Domain: arstechnica.com
Stories and comments across the archive that link to arstechnica.com.
Stories · 4,420
-
What Might a $50 Tablet Inspire? (arstechnica.com)
theodp writes: Surprisingly, says Ars Technica's review of Amazon's $50 Fire tablet, it doesn't suck. "There's simply very little reason to spend more when you can get 90 percent of the functionality for a fraction of the price," writes Mark Walton. "The only real niggle right now with the Fire Tablet is the display (and the camera, if you really want to take photos with your tablet). Once budget tabs start coming with 1080p displays as standard, the writing really will be on wall. For now, the Amazon Fire Tablet is the budget tablet to beat." How does cheap technology like this mesh with Bill Gates's dream of putting a computer in every home, and projects like OLPC? Beyond that, any thoughts on what a $50 tablet price point might inspire in education, gaming, and other areas? -
Joomla SQL-Injection Flaw Affects Millions of Websites (trustwave.com)
An anonymous reader writes: Joomla has just issued a patch that fixes a SQL-injection vulnerability discovered by a researcher at Trustwave SpiderLabs. The flaw allowed malicious users to extract a browser cookie assigned to a site's administrator, giving them access to restricted parts of the server. The flaw first appeared in Joomla 3.2, released in November, 2013. An estimated 2.8 million websites rely on Joomla. The Joomla team and the researcher who found the flaw recommend an immediate update to version 3.4.5. -
Judge Tosses Wikimedia's Anti-NSA Lawsuit Because Wikipedia Isn't Big Enough (arstechnica.com)
An anonymous reader writes: A federal judge has dismissed a lawsuit filed by the Wikimedia Foundation, Amnesty International, and others against the NSA and other U.S. intelligence agencies for their surveillance of internet communications. The judge used some odd reasoning in his ruling to absolve the NSA of any constitutional violations. He said that since the plaintiffs couldn't prove that all upstream internet communications were monitored, they didn't have standing to challenge whatever communications were monitored. This is curious, given that tech companies are known to be under gag orders preventing them from discussing certain types of government data collection. The judge also made a strange argument about Wikipedia's size: "For one thing, plaintiffs insist that Wikipedia's over one trillion annual Internet communications is significant in volume. But plaintiffs provide no context for assessing the significance of this figure. One trillion is plainly a large number, but size is always relative. For example, one trillion dollars are of enormous value, whereas one trillion grains of sand are but a small patch of beach." -
Hands-On With the Fairphone 2 Modular Android Smartphone (arstechnica.com)
An anonymous reader writes: In just a couple of months, the world's first consumer-ready modular smartphone will start shipping. It's called the Fairphone 2, and it will run Android 5.1. Ars Technica got hands-on time with the device, and they say it works surprisingly well. It's a bit thicker than most modern phones, but that's the trade-off for being able to swap out components. "The smartphone consists of seven major building blocks: the back cover, removable battery, display assembly, main chassis, receiver module, rear camera module, and speaker module. Positioned this way, the components that break most often, like the screen, are isolated for better repairability. In addition to swappable blocks, you can even change things inside the modules: for example, a mic or a speaker. They are press-fit, not glued, and can be extracted with simple tools."
Assembly and disassembly is pretty straightforward, as well: "The modules are held together by Phillips screws marked with blue circles. All screws are the same, so you won't have to remember which one goes where. It's quite hard to make a mistake in the assembling process, however Fairphone promises to release additional manuals and video instructions in collaboration with iFixit." The company also thinks it's important to get the phone's materials and components from ethical sources. -
Square Enix To Concentrate On Remaking Their Back Catalog
An anonymous reader writes: You may remember that at E3, the major announcement from Square Enix and Sony wasn't a new game, but rather that Square Enix would be remaking Final Fantasy VII in HD and releasing it for PS4 first. Square Enix's recent annual report indicates that they intend to make more HD remakes of old titles. Like many Japanese developers, they indicate in the report that they also intend to focus more on mobile platforms, including porting more of their back catalog to mobile devices. With the impending release of Final Fantasy XV, Square Enix knows a thing or two about rehashing old content, but Square Enix also owns the Dragon Quest, Deus Ex, and Tomb Raider series, giving them a fairly large library to give the HD treatment to. -
"YouTube Red" Offers Premium YouTube For $9.99 a Month, $12.99 For iOS Users (arstechnica.com)
An anonymous reader writes: YouTube is launching a subscription plan in the U.S. called Red that combines ad-free videos, new original series and movies. The official blog post reads in part: "On October 28, we’re giving fans exactly what they want. Introducing YouTube Red -- a new membership designed to provide you with the ultimate YouTube experience. YouTube Red lets you enjoy videos across all of YouTube without ads, while also letting you save videos to watch offline on your phone or tablet and play videos in the background, all for $9.99 a month. Your membership extends across devices and anywhere you sign into YouTube, including our recently launched Gaming app and a brand new YouTube Music app we’re announcing today that will be available soon." -
Nexus 5X and Nexus 6P Reviews Arrive (arstechnica.com)
An anonymous reader writes: A few weeks ago, Google announced its new Nexus phones — the 5X built by LG, and the 6P built by Huawei. The phones are starting to ship, and reviews for both devices have landed. So far, they're largely positive. Ars Technica calls them the Android phones to beat, though criticizes them for having fairly large bezels and no wireless charging. Android Police says the 6P's form factor is an improvement over the Nexus 6, being slightly narrower and taller. Meanwhile, most publications report that the 5X does a good job at carrying on the legacy of the excellent Nexus 5. It's their lower end phone, and most reviews mention that it feels that way in the hand — but battery life is reportedly excellent. The Nexus 6P's battery is capable, but doesn't last as long. Fortunately, the worries about overheating with its Snapdragon 810 chip seem overblown. -
Nintendo's New System Likely a Console/Portable Hybrid (arstechnica.com)
An anonymous reader writes: The Wall Street Journal reports (paywalled) that Nintendo has begun issuing software development kits for its new console, codenamed NX. The company hasn't provided any details publicly about how the console will work, but people who have gotten access to the SDK say it will likely include both a console and some kind of portable/mobile hardware. The intent is to be able to take some aspects of gaming with you when you leave the living room. Nintendo is also looking to step up its hardware efforts in response to criticism that the Wii U's capabilities were notably lower than those of the PS4 and Xbox One. In what ways do you think a console should be partially portable? -
Windows 10 Upgrades Are Being Forced On Some Users (arstechnica.com)
grimmjeeper writes: According to Ars Technica the Windows 10 upgrade option is being selected by default for some users. A dialogue box is appearing that only permits them to reschedule the upgrade process, not cancel it. "For the first year of its availability, Windows 10 is available for free to most Windows 7 and 8 users, and Microsoft has been trying to coax those users to make the switch by delivering the operating system through Windows Update. Until now, the OS has been delivered as an optional update; while Windows Update gives it prominent positioning, it shouldn't be installed automatically. This system has already generated some complaints, as Windows Update will download the sizeable operating system installer even if you don't intend to upgrade any time soon, but, over the last couple of days, the situation seems to have become a little more aggressive. We've received a number of reports that people's systems are not merely downloading the installer but actually starting it up." Update: 10/16 11:35 GMT by S : Microsoft said, "In the recent Windows update, this option was checked as default; this was a mistake and we are removing the check." -
Why Cybersecurity Experts Want Open Source Routers (vice.com)
derekmead writes: A coalition of 260 cybersecurity experts is taking advantage of a Federal Communications Commission (FCC) public comment period to push for open source Wi-Fi router firmware.
The cybersecurity experts asked the FCC on Wednesday to require router makers to open-source their firmware, or the basic software that controls its core functionality, as a condition for it being licensed for use in the US. The request comes amid a wider debate on how the FCC should ensure that Wi-Fi routers' wireless signals don't "go outside stated regulatory rules" and cause harmful interference to other devices like cordless phones, radar, and satellite dishes. -
New Flash Vulnerability Being Exploited In the Wild (trendmicro.com)
An anonymous reader writes: Researchers from Trend Micro report a new attack on fully-patched versions of Adobe Flash. The attacks originate from an espionage campaign run by the group known as Pawn Storm, and seem to target only government agencies. "Ministries of Foreign Affairs have become a particular focus of interest for Pawn Storm recently. Aside from malware attacks, fake Outlook Web Access (OWA) servers were also set up for various ministries. These are used for simple, but extremely effective, credential phishing attacks. One Ministry of Foreign Affairs got its DNS settings for incoming mail compromised. This means that Pawn Storm has been intercepting incoming e-mail to this organization for an extended period of time in 2015." -
Why Many CSS Colors Have Goofy Names (arstechnica.com)
An anonymous reader writes: Take a look at the list of named colors within the CSS Color Module Level 4. The usual suspects are there, like 'red,' 'cyan,' and 'gold,' as well as some slightly more descriptive ones: 'lightgrey,' 'yellowgreen,' and 'darkslateblue.' But there are also some really odd names: 'burlywood,' 'dodgerblue,' 'blanchedalmond,' and more. An article at Ars walks through why these strange names became part of a CSS standard. Colors have been added to the standard piece by piece over the past 30 years — here's one anecdote: "The most substantial release, created by Paul Raveling, came in 1989 with X11R4. This update heralded a slew of light neutral tones, and it was a response to complaints from Raveling's coworkers about color fidelity. ... Raveling drew these names from an unsurprising source: the (now-defunct) paint company Sinclair Paints. It was an arbitrary move; after failing to receive sanctions from the American National Standards Institute (ANSI), which issued standards for Web color properties, Raveling decided to take matters into his own hands. He calibrated the colors for his own HP monitor. 'Nuts to ANSI & "ANSI standards,"' he complained." -
The History of City-Building Games (arstechnica.com)
An anonymous reader writes: If you ask most gamers, the first city-building game they played was SimCity, or some sequel thereof. Though SimCity ended up defining the genre for years, it was far from the first. This article goes through the history of city-building games. It began before man first landed on the moon: "While extremely limited in its simulation, Doug Dyment's The Sumer Game was the first computer game to concern itself with matters of city building and management. He coded The Sumer Game in 1968 on a Digital Equipment Corporation PDP-8 minicomputer, using the FOCAL programming language. David H. Ahl ported it to BASIC a few years later retitled as Hamurabi (with the second 'm' dropped in order to fit an eight-character naming limit). The Sumer Game, or Hamurabi, put you in charge of the ancient city-state of Sumer. You couldn't build anything, but you could buy and sell land, plant seeds, and feed (or starve) your people. The goal was to grow your economy so that your city could expand and support a larger population, but rats and the plague stood in your way. And if you were truly a terrible leader your people would rebel, casting you off from the throne." -
The Rise and Fall of NASA's Shuttle-Centaur (arstechnica.com)
An anonymous reader writes: An article at Ars Technica tells the story of Shuttle-Centaur, a NASA project during the mid-1980s to carry a Centaur rocket to orbit within the cargo bay of a space shuttle. As you might expect, shuttle launches became vastly more complex with such heavy yet delicate cargo. Still, officials saw it as an easy way to send probes further into the solar system. They developed a plan to launch Challenger and Atlantis within 5 days of each other in mid-1986 to bring the Ulysses and Galileo probes to orbit, each with its own Shuttle-Centaur. Though popular opinion at the time was that the shuttle program was "unstoppable," individuals within NASA were beginning to push back against slipping safety standards. "While a host of unknowns remained concerning launching a volatile, liquid-fueled rocket stage on the back of a space shuttle armed with a liquid-filled tank and two solid rocket boosters, NASA and its contractors galloped full speed toward a May 1986 launch deadline for both spacecraft." The destruction of Challenger in January, 1986 put Shuttle-Centaur on hold. The safety investigation that ensued quickly came to the conclusion that it presented unacceptable risks, and the project was canceled that June. -
First Successful Collision Attack On the SHA-1 Hashing Algorithm (google.com)
Artem Tashkinov writes: Researchers from Dutch and Singapore universities have successfully carried out an initial attack on the SHA-1 hashing algorithm by finding a collision at the SHA1 compression function. They describe their work in the paper "Freestart collision for full SHA-1". The work paves the way for full SHA-1 collision attacks, and the researchers estimate that such attacks will become reality at the end of 2015. They also created a dedicated web site humorously called The SHAppening.
Perhaps the call to deprecate the SHA-1 standard in 2017 in major web browsers seems belated and this event has to be accelerated. -
From Microsoft, HoloLens VR Dev Kit, New Phones, Continuum
Ars Technica and scads of other tech hardware sites are reporting that the big news so far from this morning's Microsoft product launch event in New York is that the company's Hololens development kit will begin shipping in the first quarter of next year, and at a price that puts the units out of the hands of typical consumers: $3000. At that level, developers are more likely to make the plunge, which Ars applauds.
The company also announced three new smartphones: two of them, the Lumia 950, 950XL, are worth designating "flagships," while the 550, notably, will sell for $139, putting it in the territory of cheap grey-market Android phones. More interesting than spec bumps, though, is Continuum for Windows, a Window 10 feature which made its official debut at the event. Continuum is one manifestation of the pocket-computer idea that others have had as well in various forms: it means that with an adapter, a phone can be used as the CPU and graphics engine when connected to a screen and keyboard: "The adapter features a Microsoft Display Dock, an HDMI and Display Port, plus 3 USB ports to provide productivity on the go and let you plug in additional peripherals, such as mice and keyboards. Other accessories can be connected too, Microsoft said."
Microsoft also demo'd the Surface 4. Its improved screen is 12.3" at 2160x1440, for a pixel density of 267 PPI. The new pro has a Skylake 6th-gen processor, which they say provides a 30% performance boost over the Surface Pro 3, and a 50% boost over the MacBook Air. The SP4 goes up to 1TB of storage, and up to 16GB of RAM. The Type Cover was improved as well — the touchpad is 40% larger and supports 5-point multi-touch, while the keys have better travel and pitch.
On top of this, Microsoft also unveiled the Surface Book laptop. Its defining feature is that you can unclip the 13.5" touchscreen and use it separately as a tablet. The keyboard dock has a dedicated GPU that will boost performance when attached. Microsoft is using a new type of hinge that bends and extends at multiple points, so you can also reattach the screen backward if you want to use it as a tablet while keeping the extra GPU power available. They claim a 12-hour battery life for the Surface Book. -
From Microsoft, HoloLens VR Dev Kit, New Phones, Continuum
Ars Technica and scads of other tech hardware sites are reporting that the big news so far from this morning's Microsoft product launch event in New York is that the company's Hololens development kit will begin shipping in the first quarter of next year, and at a price that puts the units out of the hands of typical consumers: $3000. At that level, developers are more likely to make the plunge, which Ars applauds.
The company also announced three new smartphones: two of them, the Lumia 950, 950XL, are worth designating "flagships," while the 550, notably, will sell for $139, putting it in the territory of cheap grey-market Android phones. More interesting than spec bumps, though, is Continuum for Windows, a Window 10 feature which made its official debut at the event. Continuum is one manifestation of the pocket-computer idea that others have had as well in various forms: it means that with an adapter, a phone can be used as the CPU and graphics engine when connected to a screen and keyboard: "The adapter features a Microsoft Display Dock, an HDMI and Display Port, plus 3 USB ports to provide productivity on the go and let you plug in additional peripherals, such as mice and keyboards. Other accessories can be connected too, Microsoft said."
Microsoft also demo'd the Surface 4. Its improved screen is 12.3" at 2160x1440, for a pixel density of 267 PPI. The new pro has a Skylake 6th-gen processor, which they say provides a 30% performance boost over the Surface Pro 3, and a 50% boost over the MacBook Air. The SP4 goes up to 1TB of storage, and up to 16GB of RAM. The Type Cover was improved as well — the touchpad is 40% larger and supports 5-point multi-touch, while the keys have better travel and pitch.
On top of this, Microsoft also unveiled the Surface Book laptop. Its defining feature is that you can unclip the 13.5" touchscreen and use it separately as a tablet. The keyboard dock has a dedicated GPU that will boost performance when attached. Microsoft is using a new type of hinge that bends and extends at multiple points, so you can also reattach the screen backward if you want to use it as a tablet while keeping the extra GPU power available. They claim a 12-hour battery life for the Surface Book. -
From Microsoft, HoloLens VR Dev Kit, New Phones, Continuum
Ars Technica and scads of other tech hardware sites are reporting that the big news so far from this morning's Microsoft product launch event in New York is that the company's Hololens development kit will begin shipping in the first quarter of next year, and at a price that puts the units out of the hands of typical consumers: $3000. At that level, developers are more likely to make the plunge, which Ars applauds.
The company also announced three new smartphones: two of them, the Lumia 950, 950XL, are worth designating "flagships," while the 550, notably, will sell for $139, putting it in the territory of cheap grey-market Android phones. More interesting than spec bumps, though, is Continuum for Windows, a Window 10 feature which made its official debut at the event. Continuum is one manifestation of the pocket-computer idea that others have had as well in various forms: it means that with an adapter, a phone can be used as the CPU and graphics engine when connected to a screen and keyboard: "The adapter features a Microsoft Display Dock, an HDMI and Display Port, plus 3 USB ports to provide productivity on the go and let you plug in additional peripherals, such as mice and keyboards. Other accessories can be connected too, Microsoft said."
Microsoft also demo'd the Surface 4. Its improved screen is 12.3" at 2160x1440, for a pixel density of 267 PPI. The new pro has a Skylake 6th-gen processor, which they say provides a 30% performance boost over the Surface Pro 3, and a 50% boost over the MacBook Air. The SP4 goes up to 1TB of storage, and up to 16GB of RAM. The Type Cover was improved as well — the touchpad is 40% larger and supports 5-point multi-touch, while the keys have better travel and pitch.
On top of this, Microsoft also unveiled the Surface Book laptop. Its defining feature is that you can unclip the 13.5" touchscreen and use it separately as a tablet. The keyboard dock has a dedicated GPU that will boost performance when attached. Microsoft is using a new type of hinge that bends and extends at multiple points, so you can also reattach the screen backward if you want to use it as a tablet while keeping the extra GPU power available. They claim a 12-hour battery life for the Surface Book. -
From Microsoft, HoloLens VR Dev Kit, New Phones, Continuum
Ars Technica and scads of other tech hardware sites are reporting that the big news so far from this morning's Microsoft product launch event in New York is that the company's Hololens development kit will begin shipping in the first quarter of next year, and at a price that puts the units out of the hands of typical consumers: $3000. At that level, developers are more likely to make the plunge, which Ars applauds.
The company also announced three new smartphones: two of them, the Lumia 950, 950XL, are worth designating "flagships," while the 550, notably, will sell for $139, putting it in the territory of cheap grey-market Android phones. More interesting than spec bumps, though, is Continuum for Windows, a Window 10 feature which made its official debut at the event. Continuum is one manifestation of the pocket-computer idea that others have had as well in various forms: it means that with an adapter, a phone can be used as the CPU and graphics engine when connected to a screen and keyboard: "The adapter features a Microsoft Display Dock, an HDMI and Display Port, plus 3 USB ports to provide productivity on the go and let you plug in additional peripherals, such as mice and keyboards. Other accessories can be connected too, Microsoft said."
Microsoft also demo'd the Surface 4. Its improved screen is 12.3" at 2160x1440, for a pixel density of 267 PPI. The new pro has a Skylake 6th-gen processor, which they say provides a 30% performance boost over the Surface Pro 3, and a 50% boost over the MacBook Air. The SP4 goes up to 1TB of storage, and up to 16GB of RAM. The Type Cover was improved as well — the touchpad is 40% larger and supports 5-point multi-touch, while the keys have better travel and pitch.
On top of this, Microsoft also unveiled the Surface Book laptop. Its defining feature is that you can unclip the 13.5" touchscreen and use it separately as a tablet. The keyboard dock has a dedicated GPU that will boost performance when attached. Microsoft is using a new type of hinge that bends and extends at multiple points, so you can also reattach the screen backward if you want to use it as a tablet while keeping the extra GPU power available. They claim a 12-hour battery life for the Surface Book. -
This is not F1 (or NASCAR): High-End Hybrids Race In Texas
Ars Technica takes an in-depth look at some of the tech side of the hybrid racing circuit, in particular the World Endurance Championship . From the article: Hybrid systems are allowed to deploy between 2MJ and 8MJ of energy during a single lap of Le Mans, augmenting the power from an internal combustion engine. Energy can be recovered from up to two motor/generator units (MGUs); usually this means recapturing kinetic energy from the front and rear wheels under braking. To balance things out, cars that recover and deploy 8MJ carry less fuel, and the flow rate at which they can feed it to the engine decreases. Audi's R18, with its mix of turbo diesel and flywheel hybrid technology, was king of the hill for several years, but the hybrid systems were much less powerful. Last year, Toyota's gasoline V8 and supercapacitor-powered TS040 was the car to beat. But 2015 is the year of the Porsche 919 Hybrid. Porsche chose lithium-ion batteries to hybridize the 919's turbocharged gasoline V4, and this year is able to capture and deploy the full 8MJ (Toyota is in the 6MJ class and Audi 4MJ). The article spends more space on Audi's approach than the others, but offers a cool glimpse at all three of these companies' niches within the field, as represented at the Texas' Lone Star Le Mans. -
Sprint To Begin Layoffs, Cut $2.5 Billion In Expenses
An anonymous reader writes: Sprint's struggles to remain a major carrier continue. Just a few days after announcing that it is dropping out of a major low-band spectrum auction, the company now says it must cut between $2 billion and $2.5 billion in costs over the next six months. The cuts will need to be aggressive — according to the Wall Street Journal (paywalled), Sprint "had $7.5 billion in operating expenses during the three months ended June 30," even as it cut $1.5 billion over the past year. The only good news for Sprint is that its subscriber base is still slowly growing, though not quickly enough to keep pace with T-Mobile, let alone Verizon or AT&T. -
East Texas Judge Throws Out 168 Patent Cases
Earthquake Retrofit writes: Ars Technica is reporting that an East Texas judge has thrown out 168 patent cases in one fell swoop. The judge's order puts the most litigious patent troll of 2014, eDekka LLC, out of business. The ruling comes from a surprising source: U.S. District Judge Rodney Gilstrap, the East Texas judge who has been criticized for making life extra-difficult for patent defendants. Gilstrap, who hears more patent cases than any other U.S. judge, will eliminate about 10 percent of his entire patent docket by wiping out the eDekka cases. -
Nerves Rattled By Highly Suspicious Windows Update Delivered Worldwide
An anonymous reader writes: If you're using Windows 7 you might want to be careful about which updates you install. Users on Windows forums are worried about a new "important" update that looks a little suspect. Ars reports: "'Clearly there's something that's delivered into the [Windows Update] queue that's trusted,' Kenneth White, a Washington DC-based security researcher, told Ars after contacting some of the Windows users who received the suspicious update. 'For someone to compromise the Windows Update server, that's a pretty serious vector. I don't raise the alarm very often but this has just enough characteristics of something pretty serious that I think it's worth looking at.'" UPDATE: Microsoft says there's nothing to worry about, the company "incorrectly published a test update." -
Ditch Linux For Windows 10 On Your Raspberry Pi With Microsoft's IoT Kit
An anonymous reader writes: Partnering with Adafruit, Microsoft has announced the Windows IoT Core Starter Kit. The $75 kit comes comes with an SD card preloaded with Windows 10 IoT. According to the Raspberry Pi blog: "The pack is available with a Pi 2 for people who are are new to Raspberry Pi or who'd like a dedicated device for their projects, or without one for those who'll be using a Pi they already own. The box contains an SD card with Windows 10 Core and a case, power supply, wifi module and Ethernet cable for your Pi; a breadboard, jumper wires and components including LEDs, potentiometers and switches; and sensors for light, colour, temperature and pressure. There's everything you need to start building." -
Analysis: China-US Hacking Accord Is Tall On Rhetoric, Short On Substance
An anonymous reader writes: Ars takes a look at the cyberspying agreement between the U.S. and China. The article looks at what the accord does but more importantly, what it does not. "But even assuming both sides would follow the pact, the accord is tall on rhetoric and short on substance. The deal, for instance, defines the method of enforcement as requiring the two nation's to create a 'high-level joint dialogue mechanism,' according to a joint statement from Attorney General Loretta Lynch and Homeland Security chief Jeh Johnson. More important, the two superpowers make no commitment not to hack one another for intelligence-gathering purposes. That means the recent hack of the Office of Personnel Management's background investigation data—5.6 million sets of fingerprints from US federal employees, contractors and other federal job applicants—doesn't run counter to the accord. The OPM hack is believed to have originated in China and the data, as Ars has previously reported, is 'in the hands of the foreign intelligence services of China.'" -
GCHQ Tried To Track Web Visits of "Every Visible User On Internet"
An anonymous reader writes with Ars Technica's story on the relevations reported today by The Intercept that the UK's GCHQ has been tracking World Wide Web users since 2007, with an operation called "Karma Police" -- "a program that tracked Web browsing habits of people around the globe in what the agency itself billed as the 'world's biggest' Internet data-mining operation, intended to eventually track 'every visible user on the Internet.'" -
Phone Passwords Protected By 5th Amendment, Says Federal Court
Ars Technica reports that a Federal court in Pennsylvania ruled Wednesday that the Fifth Amendment protects from compelled disclosure the passwords that two insider-trading suspects used on their mobile phones. In this case, the SEC is investigating two former Capital One data analysts who allegedly used insider information associated with their jobs to trade stocks—in this case, a $150,000 investment allegedly turned into $2.8 million. Regulators suspect the mobile devices are holding evidence of insider trading and demanded that the two turn over their passcodes. However, the court ruled, "Since the passcodes to Defendants' work-issued smartphones are not corporate records, the act of producing their personal passcodes is testimonial in nature and Defendants properly invoke their fifth Amendment privilege." -
Appeals Court Bans Features From Older Samsung Phones
walterbyrd writes with news that Apple has finally emerged victorious in a long-standing patent case against Samsung — though it's more of a moral victory than a practical one. Samsung is no longer allowed to sell some of its older phones unless the company disables features that infringe upon Apple patents. "The market impact will likely be limited, since the lawsuit was filed in 2012 and covers products that came out that year, like the Galaxy S3. Furthermore, software updates to Samsung software mean that the patents may not be infringed anymore. For instance, Samsung's Android phones no longer use a 'slide to unlock' feature on the bottom of the phone. In dissent, U.S. Circuit Judge Sharon Prost paints a sharply different picture (PDF) from the majority. 'This is not a close case,' she writes, noting that Apple's patents cover a spelling correction feature it doesn't use, and two others cover 'minor features' out of 'many thousands.'" -
The Era of Open Source Cars
An anonymous reader writes: An article at Ars Technica details how open source is slowly but surely working its way into the automotive manufacturing industry. A company named StreetScooter is flattening the design process, having designers and engineers work directly with suppliers right from the get-go. Another company, Local Motors, has built an open source community that's 50,000-strong, whose members include everybody from hobbyists to industrial engineers. Even the existing auto-giants are getting in on it: Ford has created OpenXC, a platform that is attempting to standardize how to get data out of a car's computer. The article concludes, "These various automotive open source advocates come at the topic from different backgrounds and with different approaches, but they can all recognize we've entered an era for open source cars that simply didn't exist before." -
Arrangement With Science Publisher Raises Questions About Wikipedia's Commitment To Open Access
Applehu Akbar writes: Elsevier, the science publisher notorious for maintaining high-priced research journals in a time when web technology can accomplish the same tasks for a fraction of the price, has donated free ScienceDirect accounts to a select group of "top Wikipedia editors" as an incentive for citations referencing its paywalled journals. This arrangement is being criticized for its effect on Wikipedia's accessibility and openness. Ars reports: "...Michael Eisen, one of the founders of the open access movement, which seeks to make research publications freely available online, tweeted that he was 'shocked to see @wikipedia working hand-in-hand with Elsevier to populate encylopedia w/links people cannot access,' and dubbed it 'WikiGate.' Over the last few days, a row has broken out between Eisen and other academics over whether a free and open service such as Wikipedia should be partnering with a closed, non-free company such as Elsevier." -
Sharebeast, the Largest US-based Filesharing Service, Has Its Domain Seized
An anonymous reader writes: The RIAA says that the FBI has seized the domain of file-sharing service ShareBeast, shutting down what it said was responsible for the leaks of thousands of songs. The site now only displays a notice saying the FBI acted "pursuant to a seizure warrant related to suspect criminal copyright infringement." In a statement, RIAA CEO Cary Sherman called the seizure "a huge win for the music community and legitimate music services. ShareBeast operated with flagrant disregard for the rights of artists and labels while undermining the legal marketplace." -
Spy Industry Leaders Befuddled Over 'Deep Cynicism' of American Public
New submitter autonomous_reader writes: Ars Technica has a story on this week's Intelligence & National Security Summit, where CIA Director John Brennan and FBI Director James Comey had a lot to say about the resistance of the American public to government cyber spying and anti-encryption efforts. Blaming resistance on "people who are trying to undermine" the intelligence mission of the NSA, CIA, and FBI, John Brennan explained it was all a "misunderstanding." Comey explained that "venom and deep cynicism" prevented rational debate of his campaign for cryptographic backdoors. -
Ashley Madison's Passwords Cracked, Soon To Be Released
New submitter JustAnotherOldGuy writes with some news that might worry anyone caught up in the Ashley Madison data breach. ("Uh-oh," he says.) Now, besides any other possible repercussions of having one's name on the list of account holders, there's a new wrinkle. The passwords used to secure those accounts were theoretically robustly protected with bcrypt. However, as Ars Technica reports, That assurance was shattered with the discovery of the programming error disclosed by a group calling itself CynoSure Prime. Members have already exploited the weakness to crack more than 11 million Ashley Madison user passwords, and they hope to tackle another four million in the next week or two. This would matter much less if passwords weren't so frequently re-used. -
Four Year Sentence For Running Piracy Streaming Site
An anonymous reader writes: A 29-year-old man from Northern Ireland has been sentenced to two years in jail and another two "on license" for running a website from his bedroom that streamed pirated content. (Being on license is similar to a strict parole in the U.S.) Police say the man made over £280,000 from ads on the site . Law enforcement was put on the case by an anti-piracy group in the UK. Between 2008 and 2013, users of the site streamed approximately 12 million movies, which prosecutors say caused £12 million in damages. The judge in the case said time in jail was necessary "to show that behavior of this nature does not go unpunished." -
Raspberry Pi Touch Screen Released
An anonymous reader writes: The Raspberry Pi has been enormously successful, but one frequent request has been for the Foundation to create a simple touchscreen to go along with it. Gordon Hollingworth said, "I honestly believed it would only take us six months from start to end, but there were a number of issues we met (and other products diverted our attention from the display – like Rev 2.1, B+, A+, and Pi 2)." Now, after two years of development, they've launched a 7", 800x480 LCD that runs at 60 fps. The capacitive screen supports 10 simultaneous finger touches and has a 70 degree viewing angle. The Raspberry Pi Foundation's blog post provides some interesting technical background on electromagnetic compliance and how to connect and use the display. -
Amazon Reportedly Aiming For the Low End With a Loss-Leader $50 Tablet
Amazon has been dogged with criticism for its high-end, somewhat oddball phone, but done rather better with its high-end Fire tablets, and has mostly defined the market for e-ink book-reading devices with its long-lived Kindle series. Now, according to a report in the WSJ echoed by Fortune (and by Ars Technica and many others), the company is said to be working on a tablet aimed at the low end of the market, with a 6-inch screen, a mono speaker, and a tiny pricetag -- which could be as low as $50. "At the bottom end of the range at least, the devices won’t be priced to make a profit," writes Fortune. "The dirt-cheap price tag is intended to maximise the reach of its e-book and Amazon Prime video streaming content." -
Four Men Arrested Over Million-Dollar MacBook Heist
An anonymous reader writes: In January of 2014, Anton Saljanin was hired to drive 1,195 Apple MacBooks, valued at over $1 million, from a vendor in Massachusetts to a pair of high schools in New Jersey. The day after picking them up, he told police that the truck disappeared overnight while he slept. Later that day, he told police he just happened to spot the truck abandoned in a parking lot while he was driving down the highway. Unfortunately for him, detectives quickly realized none of these things could be true. Footage from CCTV cameras and cell-site records for his phone indicated he met with his brother and drove to another suspect's house, where they unloaded the laptops. Later, a fourth man helped them sell some of the MacBooks, often at steep discounts. The four men have now been charged in federal court for the theft. -
Municipal ISP Makes 10Gbps Available To All Residents
An anonymous reader writes: Five years ago, the city of Salisbury, North Carolina began a project to roll out fiber across its territory. They decided to do so because the private ISPs in the area weren't willing to invest more in the local infrastructure. Now, Salisbury has announced that it's ready to make 10 Gbps internet available to all of the city's residents. While they don't expect many homeowners to have a use for the $400/month 10 Gbps plan, they expect to have some business customers. "This is really geared toward attracting businesses that need this type of bandwidth and have it anywhere they want in the city." Normal residents can get 50 Mbps upstream and downstream for $45/month. A similar service was rolled out for a rural section of Vermont in June. Hopefully these cities will serve as blueprints for other locations that aren't able to get a decent fiber system from private ISPs. -
"Extremely Critical" OS X Keychain Vulnerability Steals Passwords Via SMS
Mark Wilson writes: Two security researchers have discovered a serious vulnerability in OS X that could allow an attacker to steal passwords and other credentials in an almost invisible way. Antoine Vincent Jebara and Raja Rahbani — two of the team behind the myki identity management security software — found that a series of terminal commands can be used to extract a range of stored credentials. What is particularly worrying about the vulnerability is that it requires virtually no interaction from the victim; simulated mouse clicks can be used to click on hidden buttons to grant permission to access the keychain. Apple has been informed of the issue, but a fix is yet to be issued. The attack, known as brokenchain, is disturbingly easy to execute. Ars reports that this weakness has been exploited for four years. -
Intel Launches Onslaught of Skylake CPUs For Laptops, Hybrids and Compute Stick
MojoKid writes: Intel is following up on its Skylake launch bonanza by opening the floodgates on at least two dozen SKUs mostly covering the mobile sector. The company is divvying up the range into four distinct series. There's the Y-Series, which is dedicated to 2-in-1 convertibles, tablets, and Intel's new Compute Stick venture. Then there's the U-Series, which is aimed at thin and light notebooks and "portable" all-in-one machines. The H-Series is built for gaming notebooks and mobile workstations, while the S-Series is designated for desktops, all-in-one machines, and mini PCs. Also, the Y-Series that was previously known as simply the Core M, (the chip found in products like the 12-inch Apple MacBook and Asus Transformer Book Chi T300) is now expanding into a whole family of processors. There will be Core m3, Core m5, and Core m7 processors, similar to Intel's Core i3, Core i5, and Core i7 CPU models in other desktop and notebook chips. -
More Popcorn Time Users Sued
An anonymous reader writes: The torrent-based video streaming software Popcorn Time has been in the news lately as multiple entities have initiated legal action over its use. Now, 16 Oregon-based Comcast subscribers have been targeted for their torrenting of the movie Survivor. The attorney who filed the lawsuit (PDF) says his client, Survivor Productions Inc., doesn't plan to seek any more than the minimum $750 fine, and that their goal is to "deter infringement." The lawsuit against these Popcorn Time users was accompanied by 12 other lawsuits targeting individuals who acquired copies of the movie using more typical torrenting practices. -
Microsoft's Telemetry Additions To Windows 7 and 8 Raise Privacy Concerns
WheezyJoe writes: ghacks and Ars Technica are providing more detail about Windows 10's telemetry and "privacy invasion" features being backported to Windows 7 and 8. The articles list and explain some of the involved updates by number (e.g., KB3068708, KB3022345, KB3075249, and KB3080149). The Ars article says the Windows firewall can block the traffic just fine, and the service sending the telemetry can be disabled. "Additionally, most or all of the traffic appears to be contingent on participating in the CEIP in the first place. If the CEIP is disabled, it appears that little or no traffic gets sent. This may not always have been the case, however; the notes that accompany the 3080149 update say that the amount of network activity when not part of CEIP has been reduced." The ghacks article explains other ways block the unwanted traffic and uninstall the updates. -
Six UK Teens Arrested For Being "Customers" of Lizard Squad's DDoS Service
An anonymous reader writes: UK officials have arrested six teenagers suspected of utilizing Lizard Squad's website attack tool called "Lizzard Stresser". Lizard Squad claimed responsibility for the infamous Christmas Day Xbox Live and PlayStation Network attacks. The teenagers "are suspected of maliciously deploying Lizard Stresser, having bought the tool using alternative payment services such as Bitcoin in a bid to remain anonymous," an NCA spokesperson wrote in an official statement on the case. "Organizations believed to have been targeted by the suspects include a leading national newspaper, a school, gaming companies, and a number of online retailers." -
OnHub Router -- Google's Smart Home Trojan Horse?
An anonymous reader writes: A couple weeks ago, Google surprised everybody by announcing a new piece of hardware: the OnHub Wi-Fi router. It packs a ton of processing power and a bunch of wireless radios into a glowy cylinder, and they're going to sell it for $200, which is on the high end for home networking equipment. Google sent out a number of units for testing, and the reviews are starting to come out. The device is truly Wi-Fi-centric, with only a single port for an ethernet cable. It runs on a Qualcomm IPQ8064 dual-core 1.4GHz SoC with 1GB of RAM and 4GB of storage. You can only access the router's admin settings by using the associated app on a mobile device.
OnHub's data transfer speeds couldn't compete with a similarly priced Asus router, but it had no problem blanketing the area with a strong signal. Ron Amadeo puts his conclusion simply: "To us, this looks like Google's smart home Trojan horse." The smartphone app that accompanies OnHub has branding for something called "Google On," which they speculate is Google's new hub for smart home products. "There are tons of competing smart home protocols out there, all of which are incompatible with one another—imagine HD-DVD versus Blu-Ray, but with about five different players. ... Other than Bluetooth and Wi-Fi, everything in OnHub is a Google/Nest/Alphabet protocol. And remember, the "Built for Google On" stamp on the bottom of the OnHub sure sounds like a third-party certification program." -
"Hack" Typeface Is Open Source, Easy On the IDEs
Ars Technica writes that "At SourceFoundry.org this week, programmer Chris Simpkins debuted the 2.0 version of Hack, an open-source typeface designed specifically for use in source code." The revamped font is "characterized by a large x-height, wide aperture, and low contrast design in order to be 'highly legible' at common coding text sizes," and the font specimen shows how legible it is right down to downright tiny sizes, though Simpkins says the sweet spot is between 8 and 12 pixels. Hack's roots are in the libre, open source typeface community, and the project expands upon the contributions of the Bitstream Vera & DejaVu projects. ... Simpkins has been working on the project throughout 2015, and he tweeted that this latest version includes "new open type features, changes in weights, significant changes in spacing, Powerline glyphs, and more." The typeface now comes with four font styles: Regular, Bold, Oblique, and Bold Oblique. -
How NASA Defended Its Assembly Facility From Hurricane Katrina
An anonymous reader writes: Tomorrow marks the 10-year anniversary of Hurricane Katrina's arrival in New Orleans. Though that time was filled with tragedy, there were survival stories, and a new article gives an insider's account of how NASA's Michoud Assembly Facility weathered the storm. Michoud was their key fuel tank production location, and if it had been lost, the space program would have gone off the rails. A 17-foot levee and a building with four water pumps capable of moving 62,000 gallons per minute stood between the storm and catastrophe for NASA's launch capabilities. "Water was merely the primary concern of the first 24 hours; Hurricane Katrina left its mark on the facilities even if Michoud was the rare speck of land to escape flooding. Roofs were lost to strong winds, one building even blew out entirely. External Tank 122 took some damage." Members of the "ride out" team spent much of the next month at Michoud, working long days to inspect and repair issues caused by the water. They maintained the facility well enough that it became a base for members of the military doing search and rescue operations. Amazingly, they did it all without any injuries to the team, and NASA didn't miss a single tank shipment. -
AMD Unveils Radeon R9 Nano, Targets Mini ITX Gaming Systems With a New Fury
MojoKid writes: AMD today added a third card to its new Fury line that's arguably the most intriguing of the bunch, the Radeon R9 Nano. True to its name, the Nano is a very compact card, though don't be fooled by its diminutive stature. Lurking inside this 6-inch graphics card is a Fiji GPU core built on a 28nm manufacturing process paired with 4GB of High Bandwidth Memory (HBM). It's a full 1.5 inches shorter than the standard Fury X, and unlike its liquid cooled sibling, there's no radiator and fan assembly to mount. The Fury Nano sports 64 compute units with 64 stream processors each for a total of 4,096 stream processors, just like Fury X. It also has an engine clock of up to 1,000MHz and pushes 8.19 TFLOPs of compute performance. That's within striking distance of the Fury X, which features a 1,050MHz engine clock at 8.6 TFLOPs. Ars Technica, too, takes a look at the new Nano. -
Oakland Changes License Plate Reader Policy After Filling 80GB Hard Drive
An anonymous reader writes: License plate scanners are a contentious subject, generating lots of debate over what information the government should have, how long they should have it, and what they should do with it. However, it seems policy changes are driven more by practical matters than privacy concerns. Earlier this year, Ars Technica reported that the Oakland Police Department retained millions of records going back to 2010. Now, the department has implemented a six-month retention window, with older data being thrown out. Why the change? They filled up the 80GB hard drive on the Windows XP desktop that hosted the data, and it kept crashing.
Why not just buy a cheap drive with an order of magnitude more storage space? Sgt. Dave Burke said, "We don't just buy stuff from Amazon as you suggested. You have to go to a source, i.e., HP or any reputable source where the city has a contract. And there's a purchase order that has to be submitted, and there has to be money in the budget. Whatever we put on the system, has to be certified. You don't just put anything. I think in the beginning of the program, a desktop was appropriate, but now you start increasing the volume of the camera and vehicles, you have to change, otherwise you're going to drown in the amount of data that's being stored." -
Many Android Users Susceptible To Plug-In Exploit -- And Many Of Them Have It
Ars Technica reports that a recently reported remote access vulnerability in Android is no longer just theoretical, but is being actively exploited. After more than 100,000 downloads of a scanning app from Check Point to evaluate users' risk from the attack, says Ars, In a blog post published today, Check Point researchers share a summary of that data—a majority (about 58 percent) of the Android devices scanned were vulnerable to the bug, with 15.84 percent actually having a vulnerable version of the remote access plug-in installed. The brand with the highest percentage of devices already carrying the vulnerable plug-in was LG—over 72 percent of LG devices scanned in the anonymized pool had a vulnerable version of the plug-in. -
Backwards S-Pen Can Permanently Damage Note 5
tlhIngan writes: Samsung recently released a new version of its popular Galaxy Note series phablet, the Note 5. However, it turns out that there is a huge design flaw in the design of its pen holder (which Samsung calls the S-pen). If you insert it backwards (pointy end out instead of in), it's possible for it get stuck damaging the S-pen detection features. While it may be possible to fix it (Ars Technica was able to, Android Police was not), there's also a chance that your pen is also stuck the wrong way in permanently as the mechanism that holds the pen in grabs the wrong end and doesn't let go.