All | Editorial | General Tech | Graphics Cards | Networking | Motherboards | Cases and Cooling | Processors | Chipsets | Memory | Displays | Systems | Storage | Mobile | Shows and Expos
Subject: General Tech | January 13, 2018 - 10:27 AM | Tim Verry
Tagged: WPA3, wifi alliance, wifi, wi-fi, networking, encryption
The Wi-Fi Alliance has announced an update to its Wi-Fi Protected Access (WPA) security suite in the form of WPA3. The first major update in more than a decade, WPA3 is a very welcome and much needed refresh with four new features aimed at both personal and enterprise networks.
Image courtesy Blue Coat Photos via Flickr Creative Commons.
The standards body did not go into many details on the new security suite, but did tease a few upcoming features in addition to closing known security vulnerabilities like KRACK. WPA3 uses a new 192-bit security suite "aligned with the Commercial National Security Algorithm (CNSA) suite from the Committee on National Security Systems" which is a collection of encryption techniques and algorithms that are reportedly up to the task of maintaining confidentiality on personal, enterprise, and industrial networks. Open Wi-Fi networks in particular will get the biggest boost from moving to WPA3 with support for individualized data encryption so that communication channels between the access point and users' devices are secured on a per-device basis. Personal networks also get improved security in the form of protections to protect users against themselves and maintain strong encryption even when they choose weak passwords. Setting up these security configurations is also being considered, and the Wi-Fi Alliance is promising easier configuration on devices with limited or no displays.
I am looking forward to more information on WPA3 as an update to WPA2 has been a long time coming. WEP has long been a joke and WPA2 has been vulnerable for a while so I hope that WPA3 lives up to its promises! What is not clear from the announcement is that if new hardware will be required or if WPA3 could be implemented through firmware and software updates. End user devices may be trickier to get updates from manufacturers, but perhaps wireless routers and access points can be upgraded without needing to buy new hardware. I suppose it depends on if radio and other hardware like the hardware accelerators / co processors need upgraded to support the new algorithms or not. In any case if you have been eyeing a new Wi-Fi AP or wireless router, maybe hold off for a few months to see how this shakes out.
Stay tuned for more information as it develops. What are your thoughts on WPA3 and the Wi-Fi Alliance's promises?
Subject: Networking | January 9, 2018 - 11:44 PM | Sebastian Peak
Tagged: Wireless-AC 1550, wireless, wi-fi, Rivet Networks, networking, killer, Intel, CES 2018, CES, 802.11ac Wave 2
For their new wireless adapter Rivet Networks has partnered with Intel, producing "the worlds fastest 2x2 11ac wireless networking adapter" in the Killer Wireless-AC 1550. This new adapter supports the 802.11ac Wave 2 standard and offers up to 1.73 Gbps throughput using 160 MHz channels.
"The first product to come out of Rivet Networks’ new partnership with Intel, the Killer™ Wireless-AC 1550 is the world’s fastest 2x2 11ac wireless networking adapter. The Killer Wireless-AC 1550 has been designed to combine the speed, intelligence, and control of Killer Networking products with the power and performance of the latest Intel wireless chipset. Delivering faster than gigabit Ethernet speeds along with the gaming functionality that gamers love, the Killer 1550 is the ideal wireless networking product for competitive gamers and performance users who demand the most from their computers."
Killer Networking lists these features for the Killer Wireless-AC 1550:
- Gigabit Wi-Fi Speeds: The Killer Wireless-AC 1550, featuring 160 MHz channel support, has a theoretical max throughput speed of 1.73Gbps when connected to a router that supports 160 MHz channels. This is faster than gigabit Ethernet and twice the speed of standard 2x2 11ac products.
- MU-MIMO Support: Killer 1550 includes full MU-MIMO (Multi-User-Multiple Input and Multiple-Output) support, which dramatically increases network efficiency by working with a MU-MIMO enabled access point. MU-MIMO allows wireless access points to support multiple transmissions at the same time, versus a single transmission at a time like normal access points. This creates additional efficiencies that can provide up to 60% faster download speeds, lower latency, and a better overall connection.
- Transmit Beamforming Technology: Killer 1550 also has Transmit Beamforming technology, which allows the Killer Wireless-AC 1550 to share location information directly to your wireless access point so that the access point can better direct its signals to you. This creates stronger wireless signals at all ranges and faster data transfers.
- Complete 802.11ac functionality: Supports dual band (2.4 GHz and 5GHz), IEEE standards-based 802.11a/b/g/n/ac, and includes Bluetooth 5.0 connectivity.
While the big news might be the Intel co-developed hardware, as this is a Killer Networking product the software is a big component in the overall experience. Options configurable via the Killer Control Panel include Advanced Stream Detect 2.0 for automated traffic prioritization for games and streaming, along with Lag and Latency Reduction Technology and Killer DoubleShot Pro support.
The first devices with the new Killer Wireless-AC 1550 adapter are being released this month.
Subject: General Tech, Networking, Storage, Mobile | January 8, 2018 - 03:53 PM | Tim Verry
Tagged: CES, CES 2018, Elgato, dock, thunderbolt 3, adapter
Elgato is launching a smaller Thunderbolt 3 dock aptly named the Thunderbolt 3 Mini Dock to its family of docks (how many times can I use dock in one sentence?). The portable dock comes with a tail Thunderbolt 3 cable that is permanently attached and stows away into a groove on the bottom of the dock when not in use.
Using the single 40 Gbps connection provided by Thunderbolt 3, the Mini Dock offers up display outputs, USB 3.1, and network ports including:
- DisplayPort 1.2 (4k60)
- HDMI 2.0 (4k60 and HDCP 2.2)
- RJ45 (Gigabit Ethernet)
- USB 3.1 Gen 1 (5Gbps UASP and 0.9A of power).
Users will need a newer laptop or desktop with Thunderbolt running Mac OS Sierra 10.12 or Window 10 operating systems or newer. The compact dock will be available in the sping with as yet unanounced pricing. It should be cheaper than Elgatos larger docks (currently their Thunderbolt 3 Dock is $291) though since it is not powered and offers fewer ports.
As notebooks continue to get thinner, these docks (along with ones based on USB Type-C) are going to become more useful in getting the most out of our faster mobile hardware.
Stay tuned to PC Perspective for more CES news as it develops!
Subject: Networking | January 8, 2018 - 09:00 AM | Jim Tanous
Tagged: smart speaker, router, mesh network, mesh, asus lyra, asus, 802.11ax
ASUS today announced new products in its Lyra brand of connected devices. The Lyra Voice is a multi-featured device that acts as both an 802.11ac mesh Wi-Fi hub as well as a voice assistant-enabled stereo speaker.
The networking side of the Lyra Voice integrates with ASUS's existing Lyra mesh networking system with a tri-band AC2200-class radio, while the personal assistant side relies on integration with Amazon Alexa, allowing users to play music, check the weather, control smart devices around the home, and all of the other Alexa-enabled capabilities.
For those looking for networking without the personal assistant features, the ASUS Lyra Trio is a dual-band, multi-hub mesh Wi-Fi system that features a design with unique antenna placement to increase wireless range and speed.
Both the Lyra Trio and Voice can be used together to form a home mesh network and are controlled and configured via the ASUS Lyra mobile app. Detailed technical specifications for both products are not yet available.
Finally, ASUS didn't forget about its traditional RT-series of wireless routers. The company also announced the RT-AX88U, an 802.11ax router with maximum throughput of up to 6000Mbps. The RT-AX88U also includes 8 Gigabit LAN ports for wired connections, and utilizes MU-MIMO technology to provide maximum performance to all connected devices.
Like the Lyra products, detailed technical specifications for the RT-AX88U are not yet available. All three products are expected to be available in the first half of the year, with pricing to be revealed closer to launch.
Subject: Networking | December 28, 2017 - 05:26 PM | Scott Michaud
Tagged: just delivered, google wifi, google
While our house isn’t particularly large, there were quite a few wireless dead zones with our previous setup. For several months now, we’ve been patching it with a Linksys wireless extender that we move around the house to extend the network in a single direction. That had a few drawbacks, and the signal wasn’t too strong to begin with, but it worked okay.
Out with the old, and in with the new.
4x Google Wifi routers + 1x Cisco 8-port Gigabit switch
I’ve now picked up a three-pack and a one-pack of Google Wifi devices, after having it recommended to me by some coworkers in my software development job (and a Boxing Week sale at BestBuy Canada). The internet comes in from the basement, so I figured that one on each floor (roughly in a vertical line) and a fourth near the deck (with rough line of sight to the middle one) would provide optimal coverage. Each Google Wifi device can only drive a single wired device, so I opened a Cisco gigabit switch that I purchased several years ago to increase that to seven.
Setup was quite easy – just plug the first one in and follow the directions on the Google Wifi app. One step will ask you how many more hotspots you have, excluding the one connected to the internet modem. I answered three, so it asked me to set them up one at a time. I needed to scan the QR code on the first of the three pack, and the QR code on the fourth (which came from the one-pack).
Yeah, I totally need to clean up these wires...
... some day.
When it was all done, everything had internet except the wired devices; that was automatically resolved by the Windows networking troubleshooter, though, so it wasn’t really a problem. Now, as I walk around the house, I see the Wi-Fi drop for an instant (seems like literally a second or two) and reconnect as it chooses a new access point. I suppose this could be annoying if you’re on a Skype chat and walking from room-to-room. The wired devices are getting the full 125/10 that my internet provides, so that’s good.
One interesting note is that, while I have the option to prioritize devices using my phone, there doesn’t seem to be a “permanently prioritize this device until further notice” option. All I can select is one hour, two hours, or four hours. Seems like an odd omission, but I almost never use prioritization in real-world scenarios anyway.
Subject: General Tech | December 14, 2017 - 01:49 PM | Jeremy Hellstrom
Tagged: AT%26T, direcTV, security, networking, linksys
To start off with the bad news, as is our wont, DirecTV kits have a rather serious code injection problem. A researcher was able access the root shell on the Linksys WVBR0-25 wireless video bridge in less than 30 seconds, once he had access to one of the devices that the bridge was streaming to. As there are many infected machines out there, often PC's used only as video players as simple, poorly secured machines, this would mean your machines could be recruited into a botnet or mining pool quite easily. The researcher passed on his research to AT&T and Linksys 181 days ago he is quite disappointed they have yet to start develop a patch, according to The Register.
On a more positive note, AT&T is testing broadband over powerlines in Georgia and an undisclosed location outside the USA. They did not release any specifics of the current bandwidth which they can provide, though their goal is to surpass 1 gigabit per second. This will be quite the project as the testing we have done with powerline adapters did not show network connectivity anywhere near that speed in the best case scenarios, let alone when less than perfect wiring nor distance degraded the overall performance. You can check out more on that topic over at Slashdot.
"AT&T's DirecTV wireless kit has an embarrassing vulnerability in its firmware that can be trivially exploited by miscreants and malware to install hidden backdoors on the home network equipment, according to a security researcher."
Here is some more Tech News from around the web:
- How fast is a piece of string? Boffin shoots ADSL signal down twine @ The Register
- Crytek sues Star Citizen developers over game engine @ Ars Technica
- Flash bang walloped: Toshiba, Western Digital sign peace treaty over memory chip fabs @ The Register
- The Last Mile to Civilization 2.0: Technologies From Our Not Too Distant Future @ Techspot
- Intel to slap hardware lock on Management Engine code to thwart downgrade attacks @ The Register
- TSMC to spend $20bn on 3-nanometer chips @ Nikkei
- New battery boffinry could 'triple range' of electric vehicles @ The Register
Subject: General Tech | November 21, 2017 - 02:03 PM | Jeremy Hellstrom
Tagged: isp, networking, Internet, net neutrality, Autonomous System
If you are reading this from the US you probably have an opinion about the news out of the FCC today and should probably express that opinion to your various congress critters, even though Ajit Pai has stated he won't listen. As a backup plan you might want to take a read through this article over at Hack a Day which describes how you can set yourself up as your own ISP, aka an Autonomous System. The process is nowhere near as simple as setting up a home internet connection and you will need some dedicated equipment you may or may not have lying around. Those who live outside the USA should still take a look as there is some very interesting learning material in the article.
"It was during the purchase of data centre rack space that [Kenneth]’s challenge was laid down by a friend. Rather then simply rely on the connection provided by the data centre, they would instead rely on forging their own connection to the ‘net, essentially becoming their own Internet Service Provider."
Here is some more Tech News from around the web:
- Foldable Samsung Galaxy X smartphone support page leak suggests imminent release @ The Inquirer
- Intel finds critical holes in secret Management Engine hidden in tons of desktop, server chipsets @ The Register
- Researchers claim 400 of the world's top 50,000 websites track user keystroke behaviour @ The Inquirer
- US lab to build ARM-based supercomputer @ eeNews
- iPhone X: Bargain! You've just bagged yourself a cheap AR device @ The Register
- Another UAV licence price hike? Commercial drone fliers rage over consultation @ The Register
Subject: Networking | November 7, 2017 - 10:00 PM | Jim Tanous
Tagged: wi-fi, vpn, ubiquiti, networking, mesh, Amplifi HD, amplifi
Earlier this year we took a look at the AmpliFi HD Home Wi-Fi System as part of our review of mesh wireless network devices. AmpliFi is the consumer-targeted brand of enterprise-focused Ubiquiti Networks, and while we preferred the eero Mesh Wi-Fi System in our initial look, the AmpliFi HD still offered great performance and some unique features. Today, AmpliFi is introducing a new member of its networking family called AmpliFi Teleport, a "plug-and-play" device that provides a secure connection to users' home networks from anywhere.
Essentially a zero-configuration hardware-based VPN, the Teleport is linked with a user's AmpliFi account, which automatically creates a secure connection to the user's AmpliFi HD Wi-Fi System at home. Users take the small (75.85mm x 43mm x 39mm) Teleport device with them on the road, plug it in and connect it to the public Wi-Fi or Ethernet, and then connect their personal devices to the Teleport.
This provides a secure connection for private Internet traffic, but also allows access to local resources on the home network, including NAS devices, file shares, and home automation products. AmpliFi also touts that this would allow users to view their local streaming content even in locations where it would otherwise be unavailable -- e.g., watching U.S. Netflix shows while overseas, or streaming your favorite sports team while in a city where the game is blacked out.
In addition to traveling, AmpliFi notes that those with multiple homes or a vacation cottage could also benefit from Teleport, as it would allow you to share the same network resources and media streaming access regardless of location. In any case, a device like Teleport is still reliant on the speed and quality of your home and remote Internet connections, so there may be cases where network speeds are so low that it makes the device useless. That, of course, is a factor that would plague any network-dependent service or device, so while it's not a mark against the Teleport, it's something to keep in mind.
Teleport's features, while incredibly useful, are of course familiar to those experienced with VPNs and other secure remote connection methods. In terms of overall functionality, the AmpliFi Teleport isn't offering anything new here. The benefit, therefore, is its simple setup and configuration. Users don't need to setup and run a VPN on their home hardware, subscribe to a third party VPN service, or know anything about encryption protocols, firewall configuration, or network tunneling. They simply need to plug the Teleport into power, follow the connection guide, and that's it -- they're up and running with a secure connection to their home network.
You'll pay for this convenience, however, as the Teleport isn't cheap. It's launching today on Kickstarter with "early bird" pricing of $199, which will get you the Teleport device and the required AmpliFi HD router. A second round of early purchasers will see that price increase to $229, while final pricing is $269. Again, that's just for the Teleport and the router. A kit including two AmpliFi mesh access points is $399. There's no word on standalone pricing for the Teleport device only for those who already have an AmpliFi mesh network at home.
Regardless of the package, once you have the hardware there's no extra cost or subscription fee to use the Teleport, so frequent travelers might find the system worth it when compared to some other subscription-based VPN services.
The AmpliFi Teleport is expected to ship to early purchasers in December. We don't have the hardware in hand yet for performance testing, but AmpliFi has promised to loan us review samples as the product gets closer to shipping. Check out the Teleport Kickstarter page and AmpliFi's website for more information.
Subject: General Tech | September 29, 2017 - 12:53 PM | Jeremy Hellstrom
Tagged: icann, bind, dns, ksk, networking, security
ICANN have had to delay their planned upgrade to the root key signing keys used by DNS thanks to between 5-8% of key validators lacking the new KSK key. If a validator only possess the 2010 key, they would no longer be able to resolve DNS properly and the vast majority of the internet would disappear for stuck on the old system. The Register points out that the problem will actually be much larger as ICANN assumed that everyone has updated to the newest version of BIND DNS database, and only scanned those validators using the newest version.
The reason for the update is to increase the length of the root KSK that DNS depends on, which will greatly increase the security of anyone surfing the net and to help move this forward ICANN will be publishing a list of those out of date validators in the hopes publicity will spur them to upgrade. As with IPv6, we will wait and see.
"A multi-year effort to update the internet's overall security has been put on hold just days before it was due to be introduced, over fears that as many as 60 million people could be forced offline."
Here is some more Tech News from around the web:
- Benchmarks Show Firefox 57 Quantum Doing Well, But Chrome Largely Winning @ Phoronix
- TSMC announces plan to build 3nm fab in Taiwan @ DigiTimes
- Microsoft continues Linux love-in by joining the Open Source Initiative @ The Inquirer
- Ignite Overview @ Microsoft
- Microsoft gives all staff a marked-up 'Employee Edition' of Satya Nadella's new book @ The Register
- ZorinOS Is a Great Linux Desktop For Any User @ Linux.com
- Patch alert! Easy-to-exploit flaw in Linux kernel rated 'high risk' @ The Register
- Air Force Gives 10-Year-Old Orbiting Satellite To Ham Radio Operators @ Slashdot
- Whole Foods hacked and credit card info bagged @ The Inquirer
- E-Win Flash Series Gaming Chair @ TechPowerUp
Subject: General Tech | August 22, 2017 - 12:00 AM | Sebastian Peak
Tagged: WRT32X, router, networking, linksys, Killer Prioritization Engine, Killer Networking, gaming, AC3200
Linksys has announced a router that they say is 'built purely for gaming' with the WRT32X, an AC3200 router with a 1.8 GHz dual-core processor and built-in Killer Prioritization Engine.
"The WRT32X takes gaming to the next level. The router built purely for gaming features AC3200 speed and the Killer Prioritization Engine. The Killer Prioritization Engine identifies, prioritizes and accelerates gaming network traffic above all other devices in your home to deliver a faster, superior gaming experience. The Killer-enabled WRT32X also synchronizes with Killer-enabled PCs to give gaming traffic the highest priority on your network. Turning the Killer Engine on protects from extreme lag spikes and reduces lag by 77%, delivering consistent and superior reaction time during intense gaming scenarios."
Linksys lists the features of the WRT32X as follows:
- 1.8 GHz CPU: Dual-Core promotes simultaneous high-speed data processing.
- Pro-grade Gigabit Ethernet Switch: Gigabit (10/100/1000) is 10X faster than Fast Ethernet.
- Dual-Band (2.4 + 5 GHz): N600 + AC2600 Mbps.
- Killer Prioritization Engine: The first router that prioritizes gaming.
- Advanced Security: WPA2 encryption and SPI rewall help keep your network safely connected.
- Customized Gaming Interface: Custom-built interface and firmware for gaming traffic control.
- 256MB Flash and 512MB of RAM Memory: Handle more without delay for optimal performance.
- 4 High-Performance Antennas: Engineered to enhance dual-band communication; four external, adjustable antennas ensure supreme Wi-Fi signal strength.
- eSATA, USB 3.0, and USB 2.0 Ports: Share content via an external storage device with ultra-fast data transfer speeds. USB 3.0 delivers enhanced performance over USB 2.0; eSATA delivers optimal data transfer speeds from external SATA drives and accommodates USB 2.0.
The WRT32X carries an MSRP of $329.99, with availability TBA.
Subject: General Tech, Networking | July 12, 2017 - 01:21 PM | Jeremy Hellstrom
Tagged: RT-AC1900P, asus, wireless router
If you are more interested in quick wireless networking than you are in upgrading to a 10Gbps wired network then perhaps this review over at The Tech Report will catch your fancy. It is similar in design and size to the RT-AC68U, at 6.2x8.6x3.2" but it hides some upgrades inside. The processor has been upgraded to a dual core Broadcom BCM4709C0 running at 1.4 GHz and the internal memory has been doubled to 256MB though the radio remains the same with rated transfers of 600 Mbps on the 2.4 GHz band and 1300 Mbps on the 5GHz band. Testing showed some improvements compared to the previous model when it came to range and broadcasting through obstacles, with some increase in transfer speeds as well. Check it out here.
"Asus' RT-AC1900P carries on the legacy of the company's popular RT-N66U "Dark Knight" router. This time around, the unit comes armed with an 802.11ac radio for faster performance on the 5GHz band. We fired up this router in our crowded wireless airspace to see whether it can stand above the rest."
Here is some more Tech News from around the web:
- Tech Giants Rally Today in Support of Net Neutrality @ Slashdot
- Hackers able to turbo-charge DJI drones way beyond what's legal @ The Register
- Intel eyes AMD's Epyc with launch of Skylake-based 'Purley' Xeon processors @ The Inquirer
- It's July 2017 – and your expensive HoloLens can be pwned over Wi-Fi @ The Register
- 24 Cores and the Mouse Won't Move: Engineer Diagnoses Windows 10 Bug @ Slashdot
- If at first you don't succeed, you're Microsoft pushing its magical white space broadband @ The Register
- Stop the clocks. Windows Phone is dead @ The Inquirer
Subject: Networking | May 30, 2017 - 05:00 AM | Sebastian Peak
Tagged: wireless, wifi extender, wi-fi, Rivet Networks, network, msi, lan, Killer xTend, Killer Networking, gigabyte, Ethernet, computex 2017, computex
Rivet Networks has a new Killer Networking product, but it isn't a line of NICs or Wireless adapters; it's actually a combination of both interfaces (including a minimum of three Gigabit Ethernet ports) that combine to turn your PC into switch and a Wi-Fi extender. They call the new product Killer xTend, and Rivet Networks has partnered with MSI and GIGABYTE to bring the new technology to market.
"Killer xTend delivers powerful network extension capabilities to your computer by integrating a network switch that includes at least three Killer Ethernet ports and using a Killer Wireless-AC module as a Wi-Fi extender. This allows your computer to share its network access with other nearby wired and wireless devices with a strong, powerful network connection.
Consumers no longer need to mess with switches and network extenders that are expensive and difficult to configure. Instead, they can use Killer’s innovative new xTend Technology to connect devices such as gaming consoles, smart phones and tablets directly to their gaming PCs. Killer xTend keeps your games, voice, and video fast and smooth because high priority traffic on the Killer PC is prioritized above the traffic from connected devices. Killer xTend also delivers amazing speeds – with potential throughput up to 1 Gbps for each Killer E2500 plus another 867 Mbps for the Killer Wi-Fi module."
The first motherboard launching with Killer xTend is the MSI Z270 GODLIKE GAMING, with three Killer E2500 NICs and a Killer Wireless-AC 1535 module onboard.
"...the new GODLIKE adapts the Killer™ xTend technology as well and delivers powerful network extension capabilities by integrating a network switch that includes 3 Killer Ethernet ports and a Killer Wireless-AC module as a Wi-Fi extender. This allows the GODLIKE GAMING to provide the network access to other nearby wired and wireless devices with a strong, powerful network connection. Gamers no longer need to mess with switches and network extenders that are expensive and difficult to configure – instead they can use Killer’s innovative new xTend Technology to connect devices such as gaming consoles, smart phones, and tablets directly to your gaming PC. The Killer xTend keeps your games, voice, and video fast and smooth because high priority traffic on the Killer PC is prioritized above the traffic from connected devices. Killer xTend also delivers amazing throughput to your home – with potential throughput up to 1 Gbps for each Killer E2500 plus another 867 Mbps for the Killer Wi-Fi module."
GIGABYTE's AORUS Gaming Series will include Killer xTend, though no specific models were mentioned in the press release from Rivet Networks.
Full press release after the break.
Subject: General Tech | May 28, 2017 - 07:10 PM | Tim Verry
Tagged: samba, linux, ransomware, security, networking
Last week, the development team behind Samba – popular software suite used on Linux and Unix clients and servers that uses TCP/IP protocol for file and print sharing to SMB/CIFS clients (including Microsoft Windows) – released a security advisory along with patches for a remote code execution hole that has been present in Samba for seven years since the release of Samba 3.5.0 in March 2010. The vulnerability, classified under CVE-2017-7494, allows an attacker to upload malicious code to a Samba server and get the server to run the code by sending a malformed IPC request that references the local file path. The Samba server will run the code in the malicious shared library (.so) file even though it is from an untrusted remote source.
The bad news is that this is a fairly serious flaw that could lead to an attacker successfully holding a business or home user’s files (including backups!) at ransom, stealing data, or using the now owned file server to attack other network resources that trust the file server. If not securely configured (e.g. allowing anonymous writes), the attack could even be wormable which would allow it to self-replicate across the network or Internet. Further, while various security firms have slightly different numbers, they all seem to agree that around 100,000 Internet-accessible machines are running vulnerable versions of Samba.
It is not all bad news though, and in some respects this vulnerability is not as big of an issue as the WannaCry ransomware and EternalBlue SMB vulnerability because in order to successfully exploit the Samba flaw an attacker needs to obtain credentials to upload the malicious code to the file share(s) which need to be writeable in the first place and not running as noexec under a SELinux policy. Also, attackers need to know or guess the local path name of the files on the file share to send the malformed IPC request. More importantly, the Samba team released three security releases (4.6.4, 4.5.10, and 4.4.14) for the newer branches and is working with OS distributions on providing patches for older Samba versions. For systems that cannot be updated or patched, there is also a workaround that can be implemented by modifying the global Samba config file to contain the setting “nt pipe support = no”. While this will break some expected Windows functionality (mainly machines will not be able to access null shares and will need to use the specific share path rather than just the server path), it will make it so that Samba will not accept the malicious requests.
Perhaps the most worrying aspect of this vulnerability is that security researchers estimate that up to 90% of the vulnerable Internet-connected Samba endpoints do not have a direct patch or update available yet and may not ever get one. While the enterprise hardware and even bigger consumer and SMB hardware providers will provide support for this in the form of patches or firmware updates, there is a sea of home routers, NAS boxes, file and print servers, and IoT devices running on home networks that are not open to user updates and may not ever get firmware updates. The best thing to do in this scenario according to the security advisory (if you can’t just not use it or replace it with different hardware that can be patched or isn’t affected of course) is to not expose it to the Internet. There would still be a risk of it being exploited should someone get a virus on a client machine through email, malicious downloads, or social engineering though. Considering these home NAS devices are usually used as destinations for backups, the risk of ransomware not only infecting client machines but also the main file share and network backups is scary. I have always been a fan of offline and/or cloud backups and in these modern times they are more important than ever with the rise of ransomware and other profit motivated viruses.
If you are not sure if your network is affected, there are tools being made available (including a Metasploit module, nmap scripts, and Internet scans) to help you determine that and reduce your attack surface using that information by updating to the latest security release, applying patches, updating, using SELinux policies to prevent the server from executing files itself, and preventing them from communicating with the Internet in order of effectiveness.
All that is to say don’t panic, stay vigilant, and make sure your important data is properly backed up and secured as much as possible!
Subject: General Tech | March 6, 2017 - 01:42 PM | Jeremy Hellstrom
Tagged: wifi, networking
Our own Sebastian Peak has delved into the nightmare world of testing WiFi, specifically MU-MIMO and explained some of the difficulties you encounter when testing wireless networks. It is now Ars Technica's turn to try to explain why your 2.4GHz router never delivers the advertised 1,000 Mbps as well as how to test your actual performance. As with many products, the marketing team has little interest in what the engineers are saying, they simply want phrases they can stick on their packaging and PR materials. While the engineers are still pointing out that even the best case scenarios involving a single user less than 10 feet away, with clear line of sight will not reach the theoretical performance peak, the PR with that high number has already been emailed and packages are printing.
Drop by Ars Technica for a look at how the current state of WiFi has evolved into this mess, as well as a dive into how the new technologies work and what performance you can actually expect from them.
"802.11n was introduced to the consumer public around 2010, promising six hundred Mbps. Wow! Okay, so it's not as fast as the gigabit wired Ethernet that just started getting affordable around the same time, but six times faster than wired Fast Ethernet, right? Once again, a reasonable real-life expectation was around a tenth of that. Maybe. On a good day. To a single device."
Here is some more Tech News from around the web:
- AMD Ryzen with VMWare ESXi: A Pink Screen of Death @ [H]ard|OCP
- Windows 10 Build 15048 Has a Windows Mixed Reality Demo You Can Try @ Slashdot
- User rats out IT team for playing games at work, gets them all fired @ The Register
- If we must have an IoT bog roll holder, can we at least make it secure? @ The Register
- Microsoft wants you to plan a new generation of legacy systems @ The Register
- Nintendo tells Switch users that dead pixels are not its problem @ The Inquirer
- One million decrypted Gmail and Yahoo accounts for sale on the bloody dark web @ The Inquirer
- The iflix HD Streaming Q&A With Ash Crick @ TechARP
Subject: Networking, Storage | March 4, 2017 - 11:57 PM | Scott Michaud
Tagged: netgear, Intel, Avoton, recall
While this is more useful for our readers in the IT field, NETGEAR has issued a (non-urgent) recall on sixteen models of Rackmount NAS and Wireless Controller devices. It looks like the reason for this announcement is to maintain customer relations. They are planning to reach out to customers “over the next several months” to figure out a solution for them. Note the relaxed schedule.
The affected model numbers are:
- WC7500 Series:
- WC7500-10000S, WC7500-100INS, WC7500-100PRS, WB7520-10000S, WB7520-100NAS, WB7530-10000S, WB7530-100NAS
- WC7600 Series:
- WC7600-20000S, WC7600-200INS, WC7600-200PRS, WB7620-10000S, WB7620-100NAS, WB7630-10000S, WB7630-100NAS
The Register noticed that each of these devices contain Intel’s Avoton-based Atom processors. You may remember our coverage from last month, which also sourced The Register, that states these chips may fail to boot over time. NETGEAR is not blaming Intel for their recall, but gave The Register a wink and a nudge when pressed: “We’re not naming the vendor but it sounds as if you’ve done your research.”
Again, while this news applies to enterprise customers and it’s entirely possible that Intel (if it actually is the Avoton long-term failure issue) is privately supporting them, it’s good to see NETGEAR being honest and upfront. Problems will arise in the tech industry; often (albeit not always) what matters more is how they are repaired.
Subject: General Tech | January 8, 2017 - 11:58 AM | Tim Verry
Tagged: networking, netgear, CES 2017, CES
Netgear introduced a new semi-managed switch under its Nighthawk brand called the Nighthawk S8000. The new gigabit switch offers eight ports and a GUI web management interface.
The Nighthawk S8000 keeps the stealth bomber design aesthetic of its larger router brethren with clean lines, sharp angles, and a dark zinc alloy housing. The one downside to this design is that these switches are not stackable but if you need that many ports you are probably looking at a bigger single switch anyway.
Exact specifications are not yet available, but the Layer 2 GS808E switch reportedly offers per-port prioritization and QoS (Quality of Service), DoS (Denial of Service) protection, and IGMP snooping (they don't list which version though so I can't say if this would work well with AT&T Uverse and running TV and PCs on). There are reportedly three pre-set modes and two user customizable profiles that can be set for each port depending on usage: gaming, media streaming, and standard LAN. Further, there are four (Netgear’s site lists 3 in some places) levels of prioritization.
The gigabit switch does support link aggregation (port trunking) up to 4 ports for a single 4Gbps connection to devices that also support link aggregation. This can be configured as a single 4Gbps connection or as redundancy in case one port or cable fails. The use case for something like this would be multiple PCs sending and receiving large amounts of data from a NAS at the same time where the wider connection back to the switch can be meaningfully utilized.
The Nighthawk S8000 comes with a 3 year warranty and will be available in March for $99.99.
There may be better options, especially at $99.99 but fans of Netgear’s Nighthawk wireless routers might be interested. It is hard to say if it is worth the price yet as independent reviews are not out yet. For those interested, PC Gamer has more photos of the switch.
Follow all of our coverage of the show at https://pcper.com/ces!
Subject: Networking | January 6, 2017 - 07:02 AM | Scott Michaud
Tagged: router, iot, internet of things, bitdefender, 802.11ac
A couple of years ago, Bitdefender released the Bitdefender BOX, which was a router designed for security that was aimed at home users. They are taking another shot at it for this year’s CES with the second-generation Bitdefender BOX. It is now running on a 1.2 GHz, dual-core ARM Cortex A9 SoC, backed with 1GB of RAM.
The goal is to have a security-conscious company stand between all of your internet-of-things devices, allowing your TVs, security cameras, and whatever else to function without being a foothold for malicious actors.
Pricing and availability has not yet been finalized, but PCWorld cites a spokesperson for the company that expects the device to sell for $199 USD with a $99/year subscription. If the service is the same as the first-generation device, and I understand the product page correctly, then this subscription also provides a license to their TotalSecurity antivirus as well.
Follow all of our coverage of the show at http://pcper.com/ces!
Subject: Networking | January 4, 2017 - 07:40 PM | Scott Michaud
Tagged: wifi, router, mesh, hivespot, hivedot, gigabit router, asus, 802.11ac
ASUS has just announced the HiveSpot and HiveDot Mesh WiFi systems, which both combine multiple access points into a single network. Any individual node could be configured as either a router or a repeater, but the system is designed around one acting as a router and the rest, repeaters. The main difference between the two models is the higher-end set, the HiveSpot, utilize an extra, 5 GHz band, running 867 megabit, that’s dedicated to communication between the access points.
Because of this, the HiveSpot is listed as AC2134 while the HiveDot is AC1300, but devices that connect to this network will see two, 650 megabit bands in either case. What the HiveSpot will get you is higher performance (and maybe stability) should multiple devices be communicating with different nodes at the same time. With the HiveDot, the routers will be sharing the same bandwidth as the devices connecting to them.
ASUS wasn’t too clear about pricing in their press release, but CNet is reporting that they will be sold in bundles of three, which is the minimum for the mesh network. Three HiveSpot devices will carry an MSRP of $399 USD, while three HiveDots, $299. In other words, it will cost you $100 if you want the high-bandwidth, dedicated link between the nodes.
Follow all of our coverage of the show at https://pcper.com/ces!
Subject: General Tech, Networking | January 3, 2017 - 03:01 AM | Sebastian Peak
Tagged: wireless keyboard, Smart Storage, smart home, Smart Assistant, Lenovo, connected, CES 2017, CES, Alexa, 500 Multimedia Controller
Lenovo is announcing a trio of new connected devices beginning with the Amazon Alexa-powered Smart Assistant.
“The Lenovo Smart Assistant with Amazon Alexa is like having your own digital assistant at home. Featuring Amazon’s Alexa Voice Service, this voice-controlled high-definition speaker with far field microphones, is there to lend a hand whenever you need it. Want to know what the morning traffic is like? Forgot to order that book from Amazon? Longing to hear your favorite playlist? Simply ask Alexa. She has all the answers to help simplify your life. What’s more, she can even help remotely with the Amazon Alexa App, which is free to download for Android and iOS.”
The Smart Assistant offers high definition sound with a speaker system that combines a 5W treble and 10W bass speaker, and the Harman Kardon Edition takes this further with a ported design for enhanced sound.
Next we have Lenovo’s Smart Storage, which provides up to 6 TB of connected storage over a wireless (or wired) home network.
“Despite this remote storage center’s compact size, the Lenovo Smart Storage comes with a big challenge: How will you and your family fill it? Capable of storing up to 6 TB of photos, movies, and other digital files, this dual-band WiFi storage system can connect wirelessly to almost any smart device you own, worldwide. You’ll maintain absolute administrative control, ensuring your data and content are secure and safe—and with Auto Sync enabled, your data will back-up automatically when within WiFi range. DLNA support also ensures you’ll be able to enjoy your movies and music on any device, anytime.”
Finally we have the Lenovo 500 Multimedia Controller, which combines a compact keyboard and touchpad in a small wireless control device for the living room.
“Want to browse the web from your couch? Or turn on your favorite playlist from the dining table? We’ve got you covered with the Lenovo 500 Multimedia Controller. It’s not only a mouse and keyboard in one, it’s also a remote control optimized for your Windows operating system. With an ergonomic design and up to 8 months battery life, the versatile Lenovo 500 Multimedia Controller will make your life easier.”
The controller is designed for Windows PCs (support for Windows 7 through 10), and uses a nano USB dongle for its 2.4 GHz wireless connection. The touchpad DPI is adjustable for user preference, and the unit offers up to 8 months of battery life from a pair of AAA batteries. At 5.71 x 3.37 x 0.74 inches (and 141 grams) this is a pretty small device, but certainly larger than some of the smart TV remote keyboards certain models have shipped with.
Follow all of our coverage of the show at https://pcper.com/ces!
Subject: Networking, Mobile | October 17, 2016 - 11:00 PM | Sebastian Peak
Tagged: Snapdragon X50, snapdragon, qualcomm, modem, mobile, mmWave, LTE, cellular, 5G
Qualcomm has officially unveiled the development of a new 5G modem with the Snapdragon X50, which targets OEMs and early 5G development. The X50 supports milimeter wave (mmWave) technology initially, and rather than replace existing LTE solutions the X50 is designed to work alongside LTE modems integrated into Snapdragon SoCs, for a seamless handoff between 5G and 4G networks.
"The Snapdragon X50 5G modem will initially support operation in millimeter wave (mmWave) spectrum in the 28GHz band. It will employ Multiple-Input Multiple-Output (MIMO) antenna technology with adaptive beamforming and beam tracking techniques, which facilitates robust and sustained mobile broadband communications in non-line-of-sight (NLOS) environments. With 800 MHz bandwidth support, the Snapdragon X50 5G modem is designed to support peak download speeds of up to 5 gigabits per second.
Designed to be used for multi-mode 4G/5G mobile broadband, as well as fixed wireless broadband devices, the Snapdragon X50 5G modem can be paired with a Qualcomm® Snapdragon™ processor with an integrated Gigabit LTE modem and interwork cohesively via dual-connectivity. Gigabit LTE will become an essential pillar for the 5G mobile experience, as it can provide a wide coverage layer for nascent 5G networks."
Ratification of an official “5G” standard has not taken place, but Qualcomm hopes to position itself at the forefront of its development. The mmWave technology (which is explained in this video) is only one part of the puzzle:
"Work has begun on defining, standardizing and designing the new OFDM-based 5G New Radio (NR) as part of the global 3GPP standard. 5G NR is being designed to support a wide variation of device-types, services and deployments. It is also being designed to get the most out of every bit of spectrum across a wide array of available spectrum bands and regulatory paradigms."
(More information is available on Qualcomm's 5G Technologies page.)
The Snapdragon X50 modem is set to begin sampling to OEMs in the second half of 2017, with the first half of 2018 projected for the first commercial products featuring the new modem.