Friday, March 3, 2017

How Fast Is Falling Rain?

How Fast Is Falling Rain?

Read a random fact yesterday that said the “average rain drop falls at 17mph.” Is that reasonable?
Let the physics begin. You might think: hey, wont’ the speed depend on how high the water started? Well, it would if air resistance on the water drop were not important. However, I suspect that the rain will fall at terminal velocity. Terminal velocity is the case when the air resistance on the object is equal to the gravitational force on the object. When this happens, the net force is zero (the zero vector) and the object falls at a constant speed.
Here is a diagram of a water drop at terminal speed.
Untitled 1
Since the air resistance force depends on the speed of the object (but the gravitational force does not), there is one speed for which these two forces add up to the zero vector. Near the surface of the Earth, the magnitude of the gravitational force can be modeled as:
La te xi t 1 4
Where g is the local gravitational field (not the acceleration due to gravity – that is a non-good name for it). And what about the air resistance? It can probably be modeled as:
La te xi t 1 5
Where:
  • ρ is the density of air (about 1.2 kg/m3).
  • A is the cross-sectional area of the object. If the object was a sphere, this area would be the area of a circle.
  • C is the drag coefficient. This depends on the shape of the object. A cone and a flat circle will have the same A, but different drag coefficients.
  • v is the magnitude of the velocity of the object with respect to the air.
  • It won’t matter for this case too much, but the direction of the air resistance force is in the opposite direction to the velocity.
At terminal velocity, the magnitudes of these two forces will be equal. I can write that as:
La te xi t 1 6
Now, what about the mass (m)? Let me assume that it is made of water (like most rain) and is spherical (even though that is not likely – it would probably be “rain drop shaped”). If I call the density of water ρw and the radius of the drop r, then the mass would be:
La te xi t 1 7
Putting this into the “weight = air resistance” expression above as well as an expression for the cross-sectional area in terms of r, I get:
La te xi t 1 8
The cool thing here is that the terminal speed of the water drop depends on the size (radius). Larger drops will have a larger terminal velocity. So, could you just make a water melon sized water drop? No. Why not? Because at some point, the force from the air on the drop is going to break the water drop apart. The surface tension holding the drop together just won’t be enough to maintain its drop status.
Then how big can it get? I have no idea. Oh, and then there is the problem of real drop instead of spherical drops. Let me look at that first. Wikipedia lists the coefficient of drag for a smooth sphere as 0.1. A rain drop should be less than this – but how much less? Well, a rain drop would take some of the water to form some sort of tail. This would decrease the cross sectional area as well as decrease the drag coefficient. I am not sure how to calculate the volume of a non-spherical rain drop, so for now I will just use a spherical drop with a drag coefficient of 0.08. I know that is wrong, but it will give me an idea about the terminal speed.
Now, how big should it be? How about I don’t decide. Instead I will plot the terminal speed for a range of rain drop sizes. Let me look at drops from 0.5 mm to 5 mm. Here is that plot.
Raindrop.png
Well, the original question asked about the speeds in units of miles per hour. Here is the same plot but with different units.
Raindrop 2.png
Based on my estimations, 17 mph would be on the low end – but possible. It could be likely that I grossly overestimated the size of a raindrop.
Homework: Yes, there is homework. If the rain drop has a radius of 0.5 mm, from how high would it have to drop to get pretty close to the terminal velocity?

Update

As usual, I rush into things without exploring things in more depth. My assumption of a raindrop shaped raindrop appears to be bogus. Who would have guessed that? Anyway, here are some very useful links from commenters (Jens and Charles) and a large thanks to them.
By David Cox (@dcox21)

Tuesday, January 24, 2017

Android Malware that Infected Millions Returns to Google Play Store


hummingwhale-android-ad-fraud-malware
HummingBad – an Android-based malware that infected over 10 million Android devices around the world last year and made its gang an estimated US$300,000 per month at its peak – has made a comeback.

Security researchers have discovered a new variant of the HummingBad malware hiding in more than 20 Android apps on Google Play Store.

The infected apps were already downloaded by over 12 Million unsuspecting users before the Google Security team removed them from the Play Store.

Dubbed HummingWhale by researchers at security firm Check Point, the new malware utilizes new, cutting-edge techniques that allow the nasty software to conduct Ad fraud better than ever before and generate revenue for its developers.

The Check Point researchers said the HummingWhale-infected apps had been published under the name of fake Chinese developers on the Play Store with common name structure, com.[name].camera, but with suspicious startup behaviors.
"It registered several events on boot, such as TIME_TICK, SCREEN_OFF and INSTALL_REFERRER which [were] dubious in that context," Check Point researchers said in a blog post published Monday.

HummingWhale Runs Malicious Apps in a Virtual Machine

android-malware
The HummingWhale malware is tricky than HummingBad, as it uses a disguised Android application package (APK) file that acts as a dropper which downloads and runs further apps on the victim's smartphone.

If the victim notices and closes its process, the APK file then drops itself into a virtual machine in an effort to make it harder to detect.

The dropper makes use of an Android plugin created by the popular Chinese security vendor Qihoo 360 to upload malicious apps to the virtual machine, allowing HummingWhale to further install other apps without having to elevate permissions, and disguises its malicious activity to get onto Google Play.
"This .apk operates as a dropper, used to download and execute additional apps, similar to the tactics employed by previous versions of HummingBad," researchers said. "However, this dropper went much further. It uses an Android plugin called DroidPlugin, originally developed by Qihoo 360, to upload fraudulent apps on a virtual machine."

HummingWhale Runs Without having to Root the Android Device


Thanks to the virtual machine (VM), the HummingWhale malware no longer needs to root Android devices unlike HummingBad and can install any number of malicious or fraudulent apps on the victim's devices without overloading their smartphones.
Once the victim gets infected, the command and control (C&C) server send fake ads and malicious apps to the user, which runs in a VM, generating a fake referrer ID used to spoof unique users for ad fraud purposes and generate revenue.
Alike the original HummingBad, the purpose of HummingWhale is to make lots of money through ad fraud and fake app installations.
Besides all these malicious capabilities, the HummingWhale malware also tries to raise its reputation on Google Play Store using fraudulent ratings and comments, the tactic similar to the one utilized by the Gooligan malware.

Over 1 Million Google Accounts Hacked by 'Gooligan' Android Malware

 
 32.1K  1371  214  34.1K
If you own an Android smartphone, Beware! A new Android malware that has already breached more than 1 Million Google accounts is infecting around 13,000 devices every day.

Dubbed Gooligan, the malware roots vulnerable Android devices to steal email addresses and authentication tokens stored on them.

With this information in hands, the attackers are able to hijack your Google account and access your sensitive information from Google apps including Gmail, Google Photos, Google Docs, Google Play, Google Drive, and G Suite.

Researchers found traces of Gooligan code in dozens of legitimate-looking Android apps on 3rd-party app stores, which if downloaded and installed by an Android user, malware starts sending your device’s information and stolen data to its Command and Control (C&C) server.
"Gooligan then downloads a rootkit from the C&C server that takes advantage of multiple Android 4 and 5 exploits including the well-known VROOT (CVE-2013-6282) and Towelroot (CVE-2014-3153)," researchers said in a blog post.
"If rooting is successful, the attacker has full control of the device and can execute privileged commands remotely."
According to CheckPoint security researchers, who uncovered the malware, anyone running an older version of the Android operating system, including Android 4.x (Jelly Bean, KitKat) and 5.x, (Lollipop) is most at risk, which represents nearly 74% of Android devices in use today.
"These exploits still plague many devices today because security patches that fix them may not be available for some versions of Android, or the patches were never installed by the user," researchers added.
Once hack into any Android device, Gooligan also generates revenues for the cyber criminals by fraudulently buying and installing apps from Google Play Store and rating them and writing reviews on behalf of the phone's owner. The malware also installs adware to generate revenue.

How to check if your Google account has been compromised with this malware?


Check Point has published an online tool to check if your Android device has been infected with the Gooligan malware. Just open ‘Gooligan Checker’ and enter your Google email address to find out if you've been hacked.

If you found yourself infected, Adrian Ludwig, Google's director of Android security, has recommended you to run a clean installation of the operating system on your Android device.

This process is called 'Flashing,' which is quite a complicated process. So, the company recommends you to power off your device and approach a certified technician or your mobile service provider in order to re-flash your device.

Tuesday, January 10, 2017

LA. College Pays Hackers $28,000 Ransom To Get Its Files Back

ransomware-malware
Ransomware has turned on to a noxious game of Hackers to get paid effortlessly.

Once again the heat was felt by the Los Angeles Valley College (LAVC) when hackers managed to infect its computer network with ransomware and demanded US$28,000 payment in Bitcoins to get back online.

The cyber-attack occurred over winter break and caused widespread disruption to online, financial aid, email and voicemail systems, including locking out 1,800 students and staffs from their computers.

As the situation was gone out of its hand, the Los Angeles Community College District (LACCD) agreed to pay the ransom demand of $28,000 in Bitcoin to criminals to resume their operations after gaining the decryption keys, the school newspaper, The Valley Star, reports.

The cyber criminals gave the college a week to pay the ransom and threatened to delete all the data if they were not paid.

Just like most ransomware victims the college obviously was not properly backing up the data. Therefore, the district agreed to pay up the ransom amount to quickly recover access to their systems and data.

However, according to the college officials, it was ultimately cheaper for them to pay the ransom than to remove the unknown ransomware virus from their systems to recover data and resume other services.

After paying the ransom, the college was given a ransomware decryption key to retaining access to its valuable data.
"LACCD and LAVC information technology staff, outside cybersecurity experts and law enforcement are working together to determine the specific nature and impact of this incident. Our top priority is the integrity of student, faculty and employee data, and we will continue to communicate with the LAVC community and the public as the investigation proceeds." the College wrote in a report [PDF].
The college was lucky this time, because, in the case of ransomware, there is no guarantee that one will get the right decryption key in return. For example, recently discovered KillDisk Ransomware that targets Linux machines, demands $218,000 to decrypt, but in return, wipes out data permanently.

One of the most notorious examples of ransomware attacks took place in March last year when crooks locked down the computers and sealed all sensitive files of a Los Angeles hospital, including patient data, which eventually made the hospital to pay $17,000.

Last year, we saw an enormous rise in Ransomware threats, both in numbers and sophistication, and the only way to secure your environment is to deploy automated and isolated backup mechanism.

Thursday, November 17, 2016

Fake USB Chargers that Wirelessly Record

Beware of Fake USB Chargers that Wirelessly Record Everything You Type, FBI warns

Last year, a white hat hacker developed a cheap Arduino-based device that looked and functioned just like a generic USB mobile charger, but covertly logged, decrypted and reported back all keystrokes from Microsoft wireless keyboards.
Dubbed KeySweeper, the device included a web-based tool for live keystroke monitoring and was capable of sending SMS alerts for typed keystrokes, usernames, or URLs, and work even after the nasty device is unplugged because of its built-in rechargeable battery. Besides the proof-of-concept attack platform, security researcher Samy Kamkar, who created KeySweeper, also released instructions on how to build your own USB wall charger.
Now, it seems like hackers and criminal minds find this idea smart.
The FBI has issued a warning advisory for private industry partners to look out for highly stealthy keyloggers that quietly sniff passwords and other input data from wireless keyboards.
According to the advisory, blackhat hackers have developed their custom version of KeySweeper device, which "if placed strategically in an office or other location where individuals might use wireless devices", could allow criminals to steal:
  • Intellectual property
  • Trade secrets
  • Personally identifiable information
  • Passwords
  • Other sensitive information
Since KeySweeper looks almost identical to USB phone chargers that are ubiquitous in homes and offices, it lowers the chances of discovering the sniffing device by a target. However, according to a Microsoft spokesperson, customers using Microsoft Bluetooth-enabled keyboards are protected against KeySweeper threat. Also, its wireless keyboards manufactured after 2011 are also protected, as they use the Advanced Encryption Standard (AES) encryption technology. So, the primary method of defense is either to restrict the use of wireless keyboards, or to use keyboards that use the Advanced Encryption Standard (AES) encryption technology.
Although the FBI made no mention of malicious KeySweeper sniffers being found in the wild, the advisory indicates the information about the KeySweeper threat was obtained through an undescribed "investigation."
"The primary method of defense is for corporations to restrict the use of wireless keyboards. Since the KeySweeper requires over-the-air transmission, a wired keyboard will be safe from this type of attack." FBI advised.
Sniffers work against wireless devices that do not use secure encryption for the data transmitted between a keyboard and the computer.
Share Excerpt

Wednesday, November 16, 2016

Researchers identify antibody that neutralizes 98% of HIV strains

© Athit Perawongmetha
An antibody from an HIV-infected person has successfully neutralized 98 percent of HIV isolates tested, including the lion’s share of strains resistant to other antibodies of the same class, US scientists have found.
The striking efficiency of the powerful antibody, named N6, makes it an ideal candidate for further research to treat or prevent HIV infection, scientists from the National Institutes of Health, the largest biomedical research agency in the world, have stated.
Scientists scrutinized the evolution of N6 over time to understand how exactly it managed to develop the ability to potently neutralize the majority of HIV strains.
Researchers say that identifying broadly neutralizing antibodies against HIV has been a real challenge because the virus rapidly changes its surface proteins to avoid recognition by the immune system.
In 2010, scientists at National Institute of Allergies and Infectious Diseases (NIAID’s) Vaccine Research Center (VRC) discovered an antibody called VRC01 that can stop up to 90 percent of HIV strains from infecting human cells.
“Like VRC01, N6 blocks infection by binding to a part of the HIV envelope called the CD4 binding site, preventing the virus from attaching itself to immune cells,” researchers said in a press release published on Tuesday.
Findings from the latest study showed that N6 developed a “unique mode of binding that depends less on a variable area of the HIV envelope known as the V5 region and focuses more on conserved regions, which change relatively little among HIV strains. This allows N6 to tolerate changes in the HIV envelope, including the attachment of sugars in the V5 region, a major mechanism by which HIV develops resistance to other VRC01-class antibodies.”
The new findings suggest that N6 could pose advantages over VRC01, researchers noted, adding that due to its potency, N6 may offer "stronger and more durable prevention and treatment benefits, and researchers may be able to administer it subcutaneously (into the fat under the skin) rather than intravenously."
According to UNAIDS, there were approximately 36.7 million people worldwide living with HIV/AIDS at the end of 2015.  Of these, 1.8 million were children younger than 15 years old. The vast majority of people living with HIV are from low- and middle-income countries.
The WHO estimated that currently only some 54 percent of people with HIV know their status.