Tuesday, February 22, 2011

Greenest cars: Natural gas Honda Civic GX, Nissan Leaf electric and, just barely, Chevrolet Volt


For a list of the greenest 2011 model-year vehicles, there are sure a lot of traditional gasoline engines among the top 12 cars ranked by the American Council for an Energy-Efficient Economy.
The council's 14th annual ratings of the most eco-friendly cars on the market include internal combustion models such as the Smart Fortwo, the Ford Fiesta and the Hyundai Elantra.
The natural gas-powered Honda Civic GX topped the list for an eighth straight year, with a score of 54, followed by the new all-electric Nissan Leaf. Other vehicles considered to be the greenest of the crop included the hybrid Toyota Prius and the hybrid electric Chevrolet Volt, which squeaked into the last spot.
The electric version of the Smart Fortwo would have pulled in a score of 60, but with only 250 units of the 2011 model available in the U.S. (and then only on a trial basis), the car didn't meet sales requirements for the list.
"Vehicles running on electricity emit nothing from the tailpipe, but their 'upstream' emissions can be substantial, depending on where they're charged," said Therese Langer, the organization's director. "As U.S. power generation becomes cleaner, these vehicles' scores will rise."
The battery manufacturing and disposal processes - which can be emissions-laden and toxic - also were factored into the calculations and knocked electricity-dependent vehicles down a few rungs.
Diesel vehicles missed out entirely. Other talked-about cars, such as the electric Tesla Roadster, didn't make the cut.
The list of gas guzzlers - known as the "meanest" - included heavy trucks and sport utility vehicles instead of the rash of European sports cars that has dominated in the past. Still, the Bugatti Veyron, one of the most expensive cars in the world, led with a score of 19.
More information: See the full list at http://www.greener … greenest.htm

SUBSCRIBE TO BLOG BY: EMAIL
:

China blocks microblogs for 'Jasmine Revolution'

China has suspended searches for content on the country's popular microblog, an apparent move to stifle mention of a "Jasmine Revolution" that was to be staged in Chinese cities on Sunday.
On Sunday afternoon, searches in Chinese for the word "Jasmine" had been blocked on a Twitter-like service operated by Sina. But by the evening, Sina had appeared to suspend searches for all content on the microblog, only allowing users to query for screen names, events and other criteria. Another microblog operated by Tencent also blocked searches relating to the word "Jasmine" or "Jasmine Revolution".
Mention of a "Jasmine Revolution" appear to have begun on the Web, telling Chinese users to demonstrate in 13 cities across the country, including the capital Beijing. The call for the demonstrations seem to be inspired by the anti-government protests in Egypt and Tunisia, but it's unclear who or what group started it. A Chinese site at Boxun.com was reportedly the first to post the call to protest.
China's Internet blocking extended to other social networking websites in the country. Renren.com, a popular Facebook-like service, would not allow users to post using the words for "Jasmine Revolution." Such attempts returned a message, "Please do not release politically sensitive content, salacious content, business advertisements or any other inappropriate content."
Along with the Internet censorship, China has responded to the call for protests by reportedly detaining activists and increasing the number of police. As of Sunday evening, it appeared that no real protests had materialized.
The censorship on China's microblogs has become increasingly more restrictive in the past weeks since the anti-government protests erupted in Egypt last month. The Sina microblog and others had blocked searches for the word "Egypt".
Earlier this week, searches in Chinese for "Hillary" and "Hillary Clinton" were blocked on the Sina microblog. The move seemed to be in response to a speech U.S. Secretary of State Clinton gave calling for governments like China to end Internet censorship.
China has the world's largest Internet population at 457 million users. The country has 63 million microblog users, according to the China Internet Network Information Center.

SUBSCRIBE TO BLOG BY: EMAIL
:

It's a Hoax: Anonymous Did Not Threaten Westboro Baptist Church


Based on its recent successes taking on the considerable forces aligned against Wikileaks, and its ability to take down HBGary--an information security firm--in a matter of hours, you do not want to be on the radar of the hacking collective known as "Anonymous". Perhaps that is why an apparent ultimatum from Anonymous to the Westboro Baptist Church (WBC) is making headlines. Problem is--it's a hoax.
Let's rewind a bit. First, a little history on Westboro Baptist Church. WBC is run by one Fred Phelps and has made a name spewing vile, bigoted trash in the name of God. It owns the domain godhatesfags.com, and regularly organizes protests picketing the funerals of fallen soldiers as evidence that some higher power is taking revenge on our nation in response to rampant homosexuality. WBC also praised the Tucson shooter and planned to picket the funeral of 9-year old Christina Taylor Green, but Arizona passed a law blocking the protest.
On February 16, an open letter to WBC claiming to be from Anonymous declared that enough is enough. The letter states that--although Anonymous is a staunch defender of the freedom of speech--WBC has crossed the line too often, and gives the church an ultimatum to cease and desist its activities and take down its websites. It ends with an ominous warning, "Should you ignore this warning, you will meet with the vicious retaliatory arm of ANONYMOUS: We will target your public Websites, and the propaganda and detestable doctrine that you promote will be eradicated; the damage incurred will be irreversible, and neither your institution nor your congregation will ever be able to fully recover."
WBC accepted the challenge and told its faceless attackers to "bring it". On February 20, however, an open letter posted on AnonNews claimed the threat was not sent by Anonymous in the first place. It asserts that the threat is a hoax, and even goes so far as to suggest WBC is behind the hoax just to make headlines. If so, it worked.
The Anonymous press release goes on to chastise the media for taking the hoax bait so quickly, and directs hackers in the Anonymous collective to abandon any attacks against WBC and steer away from what it claims is a trap.
The curious part now is--who perpetrated the hoax? Was it the WBC just playing on the notoriety of Anonymous for some headline whoring? Was it a faction within Anonymous that really backs the initial threat and would like to take down WBC? Was it anti-Anonymous forces hoping to dare the hacking collective to take on a knife fight so it could lure its members into some sort of honeypot designed to trap them and track them down?
Based on Anonymous' track record, WBC dodged a bullet. Had Anonymous chosen to "bring it", I don't believe WBC would like the outcome. The rest of us might, though.

SUBSCRIBE TO BLOG BY: EMAIL
:


Advanced Zeus Trojan Hits Polish ING Customers

A version of the Zeus malware that intercepts one-time passcodes sent by SMS (Short Message Service) is targeting customers of the financial institution ING in Poland.
The security vendor F-Secure blogged on Monday about the issue, which was analyzed on the website of security consultant Piotr Konieczny.
F-Secure wrote that it appears to be the same style of attack found by the Spanish security company S21sec last September, which marked a disconcerting evolution in Zeus, one of the most advanced banking Trojans designed to steal passwords.
Zeus has changed its tactics, since some banks are now using one-time passcodes sent by SMS to authorize transactions performed on a desktop machine. First, attackers infect a person's desktop or laptop. Then, when that person logs into a financial institution such as ING, it injects HTML fields into the legitimate Web page.
Those fields ask for a person's mobile phone number and the model of their phone. When that information is entered, the attacker sends an SMS leading to a website that will install a mobile application that intercepts SMSes and forwards messages to another number controlled by the attackers. The Zeus mobile component will work on some Symbian and Blackberry devices.
Once that setup is complete, the attacker can simply do a transfer whenever it is convenient, such as when an account has just received a deposit. An attacker can log onto the account, receive the SMS code and begin transferring money.
ING officials when contacted in the Netherlands on Monday afternoon did not have an immediate comment.
The SMS ability of Zeus has prompted vendors such as Cloudmark to warn about how SMS spam -- or SMS messages designed to enable other malware -- are a growing threat. Cloudmark sells a system to operators that analyzes SMS messages and can filter ones that have spam or other offensive content.

SUBSCRIBE TO BLOG BY: EMAIL
:


A wealth of molecules in an extreme galaxy


A Hubble image of the galaxy Arp 220, the brightest object in our local universe. A team using the Submillimeter Array studied the gas component of this galaxy, and concluded that bursts of star formation power its dramatic energetics. Credit: NASA and Hubble
Arp 220 is the closest galaxy to the Milly Way with an extreme luminosity, defined as being more than about 300 times that of our own galaxy. Some dramatic galaxies have values of luminosity ten times brighter still. Astronomers are still piecing together the reasons for these huge energy outputs, while sorting out why our own galaxy is so modest.
The two primary suspects for the energetics are bursts of star formation that produce many hot young stars, and processes associated with accretion of material onto a supermassive black hole at a galaxy's nucleus. Arp 220 is the closest example, and one of the best places to probe these scenarios.
A team of astronomers including SAO astronomer Jun-Hui Zhao have used the Submillimeter Array (SMA) to obtain the first unbiased galaxy survey of molecular and atomic lines using a telescope array. They covered a complete, large wavelength interval in the millimeter regime that is accessible through Earth's atmosphere. The team reports finding seventy-three spectral features from fifteen molecular species in this survey band. A remarkable 28% of the total flux from this galaxy in this band is emitted by these molecules. The SMA also obtains images of the galaxy at each of the many wavelengths.
The results are consistent with Arp 220's luminosity being driven primarily by star-formation. The chemistry of the galaxy derived from the observations also leads to this conclusion, with species normally enhanced by star formation clearly detected. Moreover, it appears one such burst of activity is currently underway. The team estimates, for this extreme galaxy, that several million regions of activity are localized within a relatively small volume (a few thousand light-years) around the nucleus. The new results are an important improvement in our understanding of what powers extreme galaxies, and how they differ from the Milky Way.
Provided by Harvard-Smithsonian Center for Astrophysics

SUBSCRIBE TO BLOG BY: EMAIL
:


Monday, February 21, 2011

Your New Facebook Friend Might Be A Spy

The war between security firm HBGary and Anonymous reveals a new tactic: using fake social network profiles to gather information.

Is that new friend really your friend, or just someone pretending to be your friend so he can spy on you? No, I'm not just being more paranoid than usual. This really does happen - especially if you're a member of an anonymous collective determined to do battle with the forces of corporate evil (not to mention Tom Cruise, Soulja Boy, and your mom).
The ongoing battle between Anonymous and the security wonks who are trying to take it down has revealed a new weapon: Creating fake profiles on social networks to trace out the connections between you and your comrades.
[ See also: Facebook ads use your face for free ]
In what proved to be a colossally dimwitted move, HBGary Federal executive Aaron Barr bragged to the Financial Times about his success in infiltrating Anonymous:
Mr Barr said he had collected information on the core leaders, including many of their real names, and that they could be arrested if law enforcement had the same data... But he does not plan to give specifics to police, who would face hurdles in using some of the methods he employed, including creating false Facebook profiles.
In other words, to "catch" Anonymous, Barr had to resort to methods the police could not - violating Facebook's terms of service in the process.
OK. Maybe sometimes you need to bend the rules to get the bad guys (assuming you consider Anonymous the bad guys - in this scenario it's increasingly unclear.) But bragging about it?
Barr might just as well have smeared peanut butter all over his body and jumped into the elephant cage at the San Diego Zoo.
Anonymous was not amused. And the collective decided to exact revenge in the usual manner - by pawning every digital device in Barr's realm, including his Twitter account, his iPhone, HBGary's Web site and its corporate servers. They defaced the site with a taunting letter and posted more than 40,000 HBGary emails on Pirate Bay. Among other things, those emails revealed the details of a plot cooked up by HBGary on behalf of Bank of America to take down WikiLeaks by subverting reporters sympathetic to it.
But the emails also reveal the details of how Barr "infiltrated" the group. An excellent report in Ars Technica goes into further detail on Barr's methods:
Barr had been interested in social media for quite some time, believing that the links it showed between people had enormous value when it came to mapping networks of hackers-and when hackers wanted to target their victims. He presented a talk to a closed Department of Justice conference earlier this year on "specific techniques that can be used to target, collect, and exploit targets with laser focus and with 100 percent success" through social media.
His curiosity about teasing out the webs of connections between people grew. By scraping sites like Facebook or LinkedIn, Barr believed he could draw strong conclusions, such as determining which town someone lived in even if they didn't provide that information. How? By looking at their friends.
"The next step would be ok we have 24 people in that list Auburn, NY as their hometown," he wrote to the programmer implementing his directives. "There are 60 other people that list over 5 of those 24 as friends. That immediately tells me that at a minimum those 60 can be tagged as having a hometown as Auburn, NY. The more the data matures the more things we can do with it."
The same went for hackers, whose family and friends might provide information that even the most carefully guarded Anonymous member could not conceal. "Hackers may not list the data, but hackers are people too so they associate with friends and family," Barr said. "Those friends and family can provide key indicators on the hacker without them releasing it..."


As the emails reveal, Barr wasn't actually interested in "doing good" by taking down Anonymous. He picked that group as a test case to prove that parsing publicly available information from social networks was enough to expose their identities. Barr was solely interested in getting publicity for HBGary and driving business to it in the process.
Well, he succeeded on the publicity part. Drumming up business, not so much.
Using social networks to gather intelligence about people can quickly lead you down the rabbit hole - and you often end up chasing the wrong rabbit. Barr's colleagues doubted his conclusions internally, and even Anonymous said he was way off base, including people as "key members" who were tangentially related to the group at best.
Barr has done us a public service though, by reminding us (yet again) that when we use social networks, we often end up revealing far more than we may think - and that information can be used against us.

SUBSCRIBE TO BLOG BY: EMAIL
: