Showing posts with label News. Show all posts
Showing posts with label News. Show all posts

Sunday, March 7, 2010

DHT, PEX and Magnet Links Explained

Recently The Pirate Bay confirmed it would shut down its tracker for good, instead encouraging the use of DHT, PEX and magnet links. This move confounded many BitTorrent enthusiasts, who although wishing to adapt, were confronted with hard to grasp terminology and technology. Time for some explaining.

The Pirate Bay’s recent confirmation that they had closed down their tracker since DHT and Peer Exchange have matured enough to take over, was coupled with the news that they had added Magnet links to the site. This news has achieved its aim of stimulating discussion, but has also revealed that there is much confusion over how these technologies work.

The key thing to understand is that nobody is being forced to use Magnet links or trackerless torrents. While these long-standing technologies may prove to be the future, they will co-exist with tracker-enabled torrenting for quite some time. For now, nobody will be forced to immediately change their existing downloading habits, although it may be wise to switch to a BitTorrent client that is compatible with these technologies.

In an attempt to clear some of the mystique surrounding DHT, PEX and Magnet links we will walk through all three briefly, hoping to assure those who’ve become confused earlier this week.




DHT

Using DHT instead of trackers is one of the things The Pirate Bay is now trying to encourage, and torrent downloads that rely solely on this technology are often referred to as “trackerless torrents.” DHT is used to find the IP addresses of peers, mostly in addition to a tracker. It is enabled by default in clients such as uTorrent and Vuze and millions of people are already using it without knowing.

DHT’s function is to find peers who are downloading the same files, but without communicating with a central BitTorrent tracker such as that previously operated by The Pirate Bay.

DHT is by no means a new technology. A version debuted in the BitTorrent client Azureus in May 2005 and an alternative but incompatible version was added to Mainline BitTorrent a month later. There is, however, a plugin available for Azureus Vuze which allows it access to the Mainline DHT network used by uTorrent and other clients.


Peer Exchange (“PEX”)

Peer Exchange is yet another means of finding IP addresses. Rather than acting like a tracker, it leverages the knowledge of peers you are connected to, by asking them in turn for the addresses of peers they are connected to. Although it requires a “kick start”, PEX will often uncover more genuine peers than DHT or a tracker.


Magnet links

Traditionally, .torrent files are downloaded from torrent sites. A torrent client then calculates a torrent hash (a kind of fingerprint) based on the files it relates to, and seeks the addresses of peers from a tracker (or the DHT network) before connecting to those peers and downloading the desired content.

Sites can save on bandwidth by calculating torrent hashes themselves and allowing them to be downloaded instead of .torrent files. Given the torrent hash – passed as a parameter within a Magnet link – clients immediately seek the addresses of peers and connect to them to download first the torrent file, and then the desired content.

It is worth noting that BitTorrent can not ditch the .torrent format entirely and rely solely on Magnet links. The .torrent files hold crucial information that is needed to start the downloading process, and this information has to be available in the swarm.

Pirate Bay links cf. Mininova links: When the Magnet link specification first came out, in January last year it called for a particular format (“base32 encoded”). The links that EZTV, Mininova and ShareReactor have displayed for some time all conform to that original specification. In May of last year the specification was changed, in favor of “hex encoding”, and that is the format of the links being displayed by The Pirate Bay. Torrent clients should accept either format.


Compatible Clients

All the main torrent clients: uTorrent 1.8.5, Vuze 4.3.0.2, BitTorrent 6.3, BitComet 1.16, and Transmission 1.76 (and others) support Peer Exchange and DHT (via a plugin in the case of Vuze). Neither BitComet nor Transmission yet support Magnet links but Transmission is planning to include Magnet link support in the upcoming 1.8 release. Bearing in mind that no site, including The Pirate Bay, has yet abandoned support for traditional torrent files, there is plenty of time for support to be added.

We hope that this article has cleared some of the smoke that was generated by The Pirate Bay’s announcements earlier this week. There is no need to panic, cry or be angry, and it’s not a problem if you’re still confused after reading this article. Torrents will still be available and aside from some extra downloading options thanks to sites that add Magnet links, nothing drastic will change in the near future.

Read more!

Thursday, January 10, 2008

10 security blunders

While one of the following links is actually from early 2008, they all refer to issues that arose during the year of 2007.

  1. The UK privacy breach: An employee of Her Majesty’s Revenue and Customs Office mailed two CDs containing confidential data on about 25 million UK citizens, including names, addresses, insurance account numbers, and bank account details for claimants in the national child benefit database. These CDs never made it to their destination. Just in case you think someone having your bank account number is no big deal, you should read about what happened to Top Gear TV series host Jeremy Clarkson when he published his account information in a newspaper to “prove” that having someone’s bank account will do nothing for a malicious party. At least Clarkson owned up to the mistake and started advocating disincentives for such poor security practice. I particularly like when he said “we must go after the idiots who lost the discs and stick cocktail sticks in their eyes until they beg for mercy.”
  2. Embassies confuse anonymity with security: Swedish security consultant Dan Egerstad showed that people all over the world, most notably certain embassies, tend to assume that using the Tor anonymizing network means they’re secure. Somehow, they’ve missed the importance of encryption to protect their data. One must wonder why governments are so bad at security. By the way, the Swedish equivalents to the FBI and CIA raided Egerstad’s apartment for undisclosed reasons, accused him of several crimes, then released him without charges.
  3. The iPhone runs everything as root: As Wired put it, IPhone’s Security Rivals Windows 95. This is very bad — and, of course, the root password for the iPhone was cracked in just three days. It had to happen eventually. To be fair, Windows Mobile devices all run everything as the administrative user as well, but this is not exactly unexpected (so it’s less notable). Credit to the fine folks at Metasploit for figuring it out, and figuring out how to make use of that fact.
  4. Sears installs spyware on customer computers: The depth and breadth of harvested data is truly frightening, and you just have to read it to believe it. Do not join the “My SHC Community”. Worse yet, if you follow the update link at the beginning of the article, you’ll find out that Sears (KMart is involved, too) is playing some pretty sketchy games with privacy policy presentation, based on whether the spyware is installed on your system. Considering this example, that’s probably reason enough to avoid ever getting mixed up in any online Sears community, but that’s not all. . . .
  5. Your Sears buying habits may be public knowledge: In short, by joining the Sears “Manage My Home” community, you can search through the Sears purchase history of anyone whose name and address you know. Not only should you avoid joining online Sears communities but, it seems, you should avoid shopping there as well. Apparently, major corporations are as bad as government agencies when it comes to security — especially Sears.

Old News

What follows is a list of older news items, from before 2007, that are still interesting and worth knowing about.

  1. Switching from Unix to MS Windows proves disastrous for air traffic control: A problem with a Microsoft Windows 2000 solution used to replace Unix air traffic control servers required regular restarts — and when the restart was overlooked once, it endangered 800 commercial aircraft in 2004.
  2. MS Windows crash cripples UK government agency: Only a couple months after the air traffic control debacle, almost the entire UK Department of Work and Pensions network crashed. This event was called the biggest crash in public sector history.
  3. The Pentagon improperly redacted text in a declassified document: Text was masked in a PDF by painting black lines over it, as if a physical, hardcopy, paper document had a black marker run over the relevant sections of text. Of course, doing that with Adobe Acrobat tends to leave all the text intact and recoverable, as such black “painting” occurs on a separate document layer. A Greek medical student at Bologna University recovered the obscured text with a couple of mouse clicks in 2005.
  4. The VA privacy breach: More than 26 million US military veterans’ personal data — including names, birthdates, and social security numbers — were taken home by a Veterans Administration employee. As necessitated by Murphy’s Law, the data was stolen (of course). It was stored on an unencrypted drive in the employee’s laptop but, surprisingly, it seems the thieves did not know what they had and the data was not used for identity theft purposes.
  5. Sony may have the worst consumer security record of any corporation: The six-part Boing Boing series on Sony’s “anti-consumer technology” problems makes a compelling case for getting your technology from anyone but Sony. If you thought the 2005 Sony rootkit was the only problem, you haven’t been paying attention — the rootkit installed even if you told it not to, there was a second Sony rootkit, the rootkit remover itself caused security issues, and the RIAA said it’s no big deal because other record labels also install rootkits. Somehow, I do not find that very reassuring

Read more!

Thursday, November 29, 2007

Technology never stops growing... Amazing

Cell Phone


Sprout Umbrella



iPod detachable speakers

Chair/Mat/Bed...

Laptops....


Shoe...


Cellphone...

Umbrella Lights...


Notebook Lamp...

Laptop...

Tablet PC Made Of Wood

USB Flash Drive Watch


Rubik Cube Mp3 Player

Oryx, The Bike From The Future


SkyLift - Boarding System for Aircraft


A Phone That Really Hangs Up


Cellphone Inspired By Chinese Scrolls

BYB Balance Cell Phone (touchscreen)

Dual Music Player That Plays Your MP3 Collection & Your CDs

Nokia 888 Mobile Phone

Read more!

Thursday, November 22, 2007

World's first arrests for 'virtual theft'

Dutch police are to charge five teenagers with "virtual theft" of furniture from rooms in the Habbo Hotel, a popular networking website for youngsters.

Officers believe that the arrest of one online thief, a 17-year-old accused of computer fraud and stealing, and the questioning of four other 15-year olds represents a first for policing on the internet.

An Amsterdam police spokesman confirmed that investigations began after one teenager was accused of stealing £2,800 worth of virtual furniture, paid for with real money but existing only as images on the website.

"We are trying to bring charges of theft. It is a little difficult and new. There has not yet been a judgment in a case like this," said a spokesman.

"The furniture may not be physical objects but because it represents a certain value we think theft is involved."

Habbo users create their own characters, known as avatars, and decorate hotel rooms and play a number of games, paying with credits.

The teenage gang are suspected of moving the stolen furniture into their own online hotel rooms after conning other users out of their login details and passwords.

Habbo Hotel was launched seven years ago by Finnish Internet company Sulake, which now claims the website has 80 million registered users in 31 countries.

The case has raised concerns over security on the Internet and ability of teenagers to spend money online.

One parent posting on www.theregister.co.uk described how his "children went through a phase of near-addiction to this hideous phenomenon".

"Habbo credit can be purchased 'simply' by ringing a premium-rate phone number and their target market generally has easy access to a telephone line for which they don't have to pay," writes David S.

"It doesn't really matter how much these things cost. Mum and Dad's money is essentially 'virtual' anyway, and it can be weeks before the phone bill hits the mat and the dung-heap hits the wind-farm."

Read more!

Open Web proxies, the base for malware attacks

Advertising and click-through fraud is currently topping the list of malicious activity funnelled through open proxy servers, followed by junk email, according to a research project deploying fake open proxies to catch crooks

The research was carried out by the Web Application Security Consortium (WASC) using a network of virtual Apache proxy servers running on VMware and deploying an array of tools to identify, log and block traffic. The project started off with servers in seven countries in January, and has now expanded into 14 countries.

Open proxies are a frequent means by which attackers and scammers cover their tracks, making such traffic difficult to identify and trace. The WASC's approach gives researchers an insight into exactly what is passing through such servers.

When malicious traffic is identified, the honeypot servers block it and feed spoofed information back to the attackers, such as HTTP status codes, according to Ryan Barnett, director of application security training for Breach Security and head of the WASC's Distributed Open Proxy Honeypots project.

Click fraud traffic, employed to distort results from click-throughs to web ads or other commercial links, led malicious activity during the month of October, with 2.6 million requests. That compares to 158,000 requests for the entirety of the January-April period.

Spam followed with nearly two million requests, compared to slightly more than 109,600 in January-April. Most of the attacks are automated, WASC said.

The most serious attacks measured by the WASC's honeypots were designed to implant malicious Javascript code into often legitimate websites. Malicious Javascript is often used to exploit known browser flaws, in order to install malware onto client machines.

The project also noted an extensive scan designed to break into the email accounts of a popular Internet service provider.

The scan, using a method called distributed reverse brute force authentication, is distributed across hundreds of unique email authentication hosts in order to evade detection.

The technique involves checking a large number of different email usernames to see if they match specific common passwords. By "cracking" the username rather than the password, the attackers can evade many ordinary security defences.

Even if the attack doesn't allow the attackers to break into email accounts, it yields a list of valid email accounts that can be used for spamming purposes.

Read more!

Thursday, November 15, 2007

Bug Labs: Open-sourcing hardware

Bug Labs, a start-up from New York City, hopes to bring the goodness of open source to hardware with a modular device that users can customize to their own specifications.

At the core of Bug Labs business model is a hardware appliance called the “Bug.” About the size of an iPhone, the Bugbase device is a fully featured Linux PC (IT Management) with ports that allow up to four modules to be fitted in place.

An excerpt from Technology Review:

Bug Labs CEO, Peter Semmelhack, says that the Bug’s design was inspired by the Lego set. Users, he says, should be able to snap pieces in and out without worrying about the device freezing up, and the pieces should be attractive and fun to play with. To that end, the company has developed the Bug module interface, open-source software designed to recognize modules when they are snapped into ports, keep the system from crashing as modules are plugged in or unplugged, and respond to the different power-supply needs of different modules.

The concept of open-sourcing hardware itself is not new. Similar initiatives have failed (DigiDave) to make a big mark on the masses, due to the wide-scale impracticality of hardware hacking. However, Bug Labs hopes to make a mark by following the modular approach and making different components for the Bugbase available in the market over a period of time.

Read more!

Thursday, September 27, 2007

IBM's CoScripter - Automate the browser-based tasks

IBM’s CoScripter, developed at the Almaden Research Center, helps automate repetitive tasks from the Web browser, much like what batch files do for the computer.

A quote from the article at InternetNews:

In one example, IBM said the task of preparing for a meeting — sending out notices to attendees, reserving a room, reserving equipment, catering food — can be automated by creating a script with CoScripter. The CoScripter authoring tool captures all of the steps a person takes in any Web-based applications launched in the task.

The CoScripter automates the tasks that are performed in a Web browser. It is one great tool to pass on Workplace skills (O’Reilley Radar) and can make many repetitive tasks much simpler. The tool doesn’t have an automated technique for handling areas where user action on input is required,but it’s a great way to share Web events.

CoScripter supports the sharing of scripts among users, and so there’s a threat that some scripts may lead to sites that are malicious. Hence, it is required that users exercise caution (InformationWeek) by carefully reading the scripts for suspicious URLs.

Here’s a video tutorial to the script tool and the link for the CoScripter download.

Read more!

Sunday, September 9, 2007

The Top 35 Torrent Sites of 2007

This summary is not available. Please click here to view the post.

Read more!

Friday, August 31, 2007

£200 space balloon's amazing earth pictures

Balloon space

WITH its crystal clear images of the Earth's surface, these spectacular pictures could be from a Nasa satellite.

But they were taken with an ordinary digital camera – strapped underneath a helium balloon. Tony Rafaat spent just £200 making a weather balloon, which reached an altitude of 35,843m (117,595ft).

As the balloon rose higher, the camera – fixed inside a small Styrofoam block – took pictures of its journey.

Space balloon

Mr Rafaat, 41, from Alberta in Canada, then used an onboard transmitter to track and retrieve it.

The amateur scientist and two friends spent two years perfecting their device – which they called the Southern Alberta Balloon Launch Experiment or SABLE.

Read more!

Friday, August 24, 2007

Microsoft's First website

Check out the screenshot of the first site published by now multi-billion dollar corporation

Read more!

Toshiba unleashes 32-GB SD cards


Storage options for devices such as cell phones, digital cameras, and portable media players are changing. While it used to be that you could buy a small SD card for a bit of storage, deferring to spinning hard disks when you needed more, that's no longer the case. With expandable storage options changing, platter-based drives are going out and flash drives are going in. Now that sizes of SD cards are getting bigger, people will be swapping them out of players and phones like CDs.

Just take a look at these new Toshiba SD cards. They're the first to hit a whopping 32 GB, which is bigger than most hard disk-based MP3 players. Imagine popping one of those in your digital camera; you'd never, ever run out of room. And you could keep your entire music collection on one or two of them, swapping them out in your phone or player to never be without your tunes. It's pretty great, and as soon as prices come down a bit look for them to be everywhere

Read more!