23 November 2010

M-Pesa, SSL snoopsM-Pesa, Cloud Cracking

M-Pesa
since 2007, Kenya ... phone technology..
..M-Pesa ...those without a bank account to transfer funds .. a text message.
..Vodafone and Safaricom...Pesa is Swahili for money.
50% use the service to send money to..relatives, to pay for shopping..taxi ride ..
..
"The bank in my phone"
..register with Safaricom at an M-Pesa outlet... load money onto their phone. ..sent onto a third party by text message.
The recipient takes the phone to their nearest vendor,... pick up the cash.
..Mr Makusi says he no longer has to worry about being mugged while carrying cash.
..Seema Desai, director of the Mobile Money for the Unbanked (MMU)..
..Nick Hughes and Susie Lonie.. M-Pesa. .. Economist Innovation award..
...payment to the thousands of small one or two-cow milk producers.. decided to create a payment system using M-Pesa.
...Smart and Globe were active on a smaller scale in the Philippines in 2002
...March 2010 28.59bn (KES) $351m) was transferred using the service.
..launched in Tanzania, Afghanistan and now South Africa, with trials underway in India.
..
One company that does let you pay with your mobile is Boku...buy virtual money..??? 65 countries..

NFC:
Japan and South Korea ..in use for several years
Verizon, AT&T, and T-Mobile.. NFC system called Isis by 2012,
..Google Gingerbread smartphone, will have NFC technology
bbc
................................
November 17, 2010
By ANTONY KARANJA in DALLAS TEXAS

The Bill and Melinda Gates Foundation has committed $500 million (Sh40 billion) over five years
....$4.8 million ..to expand M-Pesa into Tanzania through .. Vodafon..
..helped Kenyans cope with disasters better.
..ShoreBank Int..BRAC Bank .. Bangladesh will receive $10 million..go into introducing bKash..a mobile money ..
nation
________________________________________
SSL snoops

crypto
24March2010
A paper published today by Chris Soghoian and Sid Stamm [pdf] suggests that the threat may be far more practical than previously thought. They found turnkey surveillance products, marketed and sold to law enforcement and intelligence agencies in the US and foreign countries, designed to collect encrypted SSL traffic based on forged "look-alike" certificates obtained from cooperative certificate authorities. The products (apparently available only to government agencies) appear sophisticated, mature, and mass-produced, suggesting that "certified man-in-the-middle" web surveillance is at least commonplace and widespread enough to support an active vendor community. Wired's Ryan Singel reports in depth here.
http://files.cloudprivacy.net/ssl-mitm.pdf
pdf
http://www.wired.com/threatlevel/2010/03/packet-forensics/\
Law Enforcement Appliance Subverts SSL
marketing internet spying boxes to the feds. The boxes were designed to intercept those communications — without breaking the encryption — by using forged security certificates, instead of the real ones that websites use to verify secure connections. To use the appliance, the government would need to acquire a forged certificate from any one of more than 100 trusted Certificate Authorities.

Verisign has never issued a fake SSL certificate, and to do so would be against our policies,” said vice president Tim Callan.

___________________________________________

Cloud Cracking

..Amazon EC2 "Cluster GPU Instances": ..the power of two NVIDIA Tesla “Fermi” M2050 GPUs....
33.5 EC2 Compute Units (2 x Intel Xeon X5570, quad-core “Nehalem” architecture)2 x NVIDIA Tesla “Fermi” M2050 GPUsAPI name: cg1.4xlarge

GPUs are known to be the best hardware accelerator for cracking passwords, so I decided to give it a try: How fast can this instance type be used to crack SHA1 hashes?

Using the CUDA-Multiforce, I was able to crack all hashes from this file with a password length from 1-6 in only 49 Minutes (1 hour costs 2.10$ by the way.):
http://stacksmashing.net/2010/11/15/cracking-in-the-cloud-amazons-new-ec2-gpu-instances/
[cracking a hash is 1 thing, cracking a hash with a useful message is another]

_____________________________

arduino "smart card" or smartcard reader
arduino 8 bit controller - toys take over the world
__________________________
how to read SLE4442 smart card
com
______________________
From 64-bit Hexadecimal Representation To Decimal Floating-Point
cs
___________________
Engineers at the University of Kitakyushu have built this red snapper robot. Intended for wildlife surveys, this robot sports an array of sensors as well as a hand painted silicon body. It is decidedly more realistic looking than the Robofish and the Essex University robot fish.
aaa
botjunkie
watch
_________________________________________________________________________
Web Tech
One of the compelling reasons to use JSON instead of XML in current web applications are the imposed security restrictions in modern browsers; JSON can actually be retrieved from remote websites without too much trouble (using jsonp) while XML requires one to jump through a number of loops (such as a local proxy). Go figure!
http://norman.walsh.name/2010/11/17/deprecatingXML
______________________________
MasterCard Tap & Go
..New Zealand's first "tap and go" credit cards ..tomorrow..
..ANZ's Rugby World Cup MasterCards ..< $80 ....two seconds....terminals .. in Auckland's Eden Park and Wellington's Westpac Stadium.."corridors" of retailers around the stadiums.. protected by MC's "zero fraud liability" protection, .. ..has already been issuing prepaid and reloadable MasterCards with the embedded antennae, .. not been telling customers about the ..contactless feature. ....83 million MasterCard contactless cards on issue worldwide___________________________ stuff
_________________________________________

No comments:

Post a Comment