Thứ Hai, 15 tháng 1, 2018

Youtube daily Jan 15 2018

Every now and then we hear and read about "critical security" issue's in the software

that we use in our day to day lives.

These security holes are caused by tiny bugs in the code and can lead to devastating results:

people can hack into your computer, steal your information or even hold it hostage.

Luckily though we can fix these issue with a software update.

But on the first of June, 2017 researcher working for Google's Project Zero found

two major security flaws in modern processors.

You know, the brains of your computer, phone, tablet, TV and what not.

The flaws allows any program to read sensitive information from memory.

Yikes!

The bugs are called Meltdown and Spectre and because they're so sensitive, Google decided

to keep it a secret until vendors had come up with workarounds that would protect us.

So let's take a look at how these bugs work, but before we can do that, let's quickly

go over some basic concepts.

As you know a CPU is the brain of all of our devices.

A processor is responsible for executing all the instructions that our operating system

and our programs give it.

How fast a processor is, depends on its clock speed.

The higher this is, the more work your processor can do per second.

So for a while, chip makers were in a fight to keep increasing the clock speed.

They however reached a ceiling when they hit the 3-4GHz range.

Increasing it further was impossible, so instead chipmakers had to get creative and they came

up something called "speculative" execution.

Basically it means that the processor will guess what the outcome of an instruction will

be and execute all the subsequent steps in the background.

More on that later!

The last thing we need to understand is memory.

Our devices have two types of memory: the main system memory, also called RAM and the

cache memory in the processor.

The CPU needs to constantly read and write data from the main memory.

However the main memory is way slower then the CPU.

So chipmakers added a small cache on the processor itself to store the data that it's working

with.

Everytime the processor needs something from the main memory, it copies it, stores it in

its cache and reads it from there.

Okay, so now that we know these basics we can start explaining the Meltdown bug!

Our operating systems stores sensitive information in the main memory of our devices.

Think about your WiFi key for instance.

They store this data in protected memory and CPU's make sure that no one has access to

this part of the memory, except the operating system itself.

So far so good, except that they don't enforce this rule when they are speculating!

And that leaves the door open for exploits!

Let's assume that you visit a website that wants to steal your WiFi password, which for

now is safely stored in protected memory.

First the attacking website has to make sure that your CPU's cache doesn't contain

your actually WiFi password.

To do that it reads and writes some random data to the main memory.

Remember: when you access the main memory, the processor keeps a copy of the data in

it's own cache for faster retrieval.

It also loads an image from the internet that will be used later on.

Now that your CPU's cache is filled with random data, the website tries to read the

first letter of your WiFi password from the protected memory with code that might look

like this.

If your password starts with the letter S, the site reads the first pixel of the image

into memory.

But wait a minute!

The CPU will prevent the website from accessing the protected memory!

But because the CPU speculates, it might have executed this code in the background and didn't

tell us about it.

If your WiFi password indeed starts with the letter S, the CPU will execute our "readPixel"

command while it's speculating.

And when the CPU reads this pixel from the main memory, it puts a copy of it in it's

cache.

All the website has to do now is run a second program that times how long it takes to read

that pixel.

If it happens super fast we know that the pixel was in the CPU's cache and this could

have only happened when the CPU was speculating and only if our password starts with the letter

S. If it's not so fast, the data comes from the main memory and then we know the password

doesn't start with an S.

It's clear how this technique can be extended to not only read the first character, but

to read your full password from protected memory.

In fact, with Meltdown it's possible to read sensitive data at speeds of up to half

a megabyte per second!

(503 KB/s)

Almost all Intel processors and a handful of ARM processors are susceptible to this

bug.

Only AMD chips are resilient because they don't speculate when protected memory is

being accessed.

However, this is only the tip of the ice berg.

Let's move on to Spectre, a weakness that is very similar to Meltdown but affects all

modern CPU's, not just the ones from Intel!

While Meltdown only allows programs to read protected memory, Spectre allows malicious

programs to read the memory from any other program running on your system!

To give a concrete example: a website could use Spectre to read the contents of another

browser tab - one where you might be logged in to your bank account.

This becomes an even bigger problem in professional situations.

Public clouds like AWS, Google Cloud and Microsoft Azure are rushing to implement safeguards

against Spectre and Meltdown.

If left unpatched it would allow one customer's virtual machine to steal data from another

customers VM.

Spectre is more difficult to patch compared to Meltdown and that's also why they named

it "Spectre".

A ghost that will haunt us for quite some time…

Now that we know how the exploits work, what can we do about them?

Patching processors isn't possible because we can't change hardware that has already

shipped.

Instead we have to mitigate it with software updates.

There are already patches available for Windows, MacOS and Linux, so make sure that you have

the latest versions installed.

Mobile devices also need to be patched.

Updates for iOS are already available and also Google has patches available for Android,

however they depend on the manufactures to make the updates available to users.

Do definitely check with your vendor!

And finally: make sure that the rest of your software is up-to-date as well.

Browser's like Firefox and Chrome are also offering patches to mitigate the risk of websites

stealing sensitive information.

So that was it for this video BUT don't worry, there are plenty of other videos on

my channel that you can check out.

And as always: thank you very much for watching!

For more infomation >> Meltdown & Spectre - Simply Explained - Duration: 6:40.

-------------------------------------------

Black Lightning | Cress Williams "Jefferson Pierce" Interview | The CW - Duration: 2:26.

For more infomation >> Black Lightning | Cress Williams "Jefferson Pierce" Interview | The CW - Duration: 2:26.

-------------------------------------------

6 Things You Didn't Know About Martin Luther King Jr. - Duration: 2:11.

What's up guys, Frazier here for Complex.

We're in for another greatly appreciated long weekend but more important, it's Martin

Luther King Jr Day, where we salute one of our nation's greatest and most important

figures for his efforts and legacy.

We all know the hallmarks, the I Have a Dream Speech, his march on Washington, Selma, the

Nobel Peace Prize etc.

So since we're all well versed in his legendary feats, instead this time around we thought

we'd spotlight a few interesting but little known facts about Martin the man.

HE ALMOST TOOK HIS OWN LIFE

At age 12, Martin tried to commit suicide, because he blamed himself for his Grandmother's

death.

The two were very close, but Martin learned of her death by heart attack while attending

a parade against his parents' wishes.

He was so distraught that he tried to kill himself by jumping from a second-story window.

ONE OF STEVIE WONDER'S MOST CLASSIC SONGS WAS MADE FOR HIM

Stevie Wonder wrote his famous "Happy Birthday" song, now a staple of black birthday parties,

for MLK.

Stevie was one of the people who campaigned for MLK Day, and the single served as his

PSA to spread the cause.

SOMEONE ELSE DIED THE SAME NIGHT HE DID

Martin wasn't the only person who died at the Lorraine Hotel on April 4 of .68.

The woman the hotel was named after, Lorraine Bailey, actually saw King get shot and suffered

a fatal heart attack as a result.

HE INFLUENCED THE ORIGINAL STAR TREK

Martin convinced Nichelle Nichols to stay on Star Trek as Uhura when she considered

quitting after season one.

According to Nichols, Martin advised her to stay because Uhura's character, an intelligent

officer and equal to her white counterparts, broke the stereotype of the way black people

were typically portrayed in film and TV at the time.

It's pretty dope in retrospect when you think about Uhura's legacy to the people

who list her as an inspiration, like Whoopi from the acting side, who says she reacted

to Uhura with "There's a black lady on TV and she ain't no maid!" to Ronald McNair

the second black person in space.

MLK DAY WAS MET WITH RESISTANCE

Martin Luther King Day wasn't officially observed in all 50 states until 2000.

Some southern states even combined it with Robert E. Lee Day, which is mind-blowing.

These days though, It's also observed in Toronto and Hiroshima.

For more infomation >> 6 Things You Didn't Know About Martin Luther King Jr. - Duration: 2:11.

-------------------------------------------

Film Factory quick tutorial: "Davinci Resolve 14 how to disable / enable grades ( bypassed nodes )" - Duration: 0:39.

Ctrl + D enable/disable current node

Alt +D enable/disable all nodes

Shift +D enable/disable bypassed

For more infomation >> Film Factory quick tutorial: "Davinci Resolve 14 how to disable / enable grades ( bypassed nodes )" - Duration: 0:39.

-------------------------------------------

LA VERDAD SOBRE LA MOTIVACIÓN EXPRESS - Duration: 4:03.

For more infomation >> LA VERDAD SOBRE LA MOTIVACIÓN EXPRESS - Duration: 4:03.

-------------------------------------------

Music For Relaxing And Sleeping Deeply - Music Therapy & Relaxation - Duration: 4:03:02.

Music For Relaxing And Sleeping Deeply - Music Therapy & Relaxation

For more infomation >> Music For Relaxing And Sleeping Deeply - Music Therapy & Relaxation - Duration: 4:03:02.

-------------------------------------------

You Won't Believe Who Just Got Indicted By Department of Justice — Is Obama Next. - Duration: 3:22.

You Won't Believe Who Just Got Indicted By Department of Justice — Is Obama Next?

I had these unreasonable hopes that once Barack Obama finally left the presidency, we would

never have to hear about him again.

Unfortunately, my naive thinking got the best of me, and I'm stunned that months after

President Trump has taken office, we are still talking about Obama.

I guess it is not too surprising.

I mean, I love to hear about all of the Obama legacies that Trump is obliterating, knowing

that each legacy gone is a win for all Americans.

However, since we are slowly but surely discovering all of the heinous, deep state tactics that

Obama put together prior to his leaving office, in order to stop Trump at every turn, is shocking.

And now another layer of these deep state connections has appeared.

Thankfully, it is in the form of a formal indictment with a potential prison term of

twenty years.

Unfortunately, it's not Obama receiving the charges, but one of his State Department

cronies, Candace Marie Claiborne.

From the US Department of Justice website: A federal complaint was unsealed today charging

Candace Marie Claiborne, 60, of Washington, D.C., and an employee of the U.S. Department

of State, with obstructing an official proceeding and making false statements to the FBI, both

felony offenses, for allegedly concealing numerous contacts that she had over a period

of years with foreign intelligence agents…

"Candace Marie Claiborne is a U.S. State Department employee who possesses a Top Secret

security clearance and allegedly failed to report her contacts with Chinese foreign intelligence

agents who provided her with thousands of dollars of gifts and benefits," said Acting

Assistant Attorney General McCord.

"Claiborne used her position and her access to sensitive diplomatic data for personal

profit.

Pursuing those who imperil our national security for personal gain will remain a key priority

of the National Security Division."

"Candace Claiborne is charged with obstructing an official proceeding and making false statements

in connection with her alleged concealment and failure to report her improper connections

to foreign contacts along with the tens of thousands of dollars in gifts and benefits

they provided," said U.S. Attorney Phillips.

"As a State Department employee with a Top Secret clearance, she received training and

briefing about the need for caution and transparency.

This case demonstrates that U.S. government employees will be held accountable for failing

to honor the trust placed in them when they take on such sensitive assignments"

"Candace Claiborne is accused of violating her oath of office as a State Department employee,

who was entrusted with Top Secret information when she purposefully mislead federal investigators

about her significant and repeated interactions with foreign contacts," said Assistant Director

in Charge Vale.

"The FBI will continue to investigate individuals who, though required by law, fail to report

foreign contacts, which is a key indicator of potential insider threats posed by those

in positions of public trust."

Although I'm glad we're catching these in-house criminals, I cannot wait for the

day that Obama will be next in line for all of his crimes!

What do you think about this?

Please share this news and scroll down to Comment below and don't forget to subscribe

Top Stories Today.

For more infomation >> You Won't Believe Who Just Got Indicted By Department of Justice — Is Obama Next. - Duration: 3:22.

-------------------------------------------

르노삼성 QM3 RE 파노라믹 에디션 모델 출시|조회수4.989.283 - Duration: 3:30.

For more infomation >> 르노삼성 QM3 RE 파노라믹 에디션 모델 출시|조회수4.989.283 - Duration: 3:30.

-------------------------------------------

Meditation - Very Powerful Spiritual Music For Deep Relaxation - Duration: 2:03:52.

Meditation - Very Powerful Spiritual Music For Deep Relaxation

For more infomation >> Meditation - Very Powerful Spiritual Music For Deep Relaxation - Duration: 2:03:52.

-------------------------------------------

Stefan Kramer realiza una maravillosa imitación Luis Fonsi - Duration: 7:49.

For more infomation >> Stefan Kramer realiza una maravillosa imitación Luis Fonsi - Duration: 7:49.

-------------------------------------------

Jessica Cediel le prestó su voz a Yayita en la nueva película de -Condorito- - Duration: 3:37.

For more infomation >> Jessica Cediel le prestó su voz a Yayita en la nueva película de -Condorito- - Duration: 3:37.

-------------------------------------------

Selena's Mom admits she's Not Happy about Daughter's Reunion with Justin (16 Jan 2018) - Duration: 1:50.

Selena's Mom admits she's Not Happy about Daughter's Reunion with Justin (16 Jan 2018)

Selena's Mom admits she's Not Happy about Daughter's Reunion with Justin (16 Jan 2018)

Selena's Mom admits she's Not Happy about Daughter's Reunion with Justin (16 Jan 2018)

Selena's Mom admits she's Not Happy about Daughter's Reunion with Justin (16 Jan 2018)

For more infomation >> Selena's Mom admits she's Not Happy about Daughter's Reunion with Justin (16 Jan 2018) - Duration: 1:50.

-------------------------------------------

Dolores O'Riordan: Die Sängerin stirbt mit 46 Jahren! - Duration: 3:54.

For more infomation >> Dolores O'Riordan: Die Sängerin stirbt mit 46 Jahren! - Duration: 3:54.

-------------------------------------------

인후염을 자연적으로 치료하는 법|HYA TV - Duration: 11:08.

For more infomation >> 인후염을 자연적으로 치료하는 법|HYA TV - Duration: 11:08.

-------------------------------------------

MasterChef Latino | Dora cocina sopa de pera y calabacita en MasterChef Latino | Entretenimiento - Duration: 3:48.

For more infomation >> MasterChef Latino | Dora cocina sopa de pera y calabacita en MasterChef Latino | Entretenimiento - Duration: 3:48.

-------------------------------------------

Sindy cocina una torta de tres quesos y conquista a los jueces de MasterChef Latino - Duration: 4:42.

For more infomation >> Sindy cocina una torta de tres quesos y conquista a los jueces de MasterChef Latino - Duration: 4:42.

-------------------------------------------

Roberto Ferrer crea impresionantes piezas de arte con arena - Duration: 2:04.

For more infomation >> Roberto Ferrer crea impresionantes piezas de arte con arena - Duration: 2:04.

-------------------------------------------

MasterChef Latino | Sor Juliana cocina arroz con gandules en MasterChef Latino | Entretenimiento - Duration: 4:06.

For more infomation >> MasterChef Latino | Sor Juliana cocina arroz con gandules en MasterChef Latino | Entretenimiento - Duration: 4:06.

-------------------------------------------

5 Olympic athletes caught cheating at the games - Duration: 3:41.

1.

Dora ratjen : at the 1936 berlin games, Dora ratjen came 4th and went on to win the gold

medal in Europe athletic championship breaking the record of high jump, but it was later

discovered that Dora had an advantage over the other women Dora was a men there was a

confusion at birth as his genitals was very small and he was raised as a woman he noticed

he was different but continued to live as a woman he was arrested for fraud but officials

decided not to proceed with the charge but asked him to return to his original name and

also removed his name from the Olympic records.

2.

East German Female Lugers athlete, ortrun enderleien was part of the women�s loge

team during Grenoble games 1968 Olympics anderlien placed the first winning the gold and her

team mates came second and 4th other athletes became suspicious as the team would arrive

just before the races and leave immediately after the race it was discovered that the

rails of their sleds were heated with chemicals just before the races and this resulted in

faster time as the friction from the ice was reduced the team was disqualified.

3.

Madeline de Jesus: she was a Puerto Rican athlete in track and field at the 1984 Los

Angeles games, during the games Madeline sustained a hamstring injury from one of her jumps (long

jump) as she landed poorly.

Fearing that she would disappoint her team in the next event, she came up with a plan

and switched herself without any ones knowledge, with her twin sister Margret who was present

as a spectator in the stands and had her sister run in her place for the Puerto Rican team

in order for them to advance in the games.

When the team coach found out, he withdrew the team from the finals and revealed the

scam.

4.

Ben Johnson: at the 1988 Seoul games, Canadian sprinter ben Johnson won the gold medal in

the men�s 100 meter dash and broke a world record in the process.

He previously won two bronze medal to improve, a few days later his urine tested positive

for steroids he was stripped of his medals and fell into disgrace when he admitted to

making use of steroids since 1981 he was caught using again in 1993 and was banned for life.

5.

Marion Jones: after winning 2 bronze and 3 gold medals at the 2000 Sydney games, American

track and field athlete Marion Jones was on top of the world as she was the first woman

to win that number of medals in track and field during the span of a single Olympic

games.

Although there were rumors of steroid use, Marion denied any use of banned substances

as she had always passed the drug test.

But in 2007 she admitted to lying to the Federal investigator and that she had been using steroids

much before the Sydney games.

She was stripped of her Olympic medals and was sentenced to six months in prison for

providing a false statement.

Không có nhận xét nào:

Đăng nhận xét