头条推荐
一 | The Department of Homeland Security is telling state and local governments to update software and beef up security around devices connected to the nationwide Emergency Alert System (EAS). The recommendation comes days after security researcher Ken Pyle revealed vulnerabilities in devices used by officials to encode EAS alerts.,Pyle told KerbsOnSecurity that he first discovered the vulnerabilities in 2019 after buying old EAS equipment on eBay. He quickly found the vulnerabilities and alerted the FBI, DHS, and the manufacturer of the devices. Pyle decided to give the manufacturer and government time to address the issue before going public.,DHS Inspector General Overseeing Jan.6 Secret Service Probe Previously Misled Investigators: Report4 August, 12:27 GMT,He started to worry after the Jan 6, 2021 riot at the US Capitol, fearing that the vulnerabilities could be used “to start a civil war.”,That is because despite a patch being issued in 2019, many of the devices have not been updated either because they are too old for the new firmware or because of simple neglect by the operators. Pyle also says that many operators do not perform basic security measures recommended by the manufacturer, like changing the default password and putting the devices behind a firewall.,This is a problem because of the way EAS messages are distributed. There is no central authority and the process is automated in most cases. This means that someone could issue an alert locally and as long as it is accepted as a real EAS alert, it could spread nationwide.,“These devices are designed such that someone locally can issue an alert, but there’s no central control over whether I am the one person who can send or whatever,” Pyle told KerbsOnSecurity. “If you are a local operator, you can send out nationwide alerts. That’s how easy it is to do this.”,One device obtained by Pyle was a non-functional EAS device, purchased from an electronics recycling company. While the device no longer operated, the person who discarded it and the recycling company neglected to wipe the hard drive, giving Pyle access to cryptographic keys allowing him to broadcast messages on Comcast’s network, the third largest cable company in the US.,Comcast told KerbsOnSecurity in a statement that the EAS was lost by a third-party shipper and that the keys and credentials found on the device will no longer work on their system. They also thanked Pyle for his research and for informing them about the issue.,EAS vulnerabilities have been exploited in the past. In 2013, someone hacked the EAS networks in Great Falls, Montana, and Marquette, Michigan, using their access to issue an alert saying that zombies are rising from their graves. That same prank was repeated in Indiana in 2017. There have been other incidents, though they did not include zombies.。

二 | 对此,他们向张继科先生和广大网友表示诚挚的歉意,并进行了深刻的反思。

三 | 对两位当事的解说嘉宾,组委会已于昨日(8月1日)解除了合作关系。来源:赛事组委会HYROX一直致力于打造一项每个人都可以参与的竞技型健身跑赛事,主张“每个人都是自己的冠军”的运动精神内核。他们对张继科先生在比赛中表现出的拼搏精神与坚韧的运动品质表示由衷的钦佩和无比的敬意。但因他们直播管理工作中的疏忽,给各方均带来了负面的体验,他们非常抱歉。他们将完善解说嘉宾的遴选与培训机制,明确专业规范与行为准则。加强直播内容的审核与管理,杜绝此类情况再次发生。他们也将以此为鉴,持续提升赛事各环节的组织水平,让每一位健身跑参赛者,都能在HYROX这项赛事中,感受到最热忱的欢迎和最硬核的运动体验。致歉声明中还表示,HYROX中国已经向张继科先生及本次一同参赛的队友发出邀请,诚挚地邀请参与未来HYROX中国的各类比赛。

四 | 极目新闻记者综合整理(来源:极目新闻)

五 |
Current article:http://oj6zx.zanjionglangzhaizhizaxiying.buzz/list_gmi/omq.html
Published on:13:22:10