West Antarctic Ice Sheet May Not Be Losing Ice As Fast As Once Thought

Wednesday, October 21, 2009

New ground measurements made by the West Antarctic GPS Network (WAGN) project, composed of researchers from The University of Texas at Austin, The Ohio State University, and The University of Memphis, suggest the rate of ice loss of the West Antarctic ice sheet has been slightly overestimated.




"Our work suggests that while West Antarctica is still losing significant amounts of ice, the loss appears to be slightly slower than some recent estimates," said Ian Dalziel, lead principal investigator for WAGN. "So the take home message is that Antarctica is contributing to rising sea levels. It is the rate that is unclear."

In 2006, another team of researchers used data from the Gravity Recovery and Climate Experiment (GRACE) satellites to infer a significant loss of ice mass over West Antarctica from 2002 to 2005. The GRACE satellites do not measure changes in ice loss directly but measure changes in gravity, which can be caused both by ice loss and vertical uplift of the bedrock underlying the ice.

Now, for the first time, researchers have directly measured the vertical motion of the bedrock at sites across West Antarctica using the Global Positioning System (GPS). The results should lead to more accurate estimates of ice mass loss.

Antarctica was once buried under a deeper and more extensive layer of ice during a period known as the Last Glacial Maximum. Starting about 20,000 years ago, the ice began slowly thinning and retreating. As the ice mass decreases, the bedrock immediately below the ice rises, an uplift known as postglacial rebound.

Postglacial rebound causes an increase in the gravitational attraction measured by the GRACE satellites and could explain their inferred measurements of recent, rapid ice loss in West Antarctica. The new GPS measurements show West Antarctica is rebounding more slowly than once thought. This means that the correction to the gravity signal from the rock contribution has been overestimated and the rate of ice loss is slower than previously interpreted.

"The published results are very important because they provide precise, ground-truth GPS observations of the actual rebound of the continent due to the loss of ice mass detected by the GRACE satellite gravity measurements over West Antarctica" said Vladimir Papitashvili, acting director for the Antarctic Earth Sciences Program at the National Science Foundation, which supported the research.

WAGN researchers do not yet know how large the overestimation was. A more definitive correction will be conducted by other researchers who specialize in interpreting GRACE data. Previous estimates of postglacial rebound were made with theoretical models. Assimilation of the direct GPS results into new models will therefore produce significant improvements in estimations of ice mass loss.

The results will appear in the electronic journal Geochemistry, Geophysics, Geosystems of the American Geophysical Union and the American Geochemical Society.

A team from The University of Texas at Austin's Jackson School of Geosciences (Ian Dalziel, lead principal investigator), The Ohio State University's School of Earth Sciences (Michael Bevis), and The University of Memphis' Center for Earthquake Research and Information (Robert Smalley, Jr.) performed the WAGN project.

The network consists of 18 GPS stations installed on bedrock outcrops across West Antarctica. Precise, millimeter level, three-dimensional locations of the stations, which are bolted into the bedrock, were determined during measurements made from 2001 to 2003 and from 2004 to 2006, the two measurements being at least three years apart. The difference in the positions during the two time periods indicates the motion of the bedrock.

The WAGN data were supplemented with data from the first year of the Polar Earth Observing Network (POLENET) project, a project to establish a more sophisticated, continuously recording network of GPS and seismic stations, including the already established WAGN sites. POLENET will further improve our understanding of the interaction between the solid earth and ice sheets at both poles. The lead principal investigator of the U.S. Antarctic contribution to POLENET is Terry Wilson of The Ohio State University.

The West Antarctic GPS Network and the U.S. Antarctic contribution to the Polar Earth Observing Network of the International Polar Year were both funded and logistically supported by the Office of Polar Programs of the National Science Foundation.

credit:sciencedaily

[Read More...]

Sandboxie: Blocking Web-Based Malware From Your PC

There is no safe neighborhood anywhere on the Internet. Even honest reputable sites, such as The New York Times, can inadvertently serve up malware. If you don't keep all the software on your computer patched with the latest bug fixes, you are constantly at risk – malware exploits known bugs to install itself.

Now that Windows does a reasonably good job of self-updating, the bad guys have taken to attacking other software, such as the Adobe Acrobat Reader and the Flash player plug-in, which don't automatically install patches as well as Windows does. And, up to date antivirus software only provides limited protection.



Enter Sandboxie, an excellent program that builds a virtual sandbox around your web browser, making it impossible for your computer to accidentally get infected.

When you run a program in a sandbox, you are really running Sandboxie and it, in turn, is running the program in a walled-off virtual box. Originally developed for Internet Explorer, Sandboxie can now put a sandbox around any Windows program.


Programs running a sandbox can, by default, see everything on the computer. What they can't do is make any permanent changes. When sandboxed programs try to read files, Sandboxie does not interfere. However, when they try to create new files, Sandboxie intercepts the requests and creates the files in another location. The running program is oblivious to this re-direction. It thinks it's talking to Windows, but it really is talking to Sandoxie. The movie The Truman Show offers a pretty good analogy.


If anything malicious gets accidentally installed on your computer while browsing with a sandboxed browser, it lives only in the sandbox. Specifically, the malware may think it got installed into C:\Program Files, but it actually lives in C:\Sandbox\youruserid\DefaultBox\drive\C\Program Files. Empty the sandbox and the malicious software is gone. This is shown visually on the home page of sandboxie.com. The initial state of a computer is shown below:



Internet explorer 8 fixes, IE8 fixes

The top checkerboard pattern illustrates a hard disk with no sandbox. In the bottom one, the virtual sandbox is shown as a yellow box.

When a program runs, the changes it makes to the file system and the hard disk are shown as red boxes. In the image below we see that normally the red boxes/changes are scattered all over.



After an application makes changes

However, Sandboxie forces all changes made by a sandboxed program to live inside the sandbox. If any of the changes are not wanted, just empty the sandbox.

If this sounds like virtualizaiton, it is. But it's small, lightweight virtualization, whereas full blown virtualization products are large and cumbersome. Also, the changes Sandboxie makes to your computer are minimal compared to full-fledged desktop virtualization software like that offered by VMware. Has a problem occurred to you? Most likely, there is a simple solution. Sanboxie is nothing if not a well thought out program.

If you don't want malware on your computer, even if it's sandboxed, you can configure a sandbox so that all changes made by any program are discarded as soon as the last program in the sandbox shuts down. You can see this below:



Internet explorer 8 fixes, IE8 fixes

There are two sandboxes on this computer, the default one and another called ThrowMeAway (I chose the name). As the name implies, all changes made in this sandbox are always discarded. If you really want a private browsing mode, this beats them all.

[Read More...]

The Best Security for Wireless Networks

Securing a wireless network isn't a hard task. The cheat sheet is relatively small. However, the technical press continues to be flooded with articles and blogs containing technical mistakes.

Take, for example, everyone's trusted information source, Consumer Reports Magazine. I'm a big fan of the magazine, having subscribed to the hard copy edition for years. But they seem out of their league, when it comes to computers.



On August 6, 2009 a blog posting at the magazine's website suggested using WEP security for wireless networks. This is very poor advice. A week after the posting, an editor corrected it, to say they recommend WPA security. This too, is not the best option. Even after being shamed into a correction, they still got it wrong.

So, let me try to offer up just what most people (and Consumer Reports) need to know about securing a wireless network.

Starting at the Beginning

To begin with, there are four types of Wi-Fi networks (A, B, G and N). But the security is not tied to any one type.

If you can connect to a wireless network without entering a password, then there is no security. In this context, the term "security" refers to encrypting data as it travels over the air.

The idea being to prevent a bad guy from capturing all the information coming into and out of a victims' computer and, in effect, looking over their shoulder despite being a few hundred feet away.

Wi-Fi networks offer three security options: WEP, WPA and WPA2. As a simplistic introduction, think of WEP as bad, WPA as just fine and WPA2 as great.

WEP is the oldest security option and it has been shown to be very weak. It may be better than no security at all, but not by much. Don't use it. Other than Consumer Reports magazine, the last recommendation to use WEP was issued in 2005.

WPA is technically a certification, not a security standard, but since it includes only one security protocol, TKIP, they are often confused. When people refer to WPA security, they are really referring to the TKIP protocol.

The combination of WPA and TKIP is not the best, but it's reasonably good. If you have a choice, you should opt for the best security (next topic), but if you don't have a choice (more later) TKIP is reasonably strong.

WPA2 is also, technically, a certification rather than a security standard. WPA2 includes two security standards: TKIP and CCMP. If you are using TKIP, it doesn’t matter whether the router is WPA or WPA2. TKIP is TKIP either way.

The best security option is CCMP and it's only available in WPA2, so, here again, the security protocol is often confused with the certification. When people refer to WPA2 security, they are really referring to CCMP.

But no one refers to CCMP (don't ask what it stands for). For whatever reason, the CCMP security protocol is referred to, incorrectly, as AES. So, when you are configuring a router, you need to first select WPA2, then you need to select AES (rather than TKIP) to get the best possible security and encryption.

WPA TKIP Flaws

The TKIP security protocol (often referred to as WPA) is flawed. The first flaw came to light in November 2008, the second one just last month. But neither flaw is serious.

The first flaw can be defended against simply by disabling Quality of Service (QOS) in your router. Very few people make use of QOS.

The second flaw was described by security expert Steve Gibson as mostly theoretical. For example, it requires that the victim’s computer be out of radio reception range from the router. The bad guy has to connect to the router on one side and the victim on the other side. The bad guy has to be logically and physically positioned between the victim and the router.

Neither flaw lets the bad guy recover the password and they only support decrypting very small data packets. None of these small packets will contain any of your data.

[Read More...]

Protect Yourself on Facebook

Tuesday, October 20, 2009

Love them or hate them; social networking sites are here to stay. And your users are going to find ways to use them from home, from work, from smart phones, from shared computers, or from anywhere else they care to.
The whipped cream is out of the can. Now what can we do about it?

So, how secure are these sites?



I’ve experienced several classic Web security issues in each of the sites I frequent, and without a doubt there remain many vulnerabilities to be discovered. But that hasn’t stopped me from using them.
Like any decision involving risk, I’ve studied the issues, minimized my own exposure, and I’m getting on with what I care to do.

Let’s start by looking at the issues briefly.

Web apps:

Well, for starters, they are Web applications, and as such they’re potentially vulnerable to a plethora of issues, from the OWASP Top-10 and beyond – and yes, there are far more than 10. And don’t think for a moment that all web application vulnerabilities solely place the application at risk. Many also put the app’s users at risk: cross-site scripting (XSS), cross-site request forgery (CSRF), and others can be used to attack the users quite easily.
As a user of a social networking site, you’re placing your (and your employer’s) data at risk.

Active content:

Long-time readers of this column (hi Mom!) have heard me talk about the dangers of active content many times. Javascript, Java applets, Flash, ActiveX, and many others are all examples of active content. And guess what? Every popular social networking site in existence – or at least with a significant population of users – absolutely requires active content in order for the site to function.
The bottom line: by allowing active content into your browser, you are trusting someone else’s code to run on your computer safely. Well, what’s the big deal? We do that all the time. Well, now the code is dynamic and maintained somewhere else, and you’re trusting it every time. Gulp!

Domain of trust:

Some of the HTML, Javascript, etc., that arrives in your browser comes from (say) Facebook. Fair enough, if you’re going to use Facebook, you’ll need to trust that content. But your browser isn’t so discerning. Some of the stuff that comes into it while you’re on Facebook might be provided by someone else: another Facebook user; an attacker; a third party application on Facebook. If your browser trusts Facebook, chances are it’s also going to trust that code. This extends the active content exposure pretty substantially.

User-supplied content:

Users put all sorts of content into their own profiles. URLs pointing to cool sites, photos, etc. If they link to something dangerous—perhaps inadvertently—and you click on it… Well, you get the drift.

Third party applications:

Most of the popular social networking sites have a third-party application interface for companies to generate their own content. Most of it is pretty innocuous and in the spirit of good clean fun, like a little app that lets you “throw” a virtual snowball at someone else. But, again, it extends that trust boundary in ways you might not want.

[Read More...]
 
 
 
 
Copyright © Digital World
Template Modified by aNtH Blog