Cloudflare’s Cloudbleed Has Cryptocurrency Platforms Taking Precautionary Measures – newsBTC

The recent Cloudbleed memory leak issue has forced cryptocurrency exchanges to issue safety instructions to its users. Read more...

Cybersecurity is one of the major concerns of the cryptocurrency industry. As the cyberthreats increase, online platform operators are flocking to performance and security solutions providers like Cloudflare to ensure that their websites are protected from DDOS and other attacks. But what happens when something goes wrong with the service that is meant to protect digital property worth millions of dollars?

A recent issue with Cloudflares edge servers created a sense of panic among many cryptocurrency exchange operators. Some of them have asked their users to take precautionary measures by changing their login credentials and resetting two-factor authentication for their accounts.Cloudflare reported the recent memory leak issue, known as Cloudbleed in its recent blog post.

According to the blog, Cloudflare was informed of the issue by Tavis Ormandy from Googles Project Zero. Ormandy reported the security problem with Cloudflares edge servers, which he discovered while investigating corrupted web pages. The company offering more details about the incident said,

our edge servers were running past the end of a buffer and returning memory that contained private information such as HTTP cookies, authentication tokens, HTTP POST bodies, and other sensitive data. And some of that data had been cached by search engines.

However, Cloudflare has clarified that the customers SSL private keys were not compromised by the bug as the service always terminates SSL connections through an isolated NGINX instance. The memory leaked by the Cloudbleed bug could have contained private information which was cached by search engines. The issue seems to have gone unnoticed for almost a week, affecting 1 in every 3.3 million HTTP requests made through Cloudflare.

BTC-e, the Bitcoin exchange and betting platform has suggested a series of measures to its users to prevent any undesired aftermath incidents. The advisory issued by BTC-e is as follows,

1) You should change your account password before 16:00 (GMT +3) on 26.02.2017. If you fail to do so, your password will be reset automatically. If you enabled 2-factor authentication between the 12th and the 20th February 2017, we strongly recommend you disable and re-enable it again.

2) You should re-create your API keys (info, trade, btc-e code withdraw & coupon) before 16:00 (GMT +3) on 26.02.2017. If you fail to do so, all your keys will be blocked automatically.

3) Cloudflare explicitly mentions that SSL certificates were not leaked. However, we will change SSL certificates for btc-e.com and btc-e.nz within the next several days to provide additional security.

It is always a good idea for users to review and reset their credentials at regular intervals. Irrespective of whether one is using BTC-e, its APIs or not, they should try to follow the suggestions as applicable to ensure that they are not affected on a later date.

READ MORE:Is Bitcoin Industry Too Dependant on CloudFlare?

Continue reading here:
Cloudflare's Cloudbleed Has Cryptocurrency Platforms Taking Precautionary Measures - newsBTC

PascalCoin Is A Cryptocurrency With a Deletable Blockchain – The Merkle

Every now and then, cryptocurrency developers come up with a rather intriguing concept. PascalCoin is a great example of one such project, as this cryptocurrency offers a deletable blockchain, effectively solving one of the data storage problems bitcoin has been facing for several years now. It is time we take a closer look at this altcoin, as it shows a lot of promise.

It is not difficult to see why PascalCoin has been seeing a boost in popularity as of late. Although the project was announced in August of 2016, it looks like its potential is finally coming to fruition After all, PascalCoin is the first cryptocurrency that does not require a blockchain of historical operations to be downloaded by the end user. Despite this odd function, there is no way to double-spend ones coins.

Rather than using the blockchain as found in the bitcoin ecosystem, PascalCoin makes use of a technology called SafeBox. This hash mechanism is modified every time a new block in generated by the PascalCoin blockchain. SafeBox is updated with the new block operations, after which it generates a new Safebox hash. Even if the blockchain up to that point were to be deleted, there is still a proof of all transactions and wallet balances.

Controlling the Safebox hash is of the utmost priority for the PascalCoin team. A total of five new accounts arecreated per network block, which effectively helps to keep the hash size as small as possible. For those who want to find out more, it is well worth checking out the projects white paper on GitHub. By removing the need to download and store an entire blockchain, the PascalCoin developers could be onto something.

Other than the SafeBox feature, PascalCoin focuses on being a cryptocurrency that can appeal to the masses. It offers quite a few similarities to how bank accounts work, with easy to remember account names instead of wallet addresses. This is another intriguing development that makes cryptocurrency more approachable by the average person on the street. It remains to be seen whether or not PascalCoin can achieve its goal, though.

Looking at the PascalCoin trading charts, it is evident this cryptocurrency has become the new hot commodity among altcoin traders. That being said, the fact its blockchain can be deleted and its convenient wallet addresses are the only proper features for the time being. There are no merchants or platforms accepting PascalCoin as a payment option, indicating this altcoin still has a long way to go before it can rival bitcoin.

One final thing that sets apart PascalCoin fro other altcoins is how it seemingly favors mining with an NVIDIA GPU. Most altcoins use algorithms which make using an AMD graphics card far more convenient. PascalCoin is doing things a bit differently, although a new miner for AMD cards was released not too long ago. An intriguing take on things, although it remains to be seen whether or not PascalCoin will still be relevant a few months from now.

If you liked this article, follow us on Twitter @themerklenews and make sure to subscribe to our newsletter to receive the latest bitcoin, cryptocurrency, and technology news.

Link:
PascalCoin Is A Cryptocurrency With a Deletable Blockchain - The Merkle

Santa Clara Police Arrest Three in Connection With Identity Theft Ring – NBC Bay Area

NEWSLETTERS Receive the latest local updates in your inbox

Army Pfc. Bradley Manning wears handcuffs as he is escorted into a courthouse in Fort Meade, Md., Wednesday, Aug. 21, 2013, before a sentencing hearing in his court martial. Manning was sentenced Wednesday to 35 years in prison for giving hundreds of thousands of secret military and diplomatic documents to WikiLeaks. (AP Photo/Patrick Semansky)

Santa Clara police earlier this month busted an identity theft ring with ties to San Jose, police said Friday.

On Feb. 6, Santa Clara Police Department Special Enforcement Team Detectives served a search warrant at a residence in the 2600 block of Monterey Road in San Jose as part of an investigation into an identity theft ring.

Detectives located piles of stolen mail, checks, fake identification cards, a controlled substance and drug paraphernalia, according to police.

They also discovered printers, card readers and scanning devices used to fraudulently manufacture identification cards and a stolen vehicle, police said.

Three suspects, two men and a woman, were arrested in connection with the investigation.

One of the men had two counts of court probation, while the other had an active federal warrant outstanding for his arrest, according to police.

The woman was associated with the stolen vehicle. Additionally, her photograph was allegedly on several of the fraudulent identification cards, police said.

Police determined at least 12 Santa Clara residents were victims of the identity theft ring.

The identity of the suspects was not released.

Published at 1:29 PM PST on Feb 25, 2017 | Updated at 1:42 PM PST on Feb 25, 2017

Read more:
Santa Clara Police Arrest Three in Connection With Identity Theft Ring - NBC Bay Area

Your Guide to the Encryption Debate – Consumer Reports – ConsumerReports.org

Encryption could soon become part of national debates over consumer issues ranging from data breaches to the safety of connected cars.

Not long ago, it was the sort of thing that only bankers, spies, and military leaders worried about. But, in today's digital world, encryption has become part of our everyday lives, protecting our ability to shop online, book flights, and hold private conversations.

According to Mozilla, the open-internet advocacy group that created the Firefox browser, 49.5 percent of global web traffic is now encryptedan increase of more than 10 percent in one year.

While security experts applaud that progress, they'd like to see even more encryption, to cut down on data breaches, identity theft, and the sort of hacks that could perhaps threaten the nation's power plants.

But not everyone views encryption as a force for good. For law enforcement officials, it's also a tool that allows thieves and terrorists to escape detection.

With a new administration in the White House, one vocal about fighting crime and stamping out terrorism, the debate over encryption's merits may soon surface once again.

Encryption may be central to many everyday transactions, but the issues can be tough to follow. Heres your cheat sheet.

Excerpt from:
Your Guide to the Encryption Debate - Consumer Reports - ConsumerReports.org

Google’s Collision Shakes Up Computer Cryptography – PC Magazine

A cryptographic hash collision suggests the SHA-1 standardused to authenticate documentscan be hacked.

Google researchers have engineered an extremely rare and invisible collision, but they didn't need the Large Hadron Collider to do it.

That's because their collision isn't atomic, it's cryptographic: after years of trying, Google found a way to crack the SHA-1 cryptographic hash function, a security building block that enables digital signatures and HTTPS encryption.

Cracking SHA-1 requires creating a cryptographic hash collision, which is essentially when a single hash, or "digest" applies to two different files.

"A collision occurs when two distinct pieces of dataa document, a binary, or a website's certificatehash to the same digest," Google explained in a blog post. "In practice, collisions should never occur for secure hash functions. However if the hash algorithm has some flaws, as SHA-1 does, a well-funded attacker can craft a collision."

The danger of a collision is much the same as weak encryption: hackers could exploit it. In this case, they could use a collision to trick a system into accepting a malicious document or other file using the hash of a benign one.

Google's collision comes more than 20 years after SHA-1 was first introduced, and suggests that the standard isn't secure enough to handle sensitive information. To prove their collision, Google's researchers provided two PDFs that have identical SHA-1 hashes but different content.

"We hope that our practical attack against SHA-1 will finally convince the industry that it is urgent to move to safer alternatives such as SHA-256," Google wrote.

Other security experts agree: in light of Google's findings, password management company LastPass said it would be accelerating its retirement of SHA-1. LastPass, the Google Chrome browser, and much of the rest of the Internet is gradually moving to the SHA-256 encryption standard.

Tom is PCMag's San Francisco-based news reporter. He got his start in technology journalism by reviewing the latest hard drives, keyboards, and much more for PCMag's sister site, Computer Shopper. As a freelancer, he's written on topics as diverse as Borneo's rain forests, Middle Eastern airlines, and big data's role in presidential elections. A graduate of Middlebury College, Tom also has a master's journalism degree from New York University. Follow him on Twitter @branttom. More

Original post:
Google's Collision Shakes Up Computer Cryptography - PC Magazine

Blog: US Air Force Awards $875 Million for Cryptography and Information Assurance – Signal Magazine

General Dynamics Mission Systems, Scottsdale, Arizona (FA8307-17-D-0006); Harris Corp., Rochester, New York (FA8307-17-D-0007); L-3 Systems Corp., Camden, New Jersey (FA8307-17-D-0008); Leidos Inc., Columbia, Maryland (FA8307-17-D-0009); Raytheon, El Segundo, California (FA8307-17-D-0010); Sypris Electronics LLC, Tampa, Florida (FA8307-17-D-0011); and ViaSat Inc., Carlsbad, California (FA8307-17-D-0012) have been awarded a combined not-to-exceed $875 millionindefinite-delivery/indefinite-quantity contract. Contractors will provide total life cycle support of cryptographic and information assurance-related products and will include contracted activities during materiel solutions analysis; technology maturation and risk reduction; engineering; and manufacturing development, production and product support. Work will be performed primarily at each contractors location. The work is expected to be completed by December15, 2026.This award is the result of a competitive acquisition with seven offers received. Fiscal 2016 research, development, testand evaluation funds in the amount of $5,000 are being obligated to each company at the time of award. Air Force Life Cycle Management Center, Joint Base San AntonioLackland, Texas, is the contracting activity.

See the article here:
Blog: US Air Force Awards $875 Million for Cryptography and Information Assurance - Signal Magazine

Pamela Anderson Addresses Julian Assange Dating Rumors – E! Online

Carl Court/Getty Images, David M. Benett/Dave Benett/Getty Images

Pamela Anderson has visited WikiLeaks founder Julian Assange multiple times in London, causing a fury of speculation that they're a couple.

Assange has been living in London's Ecuador embassy for four years amid allegations of rape in Sweden, and Page Six reported that Anderson visited him at least four times there. The former Playboy model addressed the rumors on The Kyle and Jackie O Show.

"I've spent more time talking to Julian than all of my ex-husbands combined!" she joked with the Australian radio hosts.

But they weren't willing to let it go at that. They pressed her for more details, so she said, "It was never the intention to become romantic, it was just to join forces to do something important."

"It naturally happens," Jackie O said.

"Things happen, for sure," Anderson teased.

Assange reciprocated Anderson's feelings on the same outlet, telling the radio hosts, "She's an attractive person with an attractive personality. She's no idiot at all! Psychologically, she's very savvy."

Anderson recently spoke out in support of Assange on the rape charges against him on the Russian television show The Underground.

"Sweden has these very progressive laws against sexual crimes," Anderson explained. "It's almost too progressive, it's almost paralyzing. I'm going to actually start campaigning for men who have been victims of being accused of rape when they haven't actually done anything."

TheBaywatch alum, a famous animal-rights activist, is also fighting for Buckingham Palace to stop using real black bear fur for its guards' hats. She teamed up with Russian company Only Me to send samples to the palaceto try the faux fur as a substitute.

E! Online - Your source for entertainment news, celebrities, celeb news, and celebrity gossip. Check out the hottest fashion, photos, movies and TV shows!

Read this article:
Pamela Anderson Addresses Julian Assange Dating Rumors - E! Online

Julian Assange’s future hangs in the balance as Ecuador tallies its presidential vote – Fusion

WikiLeaks founder Julian Assange could be facing eviction from his current residence in the Ecuadorian embassy in Londonand a potential court date in the U.S.if Ecuadors presidential election fails to go his way this week.

Results from Sundays election are still too close to call, and as things currently stand, a run-off could be required between Lenin Moreno, a candidate from the ruling left-wing party, and Guillermo Lasso, a conservative former banker who said hed like to expel Assange from the embassy.

Ecuador has no businessprotecting someone who definitely leaked confidential information, Lasso told Reuters last week, as he prepared for Sundays election. I will take on the responsibility of inviting Assange to leave the [Ecuadorian] Embassy at the latest 30 days after the start of our government.

Assange sought political asylum at the embassy in London in 2012, after British authorities ordered his arrest and deportation to Sweden, where he faces sexual assault charges. Assange, who denies the charges, has been living in the embassy under the protection of the Ecuadorian government for the past four years because Britain has not given him safe passage to the South American country.

That situation may change if Lasso wins Ecuadors presidential election. The conservative banker hopes to improve relations with the U.S. and UK, and said he would revise Assanges status as an asylum seeker in Ecuador.

Moreno, an ally of the current Ecuadorean government, is favored in the election. But he needs 40% of the vote to avoid a runoff against Lasso. With almost all the votes tallied, he has stalled at just over 39 percent.

Lasso only has 28.4% of the votes, but he is expected to fare much better head-to-head with Moreno, as Lasso would receive the support of smaller opposition parties that ran their own candidates on Sunday.

WikiLeaks and Assange seem to be monitoring the situation closely and tweeted about Ecuadors election throughout the day. On Monday, WikiLeaks published a statement from Assanges legal team that urged Ecuador to not backtrack on his political refugee status.

Ecuador as a state has domestic and international obligations to protect refugees from persecution the statement read. Assange faces life in prison or the death sentence in the U.S.

The whistleblowing organization has long claimed that if Assange is arrested in the UK and deported to Sweden, he could end up being sent to the U.S., where the Department of Justice is still investigating him for leaking classified information.

Ecuadors National Electoral Council has said that it could take until Thursday to count all of the votes from the first round of voting, as it receives tallies from remote areas of the country and investigates irregularities at some voting centers.

If Moreno gains 40% of the vote, he would become the president outright and Assange would probably continue to receive the protection of the Ecuadorian government.

Ecuadorian opposition parties have asked their followers to stage street protests to prevent potential fraud in the vote count. But election authorities say that its normal for the country to take several days to count all votes, and that the long time lapse is only being noticed this time around because of how close this election has turned out.

The rest is here:
Julian Assange's future hangs in the balance as Ecuador tallies its presidential vote - Fusion

BitConnect Cryptocurrency Exhibits Steady Growth – newsBTC

BitConnect, the young cryptocurrency is showing steady growth within a month of its successful ICO. BitConnect Coin (BCC)is following on the path of the crypto heavyweights like Bitcoin and Ethereum as it showcases significant growth within the digital altcoin community. It continues the trend of the exponential rise as set by the two cryptocurrencies since 2015. The upcoming feature additions to BCC throughout 2017 are further expected to boost its value.

BitConnect coin is an open source, peer-to-peer, community driven decentralized cryptocurrency that allows people to store and invest their wealth in a non-government controlled currency, and even earn a substantial interest on investment.

BCC has experienced few ups and downs since the completion of BCCs initial launch following the ICO. There was a drop in its demand and value soon after its release as is the case for any new digital or physical product. Being a cryptocurrency that is providing real value to the market, BCC has recovered to emerge bigger and stronger than ever.

BCCs chart shows a more than two-fold increase in its price during the recent weeks. Due to an increase in the BitConnect Coin mining activity, the cryptocurrency platform had to increase its mining difficulty to levels much higher than that of any other scrypt-based coin in the altcoin market. Consequently, the exchange volume has been exhibiting significant growth in anticipation of the new features that are going to be included later this month.

The BCC cryptocurrencys demand and price are expected to further increase as the platform prepares to launch the much awaited BitConnect application for Android and iOS devices. The latter half of the year will also see the cryptocurrency undergoing more innovation and also the inclusion of new convenience features. The BCC mining process will stop yielding new coins by the end of 2017.

BitConnect Coin connects its users socially and financially to a secure, protected community of investors and lenders. BCC owners can also connect with the community to increase the value in their respective wallets as the cryptocurrencys price increases. They also get an opportunity to earn interest.

BitConnect hasbecome the worlds fastest growing online Bitcoin community. It has risen from being a concept in Q1 of 2016 to a top 100K website on Alexa in less than one year.

Go here to read the rest:
BitConnect Cryptocurrency Exhibits Steady Growth - newsBTC

Top 5 Cryptocurrencies Under Development By Central Banks The … – The Merkle

In most cases, imitation is the ultimate form of flattery. For Bitcoin, that is not always the case, even though many projects aim to imitate the cryptocurrencys success to date. Various central banks are working on creating their own cryptocurrencies, none of which are decentralized or subject to a free market. Below is a list of such coins which may see the light of day sooner than people think.

As the name would suggest, Citicoin aims to become a bitcoin rival developed by none other than Citibank. Citigroup claims they have built this digital currency based on blockchain technology, although most of the specifics remain unclear to this very day. Judging by the name, it appears Citicoin will only be usable for internal transaction between customers of this particular bank. That has not been confirmed by Citigroup, albeit not much has been heard from this project since July of 2015.

When this collaborative project between UBS, Deutsche Bank, Santander, and Bank of New York Mellon was announced in 2016, the world was taken a bit by storm. Four of the worlds largest banks openly admitted they envy bitcoin and its technology. All four institutions have been researching the technology and decided to create their own cryptocurrency, going by the name of Utility Settlement Coin.

Considering how all of these banks are a member of the R3 blockchain consortium, the move to develop their own cryptocurrency seems a bit strange. Then again it is believed the Utility Settlement Coin project will launch in 2018, albeit no specific date has been announced so far. It remains to be seen if such a project can survive and what type of blockchain it will use, though.

Not to be confused with the previous entry, SETLcoin is a project developed by the Goldman Sachs Group. A patent for SETLcoin was filed back in 2014, which labels it as a cryptographic currency for securities settlement. This type of cryptocurrency will not be a competitor to bitcoin by any means, as it focuses on one specific niche. Goldman Sachs wants to facilitate the exchange of assets over a peer-to-peer network, yet its capabilities are seemingly limited at this point.

The Bank of England, together with various computer scientists, feel they have cracked the code to dethrone bitcoin as the top cryptocurrency. Under the RsCoin banner, the cryptocurrency will be used for P2P transactions all over the world. It would allow the BoE to keep a tight grip on the money supply and would no longer allow for the creation of money out of thin air. Then again, with no fixed coin supply, value can still be created out of nothing. An intriguing type of cryptocurrency to keep an eye on.

One of the more worrisome cryptocurrency projects in development goes by the name of RMBCoin. This cryptocurrency, developed by the Peoples Bank of Chinaaims tobecome the new national digital currency in time. However, users will not have full control over their digital wallet, similar to how bank accounts are not controlled by the customer either. Not much else is known about RMBCoin, as there is no white paper, release date, or comprehensive list of specifications available today.

If you liked this article, follow us on Twitter @themerklenews and make sure to subscribe to our newsletter to receive the latest bitcoin, cryptocurrency, and technology news.

See more here:
Top 5 Cryptocurrencies Under Development By Central Banks The ... - The Merkle