HP

HP Keeps Installing Secret Backdoors In Enterprise Storage 193

Nerval's Lobster writes "For the second time in a month, Hewlett-Packard has been forced to admit it built secret backdoors into its enterprise storage products. The admission, in a security bulletin posted July 9, confirms reports from the blogger Technion, who flagged the security issue in HP's StoreOnce systems in June, before finding more backdoors in other HP storage and SAN products. The most recent statement from HP, following another warning from Technion, admitted that 'all HP StoreVirtual Storage systems are equipped with a mechanism that allows HP support to access the underlying operating system if permission and access is provided by the customer.' While HP describes the backdoors as being usable only with permission of the customer, that restriction is part of HP's own customer-service rules—not a limitation built in to limit use of backdoors. The entry points consist of a hidden administrator account with root access to StoreVirtual systems and software, and a separate copy of the LeftHand OS, the software that runs HP's StoreVirtual and HP P4000 products. Even with root access, the secret admin account does not give support techs or hackers access to data stored on the HP machines, according to the company. But it does provide enough access and control over the hardware in a storage cluster to reboot specific nodes, which would 'cripple the cluster,' according to information provided to The Register by an unnamed source. The account also provides access to a factory-reset control that would allow intruders to destroy much of the data and configurations of a network of HP storage products. And it's not hard to find: 'Open up your favourite SSH client, key in the IP of an HP D2D unit. Enter in yourself the username HPSupport, and the password which has a SHA1 of 78a7ecf065324604540ad3c41c3bb8fe1d084c50. Say hello to an administrative account you didn't know existed,' according to Technion, who claims to have attempted to notify HP for weeks with no result before deciding to go public."
Privacy

USPS Logs All Snail Mail For Law Enforcement 324

The NY Times reports on a program in use by the United States Postal Service that photographs the exterior of every piece of mail going through the system and keeps it for law enforcement agencies. While the volume of snail mail is dropping, there were still over 160 billion pieces of mail last year. "The Mail Isolation Control and Tracking program was created after the anthrax attacks in late 2001 that killed five people, including two postal workers. Highly secret, it seeped into public view last month when the F.B.I. cited it in its investigation of ricin-laced letters sent to President Obama and Mayor Michael R. Bloomberg. It enables the Postal Service to retroactively track mail correspondence at the request of law enforcement. No one disputes that it is sweeping." This is in addition to the "mail covers" program, which has been used to keep tabs on mailings sent to and from suspicious individuals for over a century. "For mail cover requests, law enforcement agencies simply submit a letter to the Postal Service, which can grant or deny a request without judicial review. Law enforcement officials say the Postal Service rarely denies a request. In other government surveillance program, such as wiretaps, a federal judge must sign off on the requests. The mail cover surveillance requests are granted for about 30 days, and can be extended for up to 120 days. There are two kinds of mail covers: those related to criminal activity and those requested to protect national security. The criminal activity requests average 15,000 to 20,000 per year, said law enforcement officials who spoke on the condition of anonymity because they are prohibited by law from discussing the requests. The number of requests for antiterrorism mail covers has not been made public."
Shark

Laser Blood Scan Could Help Identify Malaria and Other Diseases 34

sciencehabit writes "Combining lasers with a principle discovered by Alexander Graham Bell over 100 years ago, researchers have developed a new way to collect high-resolution information about the shape of red blood cells. The lasers pulse every 760 nanoseconds to induce red blood cells to emit sound waves with frequencies of more than 100MHz, one of the highest frequencies ever achieved. Testing the laser on blood samples collected from a group of human volunteers, researchers showed that the high-frequency sound waves emitted by red blood cells in the blood samples revealed the tiniest details about the cells' shapes. Because diseases like malaria can alter the shape of the body's cells, the device may provide a way to accurately diagnose various blood disorders before it's too late." Abstract (actual paper is paywalled).
Medicine

Microscopic "Tuning Forks" Help Determine Effectiveness of Antibiotics 36

sciencehabit writes "A patient admitted to a hospital with a serious bacterial infection may have only a few hours to live. Figuring out which antibiotic to administer, however, can take days. Doctors must grow the microbes in the presence of the drugs and see whether they reproduce. Rush the process, and they risk prescribing ineffective antibiotics, exposing the patient to unnecessary side effects, and spreading antibiotic resistance. Now, researchers have developed a microscopic 'tuning fork' that detects tiny vibrations in bacteria. The device might one day allow physicians to tell the difference between live and dead microbes—and enable them to recognize effective and ineffective antibiotics within minutes."
Science

Seismic Data Set Could Improve Earthquake Forecasting 32

sciencehabit writes "Geoscientists still can't predict when a major quake will strike, and many have given up trying. But many do try to issue more general forecasts of hazards and potential damage. This week, researchers added a potentially powerful new tool to their kit: the largest seismic database of its kind ever constructed, based on tens of thousands of earthquake records stretching back more than 1,000 years. Together with a new global map of strain accumulation at plate boundaries, the data sets will form the core of an international public-private partnership intended to reshape the science of earthquake forecasting."
Biotech

700,000-Year-Old Horse Becomes Oldest Creature With Sequenced Genome 69

sciencehabit writes "Scientists have sequenced the oldest genome to date—and shaken up the horse family tree in the process. Ancient DNA derived from a horse fossil that's between 560,000 and 780,000 years old suggests that all living equids—members of the family that includes horses, donkeys, and zebras—shared a common ancestor that lived at least 4 million years ago, approximately 2 million years earlier than most previous estimates. The discovery offers new insights into equine evolution and raises the prospect of recovering and exploring older DNA than previously thought possible."
Android

Android On the Desktop 247

puddingebola writes "John Morris at CNET offers a brief review of PC Android devices, many of them hybrids running Windows 8 and Android. From the article, 'Microsoft has spent a lot of time and effort trying to get Windows onto smartphones and tablets — so far without a whole lot to show for it. Now several PC companies are trying the opposite approach, taking the Android operating system and porting it to PCs.' The article reviews the recent releases from HP, Acer, Asus, and Samsung. Does Android creeping onto desktop or 'traditional' PC devices have any kind of possible long term consequences? Could this be a way for Android and Google to develop a larger presence in corporate IT, or could Android ever really supplant the Windows foothold?"
HP

HP Confirms Backdoor In StoreOnce Backup Products 45

wiredmikey writes "Security response personnel at HP are 'actively working on a fix' for a potentially dangerous backdoor in older versions of its StoreOnce backup product line. The company's confirmation of what it describes as a 'potential security issue' follows the public disclosure that malicious hackers can use SSH access to perform full remote compromise of HP's StoreOnce backup systems. The SHA1 hash for the password was also published, putting pressure on HP to get a fix ready for affected customers. SecurityWeek has confirmed that it is relatively trivial to brute-force the hash to obtain the seven-character password. The HP StoreOnce product, previously known as HP D2D, provides disk backup and recovery to small- to midsize businesses, large enterprises, remote offices and cloud service providers."
Science

Length of Applause Not Tied To Quality of Presentation 138

sciencehabit writes "The next time you hear extended applause for a performance you didn't think was that great, don't feel like a snob. A new study reveals that audience response has more to do with the people in the seats than those up on stage. Applause, it turns out, is a bit like peer pressure. In a study of college students, individuals were more likely to start clapping if a larger percentage of the audience had already started. If 50% of the audience was clapping, for example, individuals were 10 times more likely to start clapping than if 5% of the audience was clapping. People stop clapping for the same reason. Even more surprising, the applause for a bad presentation could be just as long as applause for a good one. Random interactions in the audience can result in very different lengths of applause regardless of the quality of the talk."
Digital

PDP-11 Still Working In Nuclear Plants - For 37 More Years 336

Taco Cowboy writes "Most of the younger /. readers never heard of the PDP-11, while we geezers have to retrieve bits and pieces of our affairs with PDP-11 from the vast warehouse inside our memory lanes." From the article: "HP might have nuked OpenVMS, but its parent, PDP-11, is still spry and powering GE nuclear power-plant robots and will do for another 37 years. That's right: PDP-11 assembler programmers are hard to find, but the nuclear industry is planning on keeping them until 2050 — long enough for a couple of generations of programmers to come and go." Not sure about the OpenVMS vs PDP comparison, but it's still amusing that a PDP might outlast all of the VAX machines.
Science

Trying To Learn a Foreign Language? Avoid Reminders of Home 200

sciencehabit writes "Show a native-born Chinese person a picture of the Great Wall, and suddenly they'll have trouble speaking English, even if they usually speak it fluently. That's the conclusion of a new study, which finds that reminders of our home country can complicate our ability to speak a new language. The findings could help explain why cultural immersion is the most effective way to learn a foreign tongue and why immigrants who settle within an ethnic enclave acculturate more slowly than those who surround themselves with friends from their new country."
Cellphones

Echolocation For Your Cell Phone 73

sciencehabit writes "In a few years, an iPhone app may give you a 3D layout of a room as soon as you step into it. Researchers have developed an algorithm that spits out the shape and contours of complex structures (including Switzerland's Lausanne Cathedral) using data compiled from four randomly placed microphones. The technology, which relies on the same sort of echolocation bats and dolphins use to navigate, could be used to develop more realistic echoes in video games and virtual reality simulations and to eliminate the echo from phone calls."
Science

Do-It-Yourself Brain Stimulation Has Scientists Worried 311

Freshly Exhumed writes "Dave Siever always fancied himself as something of a musician, but also realized he did not necessarily sing or play in perfect key. Then he strapped on the electrodes of a device made by his Edmonton company, and zapped his brain's auditory cortex with a mild dose of electricity. The result, he claims, was a dramatic improvement in his ability to hear pitch, including the sour notes he produced himself. 'Now I tune everything and I practise my singing over and over and over again, because I'm more sensitive to it.' Mr. Siever was not under the supervision of a doctor or psychologist, and nor is he one himself. He is part of an extraordinary trend that has amateur enthusiasts excited, and some scientists deeply nervous: do-it-yourself brain stimulation." With studies suggesting that small doses of electricity can: increase your memory, help you learn new tasks, make you better at math, turn you into a sniper in minutes, and most importantly make the ugly seem attractive, we can expect a lot of brain zapping in the next few years.
The Almighty Buck

Genomics Impact On US Economy Approaches $1 Trillion 115

sciencehabit writes "Despite a slow economy, business in genomics has boomed and has directly and indirectly boosted the U.S. economy by $965 billion since 1988, according to a new study (pdf). In 2012 alone, genomics-related research and development, along with relevant industry activities, contributed $31 billion to the U.S. gross national product and helped support 152,000 jobs, the biomedical funding advocacy group United for Medical Research announced today in Washington, D.C. Based on total U.S. spending, the country gets $65 back for every $1 it spends on the field."
Operating Systems

XP's End Will Do More For PC Sales Than Win 8, Says HP Exec 438

dcblogs writes "Hewlett-Packard executives say that the coming demise of Windows XP next year may do what Windows 8 could not, and that's boost PC sales significantly. 'We think this will bring a big opportunity for HP,' said Enrique Lore, senior vice president and general manager of HP's business PCs. Lore was asked, in a later interview, whether the demand for XP replacement systems could help sales more than Windows 8. His response was unequivocal: 'Yes, significantly more, especially on the commercial side,' he said. Lore said 40% to 50% of business users remain on XP systems."
HP

HP Discontinue OpenVMS 238

simpz writes "The register is reporting that 'the ancient but trustworthy server operating system' OpenVMS has been discontinued. From the article: 'HP never really promoted its acquisition and OpenVMS suffered from a lack of development compared to HP-UX, itself suffering from competition from Linux. It was only a matter of time, but it's a sad end. Many of its old-time fans, your correspondent included, cherished a hope HP would move it to x86-64 – but since development moved to India in 2009, OpenVMS has been living on borrowed time. Now, it's run out.'"
Science

Fear of Death Makes People Into Believers (of Science) 434

sciencehabit writes "Nothing, some say, turns an atheist into a believer like the fear of death. 'There are no atheists in foxholes,' the saying goes. But a new study suggests that people in stressful situations don't always turn to a higher power. Sometimes, they turn to science. Both athletes preparing for a big race and students asked to write about their own death showed a 15% stronger belief in science than those under less stressful situations (abstract). 'In stressful situations people are likely to turn to whatever worldviews and beliefs are most meaningful to them,' says study co-author, Anna-Kaisa Newheiser, a psychologist at Yale University. And many people find the scientific worldview more compatible with their own."
Science

Atomic Bombs Help Solve Brain Mystery 59

sciencehabit writes "The mushroom clouds produced by more than 500 nuclear bomb tests during the Cold War may have had a silver lining, after all. More than 50 years later, scientists have found a way to use radioactive carbon isotopes released into the atmosphere by nuclear testing to settle a long-standing debate in neuroscience: Does the adult human brain produce new neurons? After working to hone their technique for more than a decade, the researchers report that a small region of the human brain involved in memory makes new neurons throughout our lives — a continuous process of self-renewal that may aid learning."
Stats

Marriages Spawned From Online Dating As Satisfying As From Traditional Dating 313

sciencehabit writes "Millions of people first met their spouses through online dating. But how have those marriages fared compared with those of people who met in more traditional venues such as bars or parties? Pretty well, according to a new study. A survey of nearly 20,000 Americans reveals that marriages between people who met online are at least as stable and satisfying as those who first met in the real world—possibly more so."
Biotech

Gene Therapy May Protect Against Flu 72

sciencehabit writes "In 2009, a global collaboration of scientists, public health agencies, and companies raced to make a vaccine against a pandemic influenza virus, but most of it wasn't ready until the pandemic had peaked. Now, researchers have come up with an alternative, faster strategy for when a pandemic influenza virus surfaces: Just squirt genes for the protective antibodies into people's noses. The method—which borrows ideas from both gene therapy and vaccination, but is neither—protects mice against a wide range of flu viruses in a new study."

Slashdot Top Deals