, 2018.
August 14th, 2018I apologize that I wasn’t able to post more coverage over the weekend: as I expected, it turned out to be fun, but packed.
I intended to post this yesterday, but I wasn’t able to find many updates on my lunch hour. Then I got stuck in a gumption trap late in the day at work, and basically came home and collapsed.
In retrospect, that was better, because this story broke late in the afternoon: Caesars Palace security was (in the opinion of at least some DEFCON attendees) a little too aggressive about searching rooms. More from Defiant, a company that was at DEFCON. Statement from Marc Rogers.
Also: badge related coverage if you care. Personally, I don’t need a stinking badge.
Black Hat updates:
- Putting this here for my IBM mainframe friend: “Mainframe [z/OS] Reverse Engineering and Exploit Development” by Chad Rikansrud.
DEFCON 26 updates:
- Haven’t found slides yet, but reference material for “Building Absurd Christmas Light Shows” with Rob Joyce is here.
- Also no slides that I’ve found for “You’d better secure your BLE devices or we’ll kick your butts!” with Damien Cauquil. But: his Twitter feed has an interesting link to “Exploiting BLE Smart Bulb Security using BtleJuice: A Step-by-Step Guide“, a blog post by Vaibhav Bedi (I think). What’s interesting about this post is that it covers the whole process of installing and configuring BtleJuice, “a framework to perform MiTM attacks on BLE devices”. Also: GitHub repo for Btlejack, “everything you need to sniff, jam and hijack Bluetooth Low Energy devices”.
- I’m excited about this one, though I haven’t had time to go through all of it yet: “Ridealong Adventures—Critical Issues with Police Body Cameras” by Josh Mitchell. Slides. five_oh_noes, a body camera scanner. More body camera related stuff.
- GitHub repo for “Breaking Smart Speakers: We are Listening to You” with Wu HuiYu and Qian Wenxiang. At the moment, this includes the presentation slides and Amazon Echo exploit code.
Pilot error.
August 13th, 2018The Dallas Wings, who are a team in the WNBA, fired their head coach Fred Williams yesterday.
The root cause was apparently not that the Wings have lost eight games in a row: they are 14-17 so far this season, and could conceivably make the playoffs. The root cause appears to have been that Mr. Williams and the team president/CEO got into “a postgame altercation”. It isn’t clear to me if punches were thrown or exactly what the nature of the altercation was: either it was serious enough that CEO Greg Bibb felt compelled to fire Williams before the season ended, or (possibly) Mr. Bibb is just a little oversensitive.
In any case, the Wings are still one game ahead of…that’s right, the Las Vegas Aces.
(Apologies for linking to ESPN, but the Dallas paper was really obnoxious about ad blockers. I couldn’t find any mention of this in the Statesman or HouChron.)
Obit watch: August 13, 2018.
August 13th, 2018V.S. Naipaul, noted author.
Dr. Richard Jarecki. He was most famous for hacking roulette:
He and his wife honed his technique at dozens of casinos, including in Monte Carlo; Divonne-les-Bains, France; Baden-Baden, Germany; San Remo, on the Italian Riviera; and, briefly, Las Vegas. He became a regular in San Remo, where he had lucrative runs over several years.
By 1969 he had become “a menace to every casino in Europe,” Robert Lardera, the San Remo casino’s managing director, told The Morning Herald.
“I don’t know how he does it exactly, but if he never returned to my casino I would be a very happy man,” Mr. Lardera said.
According to the NYT, his technique basically amounted to painstaking long term observation of thousands of spins, looking for roulette wheels with biases, and then exploiting those biases.
DEFCON/Black Hat updates: round 2.
August 9th, 2018Another Ars story based on another Black Hat panel:
The presentation in question is “Understanding and Exploiting Implanted Medical Devices” by Billy Rios and Jonathan Butts. No slides or white paper yet, so I don’t want to comment very much. But: I do also want to point out this article, “The $250 Biohack That’s Revolutionizing Life With Diabetes“. Why? Well…
Some additional interesting looking work:
- “TRITON: How it Disrupted Safety Systems and Changed the Threat Landscape of Industrial Control Systems, Forever” by Andrea Carcano, Marina Krotofil, and Younes Dragoni. “In 2017, a sophisticated threat actor deployed the TRITON attack framework engineered to manipulate industrial safety systems at a critical infrastructure facility. This talk offers new insights into TRITON attack framework which became an unprecedented milestone in the history of cyber-warfare as it is the first publicly observed malware that specifically targets protection functions meant to safeguard human lives.” Slides. White paper.
- “There will be Glitches: Extracting and Analyzing Automotive Firmware Efficiently” by a whole bunch of people.
- And it just wouldn’t be a security conference in 2018 without a Tesla attack: “Over-the-Air: How we Remotely Compromised the Gateway, BCM, and Autopilot ECUs of Tesla Cars” by Ling Liu, Sen Nie, Wenkai Zhang, and Yuefeng Du. White paper is at the link: slides are broken.
That’s all I’ve been able to turn up today. More tomorrow, I hope.
Black Hat 2018/DEFCON 26 0 day updates.
August 9th, 2018Some of yesterday’s Black Hat presentations:
- “Stress and Hacking: Understanding Cognitive Stress in Tactical Cyber Ops” by Celeste Paul and Josiah Dykstra.
- “Reversing a Japanese Wireless SD Card – From Zero to Code Execution” by Guillaume Valadon. And here’s the GitHub repo.
- “Mental Health Hacks: Fighting Burnout, Depression and Suicide in the Hacker Community” by Christian Dameff and Jay Radcliffe.
- “Open Sesame: Picking Locks with Cortana“. “Exploiting the ‘Open Sesame’ vulnerability attackers can view the contents of sensitive files (text and media), browse arbitrary web sites, download and execute arbitrary executables from the Internet, and under some circumstances gain elevated privileges.”
Some others that I didn’t get to the first time around:
- “Software Attacks on Hardware Wallets” by Alyssa Milburn and Sergei Volokitin. “…we show how software attacks can be used to break in the most protected part of the hardware wallet, the Secure Element, and how it can be exploited by an attacker.” Slides. White paper.
- “Screaming Channels: When Electromagnetic Side Channels Meet Radio Transceivers” with a whole big bunch of folks. “…we show that it is possible to recover the original leaked signal over large distances on the radio. As a result, variations of known side-channel analysis techniques can be applied, effectively allowing us to retrieve the encryption key by just listening on the air with a software defined radio (SDR).” Slides. White paper.
Ars Technica has a story up in advance of Justin Shattuck’s “Snooping on Cellular Gateways and Their Critical Role in ICS” presentation later today:
There are a couple of other presentations from yesterday that sound interesting on second look, but the links to them are currently broken. Also, I haven’t had a chance to read through all of these yet: I did give a quick skim to “Stress and Hacking” and “Reversing a Japanese Wireless SD Card” and look forward to a more careful read of both.
I think I’m going to try to post a second update later this evening if the broken links are fixed and/or new content is available. We should also be getting close to the point where the DEFCON 26 media server has preliminary versions of the presentations up…
Edited to add: DEFCON 26 presentations are now live on the DEFCON media server.
You’re going down in flames, you tax-fattened hyena! (#51 in a series)
August 8th, 2018Personally, I kind of hope Rep. Collins turns out to be innocent, and it was a dingo who gave the stock tips.