The remote control of the TV Player of the Freebox Revolution uses wireless technology ZigBee RF4CE. This protocol has vulnerabilities a stubborn attacker can easily exploit for example, spy on a user's communications.
Security flaws are sometimes housed in the most unlikely areas. On the occasion of the conference "Nuit du Hack 2016", the security researcher Renaud Lifshitz showed that it was possible to take control of a triple play box by intercepting communications between the remote and the TV box. A condition is however required. It takes these exchanges are made via the ZigBee RF4CE protocol, as is the case of a model distributed by a French ISP "well known" , explains the researcher, without revealing the name of this actor.
However, the screenshots shown during the presentation leaves no doubt.The purpose of this study, conducted late 2015 - early 2016, was the Player of TV Freebox Revolution.
The wireless technology ZigBee is widely used in the home automation sector. It allows the interconnection of devices with a range of 10 to 100 meters. The RF4CE variant is found mostly in remote controls. Compared to infrared communication, ZigBee RF4CE it offers many advantages. There is no need to aim the remote device or pay attention to the brightness level.Moreover, communication is bidirectional and can be encrypted in 128-bit AES.
The key exchange is done in clear
But there's a catch: for encryption to happen, we must first discuss the key between the remote and the unit. Unfortunately, this procedure - which is when pairing - is very secure.
In reality, the TV box will send the encryption key to clear remote. The only safety measure implementation, if one can say, is that the key is cut into 37 little pieces that will be sent sequentially with a relatively low level of signal, just to limit the interception. That's all. "Dilute the key in several whispered exchanges. This is security by obscurity, nothing more " , sums Renaud Lifshitz.
This process - 37 bits sent low intensity - is also rather strange for ZigBee RF4CE: supplier has obviously been aware of this weakness and sought to limit the damage.
According to the researcher, then all it takes to recover the famous key is compatible radio ZigBee dongle, a directional antenna and an amplifier. The total cost of such equipment would be between 500 and 1000 euros. If it is not too far away, the attacker can then intercept 37 bits and reconstruct the key. And it does not need to wait for the fateful moment of the pairing: it can cause the procedure by sending to the TV box a large number of applications for association, which will effectively disassociate the remote control of the victim . The latter will, so, again a pairing.
Once in possession of the key, the attacker can intercept all orders of the victim and, in particular, any passwords that will type. It may also involve its own remote control and inject commands. Several operating scenarios are then possible. It can realize the denial of service by turning off the device and subscribe to paid subscriptions. It can also activate Bluetooth to connect a keyboard, mouse or headphones. "In the latter case, the attacker can listen to the victim's voicemail" says Renaud Lifshitz.
The attacker can also open the email client or Twitter client and send messages on behalf of the user. It could involve a DECT phone and call the eye, receiving phone calls from the victim and listen to his messages. Finally, it could also get the Wi-Fi password, provided they have an angle on the TV screen. The attacker will then have full access to the Internet connection of the victim, leaving the door open to possible attacks by interception (Man in the Middle).
The user has unfortunately no way to protect against this attack because the vulnerability lies in the protocol. The supplier can not deliver a simple patch, but it can improve the situation by modifying or changing the protocol. "A good alternative is that Bluetooth 4.0 is almost perfect level of security. The key exchange, in particular, is done according to the Diffie-Hellman algorithm on elliptic curves " , adds Renaud Lifshitz.
Should we worry about this type of attack? It depends who you are. Given the efforts to deploy and equipment to buy, this attack can not be large-scale and is not profitable if the goal is just to have free Internet access or make a joke to his neighbor. But she may have an interest in the context of espionage of a large target. Note, finally, that the Freebox is not the only device subject to this vulnerability: all appliances using ZigBee can be attacked in this way.This was the case of many products marketed by French operators and some vendors as part of their deals automation there are still a few years.
Friday, 1 July 2016
Google detect these vulnerabilities could allow remote code exploitation and the creation of worms. It is strongly recommended to update their antivirus.
Tavis Ormandy struck again, and it hurts. In a note of blog , security researcher for Google Project Zero has just pin again Symantec security software. He has released seven new critical vulnerabilities that impact all publisher's products, whether for the general public (Norton) or businesses (EndPoint Protection, Scan Engine, ...).
"One can hardly do worse than these flaws. They require no user interaction, affect the configuration of origin and allow to obtain the highest level of execution privilege. In some cases on Windows, the same vulnerable code impacts the core " , says Tavis Ormandy, adding that several of these flaws can be used to create worms, which is particularly dangerous. Last May, the Google engineer had already published a first dive group of critical vulnerabilities in Symantec software.
A careless development process
Among the new found flaws in Mr. Ormandy details linked to a PowerPoint document analysis (CVE-2016-2209). It shows the source code to support, how a buffer overflow in this feature allows an attacker to execute arbitrary code on the system with administrator rights.
The researcher also critical management of software development at Symantec. According to him, the publisher has integrated open source libraries in its products without updating it since ... seven years! "Dozens of public libraries in these vulnerabilities impact the Symantec products. For some of them, there are even public exploits " , he says.
His advice is simple: always check that the third-party software does not have vulnerabilities and they are updated. "Nobody wants to do that, but it must be an integral part of a process of Secure development " , he added. Symantec is obviously pretty far from such a quality standard, which is strange for a specialized security editor!
The good news is that Symantec has released patches for all these faults.The most Norton products, in particular, will be updated automatically by the LiveUpdate system. Norton Bootable Removal Tool will require manually download the new version. However, no update is available now for Norton Security for Mac.
11,000 bots have been created since the launch of Messenger Platform. Its director David Marcus today takes stock of the innovation and announces the integration of Facebook by assistant M two or three years.
French passed through Geneva, David Marcus was president of PayPal before taking the head of Facebook messaging activities in 2014 as Vice-President. He has been the architect of the Messenger of empowerment.Present on the Viva Technology Lounge this Friday 1 st July, he looks back on the opening there are two and a half months Messenger Platform . This tool allows third party developers to create their own bot to interact with Messenger users after they have subscribers. A small revolution in the world of messaging.
01net: What are the results you pull the first months of Messenger Platform?
David Marcus: it currently has over 11,000 bots that have been created since the beginning and 23,000 developers have registered on the platform. We consider it a success.
Users complain messages too frequently and stress out about . What do you say?
But I have no problem to recognize that the first bots were not all quality.Similarly there have been many terrible sights in the beginning of the Web, and then excruciating mobile app with the first smartphones. Today we have enough distance to see what works. Travel SNCF in France or American Express in the United States work very well, for example.
What are the bots that work exactly?
What is certain is that a bot can not be a replica of a website. If the NBA is very popular, it's because he does not comment on results throughout a game. Instead, it sends a very short video after each meeting, as a kind of summary. It was also noted that the media that raised the most membership were those who were the most advanced and do not send more than one notification per day. General information are less successful.
Another formula that works, the bot Meetic dating in France, which has just been launched in demonstration and revolves around two characters, Lara and Tom. Internet users spend a little test in dialogue with them, leading or not registration. In this case, the bot can perform the same function than form.Except that it is more pleasant and convenient to use and no need to identify.
We are now working to ensure that all interactions are not necessarily conversational. That people can click pictures or a list of possible answers without having to take the trouble to write. It also hopes to launch very soon be able to order a pizza or a taxi from a bot in Facebook Messenger in France as is already the case in the United States.
At what point do you consider that a bot found success?
When brands have a score higher than they would have with a site or app in terms of audience and transformation.
But these bots are they not a threat to hearing loss for media and brands?
No, I do not think so. Today, we do not use more than 5 to 10 mobile applications. It becomes extremely difficult for a new application to impose a large scale. If you are traveling once with KLM, for example, we are not going to want to download the app. We offer an alternative and hybrid solution with bots. You can give all the details of your booking during a conversation and keep all the information of your trip and your history, centralized in Facebook Messenger. Same for booking a hotel room with the bot InterContinental Hotel.
I believe today is that it is better that we add value to Facebook Messenger rather than create services that do not yet exist.
Do you still plans to offer an encrypted mode option on Facebook Messenger?
Yes. I can not say more at this stage.
Where is the project Facebook M ?
We continue to move forward. I think we will be able to integrate it into our servers in two or three years. The project is led by Alexandre Lebrun, the founder of the start-up Wit.ai that we bought last year in partnership with Yann LeCun who heads the FAIR. For the moment we are testing Facebook M very small scale in the United States and we intend to open to third party developers.
The principle is to rely on both artificial intelligence and human resources to respond to questions from users formulated in natural language. Initially AI was not even able to say the weather in Bordeaux. Since then we have made much progress. Men are here to bring added value to answers and allow the machine to better understand the requests. But Facebook M will be hard to internationalize.
Wednesday, 29 June 2016
Microsoft will deploy the biggest update of its operating system a few days after the end of the period of free Windows 10.
350 million. Microsoft announced today that Windows 10 is now installed on 350 million devices worldwide. An excellent figure, considering that Redmond had provided 300 million on early May. The new OS is continuing its merry way to the peaks at the expense of Windows 7, with a 18.3% adoption rate in the world and 23.3% in France (Statcounter figures).
Within a month, however the curve could decline slightly. For Windows 10, the upgrade is free since the launch will be paying, pile a year after its launch on July 29. Impossible, for now, to know the price of a future update .
The largest Windows 10 update to date
Other notable dates: August 2, Microsoft will start distributing the biggestupdate of Windows 10 to date. Soberly called "updating birthday," she brings many new features that were detailed in the last few weeks, during the Build conference.
Among them, particularly one notices the arrival of Windows Ink, a module that integrates handwriting in many native applications. Windows Hello -the biometric identification system of Microsoft- also made progress: it is now part of some native applications and especially Edge browser, allowing to login to a website without having to enter their password . This update also integrates the new service Xbox Play Anywhere , which allows to abolish the borders between PC and Xbox One.
Fever E3 2016 back down, it's time to make the selection of games that have most marked us and, more importantly, those we are ready to play right out!
Difficult to choose among all seen games played or announced at the 2016 edition of E3. We managed with difficulty to limit ourselves to 11 titles, coming overwhelmingly in the year or in 2017. Some are expected later ... or never, if one is pessimistic.
We begin our list with a game we expect to firm up. And having been able to take over for several tens of minutes only strengthened our ... feelings about it. Wildlands is the only game that we took the time to test at two different locations on the living room. First, on the Microsoft stand, controller in hand and then on the Ubisoft booth on a running PC and calibrated monitors. The principle of full cooperation to 4 players to carry out missions in many different ways is more than successful. The slightest mistake will not forgive and targeted stealthy operation can very quickly turn into general bloodshed.Much is expected, Ubisoft put too heavily on his colt, hope that the eight months remaining before the release allows developers to fine tune this title open world of the most beautiful way. Released: March 7, 2017 / Platforms:PS4 , XBO and PC
2.Battlefield 1 - DICE - EA
Second slap this E3 2016 demo alpha Battlefield 1 on which we could lay hands upon EA Play event. A great atmosphere, beautiful effects, realistic weapons to an anachronistic World War, full of decorative elements to destroy and use to protect themselves or ambush, that the BF was expected to recover in the license . And the good news is that it arrives this fall. The bad is that it is happening in France and that the French will not be present in the basic version ... only DLC. ? Really Released: October 21, 2016 / Platforms:PS4, PC and XBO
3.Recore - Armature Studio / Comcept - Microsoft Studios
Exclusive Xbox One and Windows 10, and probably one of the best this year,Recore was finally playable! Let us rejoice, it will not have to wait another year to survey the levels of this attractive GST and seems to offer its challenges. Remember, Recore is the result of collaboration between Keiji Inafune ( Mega Man , Mighty No. 9 , Lost Planet , Street Fighter ) and the creators of Metroid Primes . . Yes, even Released: September 13, 2016 /Platforms: XBO and PC
4.Horizon Zero Dawn - Guerrilla Games - SIE
Exclusive always, but this time on PS4. Horizon Zero Dawn may take a few million PS4 owners from next year. Aloy, the hunter facing the hostile bio-mechanical nature will have to find his way and lead his quest, at the risk of mankind extinction forever. Unfortunately, it was impossible for us to take over that title on the Sony booth. Released: February 28, 2017 / Platform: PS4 only
5.The Legend of Zelda: Breath of the Wild - Nintendo
25 minutes. This is the time we spent with Link in the universe of the nextZelda . A very searched opus, probably for more adult players and the eternal love of the license. Players unfamiliar with role plays will, themselves, probably more difficult to adapt to this new start of the license. The output is still expected in 2017 (along with the NX console, a priori) which leaves time for amateurs to learn the basics of Hyrule world on one of the last installment 3DS, very successful. Although the graphics we have not really thrilled about Wii U, we wait to see what he will give the next generation of Nintendo console. In any case, the open world offers many possibilities hardly interviews during the demo. See you in 2017. Released: 2017 / Platforms:Nintendo Wii U and Nintendo "NX"
6.Dishonored 2 - Arkane Studios - Bethesda
The next creation of Arkane Studios in French was not playable on the Bethesda booth and this is a pity. We dreamed of us throw headlong, just to see what Emily was in the belly Corvin time qu'assassine with supernatural powers and steampunk diversified arsenal. Still, the title seems in line with its predecessor and that's already good news. Released: November 11, 2016 /Platforms: PS4, and PC XBO
7.Deus Ex: Mankind Divided - Eidos Montreal - Square-Enix
Present at E3 2016, the next installment of Deus Ex is left even test for over 20 minutes, during which we paced the first mission of the game, according to two general types of approaches: Lethal and Non-Lethal.
Good feeling, a level quite well modeled but may be a little too linear ... probably to familiarize beginners to the world of Deus Ex. Also note, a few minutes spent in the Breach fashion very attractive and discover more fully the launch.
Released: August 23, 2016 / platforms: XBO, PS4 and PC
8.Absolver - SloClap - Devolver
Discovered in a trailer outside the lounge, Absolver was our little slap and also our heart stroke this E3 2016. A fighting game online fray with learning system player against player and customisations combat sequences to imagine based on postures and martial art style that you want to create, the French of SloClap impressed us. Released: 2017 / Platforms: PC and PS4 (for now)
9.God of War - SIE Santa Monica
Kratos is not in the Top 5. Yes, sorry for him. The dissipated surprise, we return to reason and release date of fault, this remains a dream for now. But what a dream! Became father, destroyer of creatures from hell back in action in the upcoming God of War . After the death of his wife, he's in charge of the education of his son. And if the live demo made was pulling too much on pathos for such a large and violent fellow, the return of the warrior on PS4 promises epic battles. Output: Not specified / Platform: PS4 only
10.For Honor - Ubisoft Montreal
Are you able to don armor and carry the weapon of a fighter of the Middle Ages? In For Honor , you will have to prove worthy for the battles to fight and fortresses ask to take a little more than "buggers" button on the controller.Whether Vikings, Samurai or Knights, opt for safekeeping, be attentive to the movements of opponents and correctly use the environment are all essential items to survive the pitfalls designed by Ubisoft. Released: February 14, 2017 / plat- forms: PC, PS4, Xbox One
11.Mafia III - Hangar 13 - 2K Games
For this E3, Mafia 3 has largely unveiled but was not playable either. Too bad (yes, we repeat but we are frustrated!). We would have liked to walk the streets of New Bordeaux looking for a big shot and a big revenge. However, the video shows a large map, opportunities approach and multiple actions. No doubt some adjustments remain to be done to improve the realism of certain movements and behavior of AI, but for the rest, we expect this third installment with friendly curiosity. Released: October 7, 2016 /Platforms: PS4, Xbox One, PC, Mac OS
If Nintendo was conspicuously absent from this E3 announcements regarding hardware and game catalog, Microsoft and Sony - them - revealed a consistent roadmap, each revealing a different strategy there to satisfy their players.
E3, the largest trade show for video game professionals, closed its doors last Thursday night in Los Angeles. Some have described as "quiet", others "the best E3 in recent years." No show of force nor tackles (too) supported on the neighbor. Whether the publishers' side or hardware manufacturers, Sony and Microsoft. Besides, everyone has unveiled its release schedule without almost never refer to another. Very different battle plans which, this year, put the same person at the center of everything: the player. Good! It is now time to take stock and see how Sony and Microsoft went about trying to seduce us.
Two Xbox consoles, cross-platform and features for Live
First on the agenda of "big" conference, Microsoft. After weeks of rumors and a nice escape in the night from Sunday to Monday, the US has - finally - unveiled its new console, the Xbox One S. Scheduled for August from 299 euros (with a disc hard 500GB), this Xbox is a condensed model of the first with a built power supply (well), and retains the same power. It is thus compatible with all games, present and future. The new functions are to look for the multimedia side, with the support of the format 4K video (and soon games?) , Both streaming (Netflix, etc.) than physical medium since the Blu-ray drive for change 4K model. HDR management is also added for brighter colors, more vibrant. The console will also be supplied with a "new" handle the covering has changed and is close to one of the Elite model . This paddle still infrared dialogue with the Xbox One but now supports Bluetooth to be used on PC.
A new mode of wireless connection that helps give meaning to Play AnywhereMicrosoft also launched at its conference. Remember, it is able to play a game on both console and PC, buying only one copy of the game. " As was the case for Quantum Break but we guarantee players a better fluidity and optimization on top for all titles Xbox Play Anywhere. We learned a lot in recent months during the development of Play Anywhere and have worked with the devel oppeurs to make the experience the best possible with the same game, and that although the platform is different "admitted Mike Nichols, Corporate Vice President of Marketing for Xbox, in an interview on the show.
For now, games are advertised as compatible least fifteen including Gears of War 3, Forza Horizon 3 Scalebound, Recore or self We Happy Few andCuphead .
But be careful, this only works with digital copies! Not with the physical media sold in stores. Of course, this convergence is made possible by the presence of Windows 10 on the PC and the Windows Experience on Xbox. Despite this, Play Anywhere requires some updates to both the console that the PC but should soon be functional. Some compatible titles will -aussi- support a cross-platform function for PC gamers and Xbox One can play together in one game, against co-op or each other (in the case of a game cars for example).
Continuing with the Xbox Live service. It is enriched with several social functions as the formation of guilds (clubs), a tournament platform for all (Arena) or the research group to play a particular game. It will also change the language of a game without changing the system.
Scorpio: towards a second generation of Xbox One?
Finally, Microsoft unveiled its future plans for the next two years. Xbox One family will grow by a third device, the Project Scorpio . The latter came close the conference, but without really show leaves no doubt as to its nature. It's a new console, ultra powerful as Microsoft prepares and, like the other two Xbox One, will run all games released since 2 ½ years. Microsoft agrees to it.Also according to Mike Nichols, announcing Scorpio so early " that allows developers to anticipate the release of upcoming games, and especially to enable them to approach us [Microsoft, Ed] to learn more about everything our project will bring them to make their future creations fully compatible with all Xbox ecosystem . " with Scorpio, computing power and display will be reviewed seriously on the rise since the estimated power calculation is given 6 Teraflops. However, despite our coaxing smiles and diverted our questions, Corporate VP of Microsoft Xbox did not want to tell us more about the nature of the embedded chip in Scorpio or what its manufacturer. " It's a secret for now. If we need to, we will do so in due time , "we let go of it.
With this new processor in addition to the game in 4K native, it would even be possible to run titles in VR. On paper, Scorpio is therefore a third console in the Xbox park, clearly oriented towards the future without denying or abandoning its roots. See you in 2017 to learn more, the availability is estimated for the end of next year.
A final word about the one we do not talk for several conferences: Kinect. No trace of game or new functions to it. Worse on the Xbox One S, the only mention made of this camera, once presented as revolutionary, is at the back, just above a multiple sockets ...
No PS4 Neo, Sony is trying to reassure the PSVR ...
At Sony , and hardware development side software , it is in the reservoir. A few days before the show opens, Andrew House , head of Sony InteractiveEntertainment , announced that the "PS4 Neo" was real but was absent from E3. What leave a boulevard to Microsoft to announce its consoles ... and joinNintendo on the bench giving manufacturers to show their new hardware in Los Angeles . Since then, rumors are spread more beautiful and suggests that this new PS4 could be presented and launched for the year-end.
However, to complete the game ads, the Japanese giant has officially announced the price and availability date for its virtual reality headset.October 13, for $ 400 (and therefore euros ), the PlayStation VR will integrate the curious and passionate home RV. To ensure the show, Sony announces 50 games, but how many will be beneficial security and not "experience" VR?For now Sony does not say much. Launched simultaneously with this announcement, a new accessory for playing one of VR games Sony (Farpoint ), which is nothing but a PS Move mounted on a frame-shaped gun.
VR side precisely, apart Farpoint, Sony showed several "experiments" that is to say, demos and small games very short ... Batman Arkham VR, a mission of Star Wars Battlefront or a side game of Final Fantasy XV have shown nothing but very addictive. And, at first glance, we are far from the 50 games announced at the exit or in the weeks following the sale of the helmet.
... And dream games but distant
And, not having announced a new console, Sony opened its catalog of games for us eyeful. Among the biggest surprises, the new God of War is positioned in pole position, but has yet to release date. It is followed closely by HorizonZero Dawn , postponed to next year, and Resident Evil 7 whose output is announced for 24 January. Next come Detroit : Become Human of QuanticDream (the studio of David Cage), the mysterious Death Stranding of Kojimaor Days Gone . No release date for these three there either and we bet on several years of development ahead of them to appear on the shelves.Another surprise planned it for October: The Last Guardian , which will further expected last year.
As for independent, a pool where chips tend to be numerous in recent years, we have retained Abzu (released August 2), Bound or Pyre (2017). But in all, more than a dozen titles that were mentioned in demo or placed on the Sony stand, what garnish the offer of PSN Plus (or the PS4 radius storage) at varying lengths terms.
Again a big catalog for Xbox
At Microsoft, we cut his arms and fired heavily at once of "exclusive Xbox One and Windows 10," and with great fanfare availability dates. And the offensive will begin from September 18 with Recore , followed by Forza Horizon 3 , available on 27 of the same month. Then it was the turn of Gears of War 4coming to settle on our hard drives, from October 11.
As for independent games, the ID @ Xbox program full of songs. Microsoft site Inside , the creators of Limbo under the spotlight at the end of June. It will be followed more or less closely by a big twenty titles, including Cuphead(already presented last year), New Happy Few (by some creators of the firstBioshock ) or Sea of Thieves .
And not to mention the highly anticipated Gwent CD Projekt RED, the father of The Witcher , as Microsoft has offered to his lecture. Finally, in 2017, the big exclusive titles will be back with Scalebound , State of Decay 2 , Dead Rising 4 or Halo Wars (the 21/2), definitely more playable on PC and console. In terms of multi-flat outputs platforms, we simply point that Call of Duty: Infinite Wars, Activision, will be present on both platforms (and PC), probably with exclusive content for owners of PS4. As Watch_Dogs 2 with DLC will be playable on the Sony console 30 days before the official release on Xbox and PC. Microsoft's console meets these attacks - especially - with early access toBattlefield 1 , on October 13, for subscribers to EA Access .
No winner, strategies differ
Overall, the general impression that emerges from the conference Xbox One is that Microsoft wants to increasingly impose its console as a media center and games in the house. What is ultimately reminiscent of the original positionally Xbox One, which had so cringe players. A hub open to all, with the option of either playing the same games of its eco system on PC and console. The Windows father seems to have a clear vision of the way forward and becoming more and more the desire to s impose to the "general public". And for that, you have an affordable console, various games for all tastes, and whether they are large or independent licenses, more confidential.
However, in the American discourse, we found it lacked a bit of aggression ... and game effects to "wow" to hope to get over its competitor this year.
Sony, meanwhile, as in 2015, played the card affects heroes / licenses and multiplies the effects of surprises ... without necessarily having - in fact - concrete to announce. By concrete, is meant for example a date of availability, even vague ... Most surprising songs still seem distant, intangible.Hard to really dream in these circumstances. A asks whether the Japanese giant, the market leader of next generation consoles, will offer the luxury of taking their time to announce his games in the future, more or less nearby as its new console. All will arrive on time.
No doubt Sony he keeps aside for GamesCom 2016 this summer, or more likely, to the Paris Games Week . Indeed, every year, the Paris event is growing in importance and in 2015, Sony was the only one doing a press conference on the sidelines of the fair. Deeply the end of October so for may finally have the chance to see pictures of those who have conspicuously absent: Final Fantasy VII Remake , Shen Mue III or Gran Turismo 7Concerning the gaming license. car, we must be content for the time Gran Turismo Sport , present on the stand but not presented during the keynote, an intermediate stage focused mainly on sports car racing in multiplayer and whose release date is scheduled for the month October ... Between that Sony and Microsoft working hard to spread its conquest over two years unclear which strategy will prevail. Coming out of E3, in any event, objectively, the party seems tight ...