OpenSSH Client Bug Leaks Memory Contents

A newly revealed bug in the OpenSSH client from versions 5.4 through 7.1 allows memory contents to be read by malicious servers (archived). The vulnerability exists in code that allows "roaming" which was added to the OpenSSH client but not the OpenSSH server. Patches which remove the roaming code from the OpenSSH client are available.

Intel Skylake Brings Optimized #ROWHAMMER Exploit

In spite of marketing that Intel's latest Skylake family of chips would be more resistant to the Rowhammer exploit through use of DDR4 memory, it has come out that not only does Rowhammer survive (archived), exploiting it is more optimizable than ever (archived) thanks to the new clflushopt instruction. Remember to watch your bits and be selective in the code and hardware you choose to run.

Zero-Conf Shenanigans Lead To Peter Todd Reddit Ban

For demonstrating the absolute insecurity offered by unconfirmed Bitcoin transactions, Peter Todd was suspended from Reddit. Peter Todd, without using any script hash shenanigans mundanely sent a transaction with a low fee which was followed by a transaction with a higher fee using the same inputs. Miners opted to mine the transaction with higher fees as they often tend to. While many try to use unconfirmed Bitcoin transactions as a part of various pseudo business practices, actual uses demanding Bitcoin also demand the commitment of complete transactions to the blockchain.

Deputy Arrested For Dropbox Child Porn

Greene County Missouri Sheriff's deputy Juan T. Jones was arrested Wednesday for possessing child pornography on his account with cloud storage provider Dropbox (archived). Jones reportedly admitted to spending at least the last 10 years viewing and exchanging child pornography online while only spending the past two years as a Sheriff's Deputy in Greene County. This means that the Sheriff's department hired a man who already had been viewing child pornography for 8 years by the time he became a deputy. "Law enforcement" seems to be a disturbingly popular career field for pedophiles.

Paxful Gets Desperate, Priced Out Of Bitcoin

Paxful, a website that claims to do "peer to peer" matching of Bitcoin buyers and sellers, issued a desperate plea on their blog (archived) threatening to move to an altcoin as they get priced out of Bitcoin. Because Paxful specializes in facilitating very small trades any pricing of transaction fees in an actual market obliterates their market niche, and Bitcoin is definitely moving towards a healthy market for block inclusion fees. Paxful claims to: Continue reading