Domain: slashdot.org
Stories and comments across the archive that link to slashdot.org.
Stories · 37,380
-
Boston Dynamics Reveals Handle, A Robot That Is 6 Feet Tall, Lifts 100 Pounds, and Jumps Up To 4 Feet (popularmechanics.com)
An anonymous reader quotes a report from Popular Mechanics: Back at the beginning of February, a leaked video showed the newest creation from Boston Dynamics -- a wheeled humanoid robot called "Handle." Now the secretive maker of amazing robots has released the full introduction video, revealing some of Handle's brand new tricks. The wheeled bot can travel up to 9 mph, and as you can see in the video, it has no trouble rolling over some light off-road terrain such as patches of grass and flights of stairs. The bot stands 6.5 feet tall when fully extended, though it often crouches to turn or balance. Batteries power the robot's electric and hydraulic actuators, allowing it to crouch down, make sharp turns, and lift objects that weigh at least 100 pounds. Handle has enough battery juice to travel about 15 miles on one charge. Oh and one more thing, this rolling bot can leap four feet into the air. -
Battle of the Carriers: T-Mobile's New Promotion Offers Three Unlimited Data Lines For $100 (theverge.com)
A battle is raging between telecommunications giants and the public is benefiting from it. In response to T-Mobile's "One" unlimited data plan announced in August, Verizon introduced unlimited data plans of their own a couple of weeks ago. This caused a ripple effect as Sprint and AT&T unveiled new unlimited data plans that same week, both of which have their own restrictions and pricing. The battle appears to show no signs of slowing as the carriers are continuing their efforts to win consumers over. Today, AT&T undercut Verizon and T-Mobile with newer unlimited data plans. The "Unlimited Choice" plan is the cheaper of the two new plans, featuring unlimited data at a maximum speed of 3 megabits per second, standard definition, and no mobile hotspot for $60 per month. While it's lower than T-Mobile's $70 plan and Verizon's $80 option, it may not be as generous as T-Mobile's latest promotion. The company just announced a new promotion after AT&T's announcement that offers three unlimited data lines for $100. The Verge reports: In its continuing efforts to attract more sign-ups, T-Mobile's latest promotion offers an additional line for free for accounts with two or more lines. The offer works whether you want to add an extra phone line or a line for wearables or tablets. The deal is available for current and new customers -- the amount of data available to the free line will match up with whatever your current plan is for the other lines. If your plan does not have the same amount of data between devices, the free line will get whatever's the lowest of the bunch. Just two weeks ago, the company updated its T-Mobile One plan to include unlimited data for $100 a month between two lines. CEO John Legere said the free line promotion also applies this new plan. If you are confused about the four carriers' recent announcements, you are not alone. We have included related links below to help you make sense of each carrier's plans. -
Battle of the Carriers: T-Mobile's New Promotion Offers Three Unlimited Data Lines For $100 (theverge.com)
A battle is raging between telecommunications giants and the public is benefiting from it. In response to T-Mobile's "One" unlimited data plan announced in August, Verizon introduced unlimited data plans of their own a couple of weeks ago. This caused a ripple effect as Sprint and AT&T unveiled new unlimited data plans that same week, both of which have their own restrictions and pricing. The battle appears to show no signs of slowing as the carriers are continuing their efforts to win consumers over. Today, AT&T undercut Verizon and T-Mobile with newer unlimited data plans. The "Unlimited Choice" plan is the cheaper of the two new plans, featuring unlimited data at a maximum speed of 3 megabits per second, standard definition, and no mobile hotspot for $60 per month. While it's lower than T-Mobile's $70 plan and Verizon's $80 option, it may not be as generous as T-Mobile's latest promotion. The company just announced a new promotion after AT&T's announcement that offers three unlimited data lines for $100. The Verge reports: In its continuing efforts to attract more sign-ups, T-Mobile's latest promotion offers an additional line for free for accounts with two or more lines. The offer works whether you want to add an extra phone line or a line for wearables or tablets. The deal is available for current and new customers -- the amount of data available to the free line will match up with whatever your current plan is for the other lines. If your plan does not have the same amount of data between devices, the free line will get whatever's the lowest of the bunch. Just two weeks ago, the company updated its T-Mobile One plan to include unlimited data for $100 a month between two lines. CEO John Legere said the free line promotion also applies this new plan. If you are confused about the four carriers' recent announcements, you are not alone. We have included related links below to help you make sense of each carrier's plans. -
Battle of the Carriers: T-Mobile's New Promotion Offers Three Unlimited Data Lines For $100 (theverge.com)
A battle is raging between telecommunications giants and the public is benefiting from it. In response to T-Mobile's "One" unlimited data plan announced in August, Verizon introduced unlimited data plans of their own a couple of weeks ago. This caused a ripple effect as Sprint and AT&T unveiled new unlimited data plans that same week, both of which have their own restrictions and pricing. The battle appears to show no signs of slowing as the carriers are continuing their efforts to win consumers over. Today, AT&T undercut Verizon and T-Mobile with newer unlimited data plans. The "Unlimited Choice" plan is the cheaper of the two new plans, featuring unlimited data at a maximum speed of 3 megabits per second, standard definition, and no mobile hotspot for $60 per month. While it's lower than T-Mobile's $70 plan and Verizon's $80 option, it may not be as generous as T-Mobile's latest promotion. The company just announced a new promotion after AT&T's announcement that offers three unlimited data lines for $100. The Verge reports: In its continuing efforts to attract more sign-ups, T-Mobile's latest promotion offers an additional line for free for accounts with two or more lines. The offer works whether you want to add an extra phone line or a line for wearables or tablets. The deal is available for current and new customers -- the amount of data available to the free line will match up with whatever your current plan is for the other lines. If your plan does not have the same amount of data between devices, the free line will get whatever's the lowest of the bunch. Just two weeks ago, the company updated its T-Mobile One plan to include unlimited data for $100 a month between two lines. CEO John Legere said the free line promotion also applies this new plan. If you are confused about the four carriers' recent announcements, you are not alone. We have included related links below to help you make sense of each carrier's plans. -
Battle of the Carriers: T-Mobile's New Promotion Offers Three Unlimited Data Lines For $100 (theverge.com)
A battle is raging between telecommunications giants and the public is benefiting from it. In response to T-Mobile's "One" unlimited data plan announced in August, Verizon introduced unlimited data plans of their own a couple of weeks ago. This caused a ripple effect as Sprint and AT&T unveiled new unlimited data plans that same week, both of which have their own restrictions and pricing. The battle appears to show no signs of slowing as the carriers are continuing their efforts to win consumers over. Today, AT&T undercut Verizon and T-Mobile with newer unlimited data plans. The "Unlimited Choice" plan is the cheaper of the two new plans, featuring unlimited data at a maximum speed of 3 megabits per second, standard definition, and no mobile hotspot for $60 per month. While it's lower than T-Mobile's $70 plan and Verizon's $80 option, it may not be as generous as T-Mobile's latest promotion. The company just announced a new promotion after AT&T's announcement that offers three unlimited data lines for $100. The Verge reports: In its continuing efforts to attract more sign-ups, T-Mobile's latest promotion offers an additional line for free for accounts with two or more lines. The offer works whether you want to add an extra phone line or a line for wearables or tablets. The deal is available for current and new customers -- the amount of data available to the free line will match up with whatever your current plan is for the other lines. If your plan does not have the same amount of data between devices, the free line will get whatever's the lowest of the bunch. Just two weeks ago, the company updated its T-Mobile One plan to include unlimited data for $100 a month between two lines. CEO John Legere said the free line promotion also applies this new plan. If you are confused about the four carriers' recent announcements, you are not alone. We have included related links below to help you make sense of each carrier's plans. -
Battle of the Carriers: T-Mobile's New Promotion Offers Three Unlimited Data Lines For $100 (theverge.com)
A battle is raging between telecommunications giants and the public is benefiting from it. In response to T-Mobile's "One" unlimited data plan announced in August, Verizon introduced unlimited data plans of their own a couple of weeks ago. This caused a ripple effect as Sprint and AT&T unveiled new unlimited data plans that same week, both of which have their own restrictions and pricing. The battle appears to show no signs of slowing as the carriers are continuing their efforts to win consumers over. Today, AT&T undercut Verizon and T-Mobile with newer unlimited data plans. The "Unlimited Choice" plan is the cheaper of the two new plans, featuring unlimited data at a maximum speed of 3 megabits per second, standard definition, and no mobile hotspot for $60 per month. While it's lower than T-Mobile's $70 plan and Verizon's $80 option, it may not be as generous as T-Mobile's latest promotion. The company just announced a new promotion after AT&T's announcement that offers three unlimited data lines for $100. The Verge reports: In its continuing efforts to attract more sign-ups, T-Mobile's latest promotion offers an additional line for free for accounts with two or more lines. The offer works whether you want to add an extra phone line or a line for wearables or tablets. The deal is available for current and new customers -- the amount of data available to the free line will match up with whatever your current plan is for the other lines. If your plan does not have the same amount of data between devices, the free line will get whatever's the lowest of the bunch. Just two weeks ago, the company updated its T-Mobile One plan to include unlimited data for $100 a month between two lines. CEO John Legere said the free line promotion also applies this new plan. If you are confused about the four carriers' recent announcements, you are not alone. We have included related links below to help you make sense of each carrier's plans. -
Questioning The Privacy Policies Of Data-Collecting Cars (autoblog.com)
Remember when Vizio's televisions started collecting data about what shows people were watching? One transportation reporter is more worried about all the data being collected by cars. schwit1 quotes Autoblog: Nowadays, auto manufacturers seem to be tripping over each other pointing out that they offer Apple CarPlay and Google Android Auto. And more recent phenomenon are announcements -- from companies including Ford and Hyundai -- that they are offering Amazon Alexa capabilities. You talk. It listens... Here's the thing. While it may seem appealing to have all manner of connectivity in cars, there is the other side of that. Without getting all tinfoil hat about this, when your TV set is ratting you out, isn't it likely that your car will? It drives. And watches. And listens. And collects data...
That data could be shared with everyone from auto insurers and advertisers to law enforcement officials and divorce attorneys. But the real problem may be consumers assuming strong privacy protections that don't actually exist. The article argues that GM's privacy policy "is like most privacy policies, which boils down to: You use it (the device, software, etc.), you potentially give up a portion of your privacy." -
Ask Slashdot: Would You Use A Cellphone With A Kill Code?
Slashdot reader gordo3000 writes: Given all the recent headlines about border patrol getting up close and personal with phones, I've been wondering why phone manufacturers don't offer a second emergency pin that you can enter that wipes all private information on the phone? In theory, it should be pretty easy to just input a different pin (or unlock pattern) that opens up a factory reset screen on the phone and in the background begins deleting all personal information.
I'd expect that same code could also lock out the USB port until it is finished deleting the data, to help prevent many of the tools they now have to copy out everything on your phone. This nicely prevents you from having to back up and wipe your phone before every trip but leaves you with a safety measure if you get harassed at the border.
It could be built into the operating system, added by the manufacturer, or perhaps sideloaded as a custom mod -- but that begs the question of whether it'd really be a popular feature. So leave your own thoughts in the comments. Would you use a cellphone with a kill code? -
'Uber Is Doomed', Argues Transportation Reporter (jalopnik.com)
When an Uber self-driving car ran a red light last year, they blamed and suspended the car's driver, even though it was the car's software that malfunctioned, according to two former employees, ultimately causing Uber cars to run six different red lights. But technical issues may be only the beginning. An anonymous reader writes: Jalopnik points out that in 2016 Uber "burned through more than $2 billion, amid findings that rider fares only cover roughly 40% of a ride, with the remainder subsidized by venture capitalists" (covering even less than the fares of government-subsidized mass transit systems). So despite Google's lawsuit and other recent bad publicity, "even when those factors are removed, it's becoming more evident that Uber will collapse on its own."
Their long analysis argues that the problems are already becoming apparent. "Uber, which didn't respond to questions from Jalopnik about its viability, recently paid $20 million to settle claims that it grossly misled how much drivers could earn on Craigslist ads. The company's explosive growth also fundamentally required it to begin offering subprime auto loans to prospective drivers without a vehicle."
Last month transportation industry analyst Hubert Horan calculated that Uber Global's losses have been "substantially greater than any venture capital-funded startup in history." -
'Uber Is Doomed', Argues Transportation Reporter (jalopnik.com)
When an Uber self-driving car ran a red light last year, they blamed and suspended the car's driver, even though it was the car's software that malfunctioned, according to two former employees, ultimately causing Uber cars to run six different red lights. But technical issues may be only the beginning. An anonymous reader writes: Jalopnik points out that in 2016 Uber "burned through more than $2 billion, amid findings that rider fares only cover roughly 40% of a ride, with the remainder subsidized by venture capitalists" (covering even less than the fares of government-subsidized mass transit systems). So despite Google's lawsuit and other recent bad publicity, "even when those factors are removed, it's becoming more evident that Uber will collapse on its own."
Their long analysis argues that the problems are already becoming apparent. "Uber, which didn't respond to questions from Jalopnik about its viability, recently paid $20 million to settle claims that it grossly misled how much drivers could earn on Craigslist ads. The company's explosive growth also fundamentally required it to begin offering subprime auto loans to prospective drivers without a vehicle."
Last month transportation industry analyst Hubert Horan calculated that Uber Global's losses have been "substantially greater than any venture capital-funded startup in history." -
'Uber Is Doomed', Argues Transportation Reporter (jalopnik.com)
When an Uber self-driving car ran a red light last year, they blamed and suspended the car's driver, even though it was the car's software that malfunctioned, according to two former employees, ultimately causing Uber cars to run six different red lights. But technical issues may be only the beginning. An anonymous reader writes: Jalopnik points out that in 2016 Uber "burned through more than $2 billion, amid findings that rider fares only cover roughly 40% of a ride, with the remainder subsidized by venture capitalists" (covering even less than the fares of government-subsidized mass transit systems). So despite Google's lawsuit and other recent bad publicity, "even when those factors are removed, it's becoming more evident that Uber will collapse on its own."
Their long analysis argues that the problems are already becoming apparent. "Uber, which didn't respond to questions from Jalopnik about its viability, recently paid $20 million to settle claims that it grossly misled how much drivers could earn on Craigslist ads. The company's explosive growth also fundamentally required it to begin offering subprime auto loans to prospective drivers without a vehicle."
Last month transportation industry analyst Hubert Horan calculated that Uber Global's losses have been "substantially greater than any venture capital-funded startup in history." -
Is Google's Comment Filtering Tool 'Vanishing' Legitimate Comments? (vortex.com)
Slashdot reader Lauren Weinstein writes: Google has announced (with considerable fanfare) public access to their new "Perspective" comment filtering system API, which uses Google's machine learning/AI system to determine which comments on a site shouldn't be displayed due to perceived high spam/toxicity scores. It's a fascinating effort. And if you run a website that supports comments, I urge you not to put this Google service into production, at least for now.
The bottom line is that I view Google's spam detection systems as currently too prone to false positives -- thereby enabling a form of algorithm-driven "censorship" (for lack of a better word in this specific context) -- especially by "lazy" sites that might accept Google's determinations of comment scoring as gospel... as someone who deals with significant numbers of comments filtered by Google every day -- I have nearly 400K followers on Google Plus -- I can tell you with considerable confidence that the problem isn't "spam" comments that are being missed, it's completely legitimate non-spam, non-toxic comments that are inappropriately marked as spam and hidden by Google.
Lauren is also collecting noteworthy experiences for a white paper about "the perceived overall state of Google (and its parent corporation Alphabet, Inc.)" to better understand how internet companies are now impacting our lives in unanticipated ways. He's inviting people to share their recent experiences with "specific Google services (including everything from Search to Gmail to YouTube and beyond), accounts, privacy, security, interactions, legal or copyright issues -- essentially anything positive, negative, or neutral that you are free to impart to me, that you believe might be of interest." -
Google Discloses Yet Another New Unpatched Microsoft Vulnerability In Edge/IE (bleepingcomputer.com)
An anonymous reader quotes BleepingComputer: Google has gone public with details of a second unpatched vulnerability in Microsoft products, this time in Edge and Internet Explorer, after last week they've published details about a bug in the Windows GDI (Graphics Device Interface) component... The bug, discovered by Google Project Zero researcher Ivan Fratric, is tracked by the CVE-2017-0037 identifier and is a type confusion, a kind of security flaw that can allow an attacker to execute code on the affected machine, and take over a device.
Details about CVE-2017-0037 are available in Google's bug report, along with proof-of-concept code. The PoC code causes a crash of the exploited browser, but depending on the attacker's skill level, more dangerous exploits could be built... Besides the Edge and IE bug, Microsoft products are also plagued by two other severe security flaws, one affecting the Windows GDI component and one the SMB file sharing protocol shipped with all Windows OS versions...
Google's team notified Microsoft of the bug 90 days ago, only disclosing it publicly on Friday. -
UK Police Arrest Suspect Behind Mirai Malware Attacks On Deutsche Telekom (bleepingcomputer.com)
An anonymous reader writes: "German police announced Thursday that fellow UK police officers have arrested a suspect behind a serious cyber-attack that crippled German ISP Deutsche Telekom at the end of November 2016," according to BleepingComputer. "The attack in question caused over 900,000 routers of various makes and models to go offline after a mysterious attacker attempted to hijack the devices through a series of vulnerabilities..." The attacks were later linked to a cybercrime groups operating a botnet powered by the Mirai malware, known as Botnet #14, which was also available for hire online for on-demand DDoS attacks.
"According to a statement obtained by Bleeping Computer from Bundeskriminalamt (the German Federal Criminal Police Office), officers from UK's National Crime Agency (NCA) arrested a 29-year-old suspect at a London airport... German authorities are now in the process of requesting the unnamed suspect's extradition, so he can stand trial in Germany. Bestbuy, the name of the hacker that took credit for the attacks, has been unreachable for days." -
UK Police Arrest Suspect Behind Mirai Malware Attacks On Deutsche Telekom (bleepingcomputer.com)
An anonymous reader writes: "German police announced Thursday that fellow UK police officers have arrested a suspect behind a serious cyber-attack that crippled German ISP Deutsche Telekom at the end of November 2016," according to BleepingComputer. "The attack in question caused over 900,000 routers of various makes and models to go offline after a mysterious attacker attempted to hijack the devices through a series of vulnerabilities..." The attacks were later linked to a cybercrime groups operating a botnet powered by the Mirai malware, known as Botnet #14, which was also available for hire online for on-demand DDoS attacks.
"According to a statement obtained by Bleeping Computer from Bundeskriminalamt (the German Federal Criminal Police Office), officers from UK's National Crime Agency (NCA) arrested a 29-year-old suspect at a London airport... German authorities are now in the process of requesting the unnamed suspect's extradition, so he can stand trial in Germany. Bestbuy, the name of the hacker that took credit for the attacks, has been unreachable for days." -
How Cable Monopolies Hurt ISP Customers (backchannel.com)
"New York subscribers have had to overpay month after month for services that Spectrum deliberately didn't provide," reports Backchannel -- noting these practices are significant because together Comcast and Charter (formerly Time Warner Cable) account for half of America's 92 million high-speed internet connections. An anonymous reader quotes Backchannel: Based on the company's own documents and statements, it appears that just about everything it has been saying since 2012 to New York State residents about their internet access and data services is untrue...because of business decisions the company deliberately made in order to keep its capital expenditures as low as possible... Its marketing department kept sending out advertising claims to the public that didn't match the reality of what consumers were experiencing or square with what company engineers were telling Spectrum executives. That gives the AG's office its legal hook: Spectrum's actions in knowingly saying one thing but doing another amount to fraudulent, unfair, and deceptive behavior under New York law...
The branding people went nuts, using adjectives like Turbo, Extreme, and Ultimate for the company's highest-speed 200 or 300 Mbps download offerings. But no one, or very few people, could actually experience those speeds...because, according to the complaint, the company deliberately required that internet data connections be shared among a gazillion people in each neighborhood... [T]he lawsuit won't by itself make much of a difference. But maybe the public nature of the attorney-general's assault -- charging Spectrum for illegal misconduct -- will lead to a call for alternatives. Maybe it will generate momentum for better, faster, wholesale fiber networks controlled by cities and localities themselves. If that happened, retail competition would bloom. We'd get honest, straightforward, inexpensive service, rather than the horrendously expensive cable bundles we're stuck with today.
The article says Spectrum charged 800,000 New Yorkers $10 a month for outdated cable boxes that "weren't even capable of transmitting and receiving wifi at the speeds the company advertised customers would be getting," then promised the FCC in 2013 that they'd replace them, and then didn't. "With no competition, it had no reason to upgrade its services. Indeed, the company's incentives went exactly in the other direction." -
Ask Slashdot: How Are You Responding To Cloudbleed? (reuters.com)
An anonymous IT geek writes: Cloudflare-hosted web sites have been leaking data as far back as September, according to Gizmodo, which reports that at least Cloudflare "acted fast" when the leak was discovered, closing the hole within 44 minutes, and working with search engines to purge their caches. (Though apparently some of it is still lingering...) Cloudflare CEO Matthew Prince "claims that there was no detectable uptick in requests to Cloudflare-powered websites from September of last year...until today. That means the company is fairly confident hackers didn't discover the vulnerability before Google's researchers did."
And the company's CTO also told Reuters that "We've seen absolutely no evidence that this has been exploited. It's very unlikely that someone has got this information... We do not know of anybody who has had a security problem as a result of this." Nevertheless, Fortune warns that "So many sites were vulnerable that it doesn't make sense to review the list and change passwords on a case-by-case basis." Some sites are now even resetting every user's password as a precaution, while site operators "are also being advised to wipe their sites' cookies and security certificates, and perform their own web searches to see if site data leaked." But I'd like to know what security precautions are being taken by Slashdot's readers?
Leave your own answers in the comments. How did you respond to Cloudbleed? -
Linus Torvalds On Git's Use Of SHA-1: 'The Sky Isn't Falling' (zdnet.com)
Google's researchers specifically cited Git when they announced a new SHA-1 attack vector, according to ZDNet. "The researchers highlight that Linus Torvald's code version-control system Git 'strongly relies on SHA-1' for checking the integrity of file objects and commits. It is essentially possible to create two Git repositories with the same head commit hash and different contents, say, a benign source code and a backdoored one,' they note." Saturday morning, Linus responded: First off - the sky isn't falling. There's a big difference between using a cryptographic hash for things like security signing, and using one for generating a "content identifier" for a content-addressable system like git. Secondly, the nature of this particular SHA1 attack means that it's actually pretty easy to mitigate against, and there's already been two sets of patches posted for that mitigation. And finally, there's actually a reasonably straightforward transition to some other hash that won't break the world - or even old git repositories...
The reason for using a cryptographic hash in a project like git is because it pretty much guarantees that there is no accidental clashes, and it's also a really really good error detection thing. Think of it like "parity on steroids": it's not able to correct for errors, but it's really really good at detecting corrupt data... if you use git for source control like in the kernel, the stuff you really care about is source code, which is very much a transparent medium. If somebody inserts random odd generated crud in the middle of your source code, you will absolutely notice... It's not silently switching your data under from you... And finally, the "yes, git will eventually transition away from SHA1". There's a plan, it doesn't look all that nasty, and you don't even have to convert your repository. There's a lot of details to this, and it will take time, but because of the issues above, it's not like this is a critical "it has to happen now thing".
In addition, ZDNet reports, "Torvalds said on a mailing list yesterday that he's not concerned since 'Git doesn't actually just hash the data, it does prepend a type/length field to it', making it harder to attack than a PDF... Do we want to migrate to another hash? Yes. Is it game over for SHA-1 like people want to say? Probably not." -
$10K Package Of Super Nintendo Games Finally Found By Post Office (eurogamer.net)
A project to preserve (and validate) every Super Nintendo game ROM had been derailed when the post office lost a package containing 100 games from the PAL region. But now Byuu, the creator of the Higan SNES emulator, reports that the package has been found. An anonymous reader writes: Thursday Byuu finally posted photos of the unboxing for the package that was shipped to him January 5th. "I'd like to offer my sincerest apologies to the USPS for assuming the worst in that these games were stolen. I should not have been so hasty to assume malicious intent." At the same time, Byuu writes that "My package was sitting in Atlanta, GA for well over a month with my address clearly visible right on the box. Had this case not been escalated to the media, it likely would have gone up for auction in a bin with other electronics sometime in March."
Byuu is now refunding donations he'd received to replace the missing games, and says he can now also resume work on the SNES Preservation Project. And going forward, according to Eurogamer, "Byuu has said he will be more cautious with shipping games in the future -- only using smaller shipments, or buying individual games to scan and archive then selling them on to get some money back." -
Are Your Slack Conversations Really Private and Secure? (fastcompany.com)
An anonymous reader writes: "Chats that seem to be more ephemeral than email are still being recorded on a server somewhere," reports Fast Company, noting that Slack's Data Request Policy says the company will turn over data from customers when "it is compelled by law to do so or is subject to a valid and binding order of a governmental or regulatory body...or in cases of emergency to avoid death or physical harm to individuals." Slack will notify customers before disclosure "unless Slack is prohibited from doing so," or if the data is associated with "illegal conduct or risk of harm to people or property."
The article also warns that like HipChat and Campfire, Slack "is encrypted only at rest and in transit," though a Slack spokesperson says they "may evaluate" end-to-end encryption at some point in the future. Slack has no plans to offer local hosting of Slack data, but if employers pay for a Plus Plan, they're able to access private conversations.
Though Slack has 4 million users, the article points out that there's other alternatives like Semaphor and open source choices like Wickr and Mattermost. I'd be curious to hear what Slashdot readers are using at their own workplaces -- and how they feel about the privacy and security of Slack? -
Are Your Slack Conversations Really Private and Secure? (fastcompany.com)
An anonymous reader writes: "Chats that seem to be more ephemeral than email are still being recorded on a server somewhere," reports Fast Company, noting that Slack's Data Request Policy says the company will turn over data from customers when "it is compelled by law to do so or is subject to a valid and binding order of a governmental or regulatory body...or in cases of emergency to avoid death or physical harm to individuals." Slack will notify customers before disclosure "unless Slack is prohibited from doing so," or if the data is associated with "illegal conduct or risk of harm to people or property."
The article also warns that like HipChat and Campfire, Slack "is encrypted only at rest and in transit," though a Slack spokesperson says they "may evaluate" end-to-end encryption at some point in the future. Slack has no plans to offer local hosting of Slack data, but if employers pay for a Plus Plan, they're able to access private conversations.
Though Slack has 4 million users, the article points out that there's other alternatives like Semaphor and open source choices like Wickr and Mattermost. I'd be curious to hear what Slashdot readers are using at their own workplaces -- and how they feel about the privacy and security of Slack? -
ZeniMax Files Injunction To Stop Oculus From Selling VR Headsets (gamespot.com)
ZeniMax, the parent company of Fallout and Skyrim developer Bethesda, has filed for an injunction against virtual-reality company Oculus over the recent stolen technology case. The company had accused Oculus of stealing VR-related code, and was subsequently awarded $500 million by a Dallas court earlier this month. ZeniMax has now filed additional papers against Oculus, requesting that Oculus' products using the stolen code be removed from sale. GameSpot reports: Specifically, ZeniMax is seeking to block sales of its mobile and PC developer kits, as well as technology allowing the integration of Oculus Rift with development engines Unreal and Unity, reports Law360. If the injunction isn't granted, ZeniMax wants a share of "revenues derived from products incorporating its intellectual properties," suggesting a 20 percent cut for at least 10 years. ZeniMax argues the previous settlement of $500 million is "insufficient incentive for [Oculus] to cease infringing." Oculus, meanwhile, says that "ZeniMax's motion does not change the fact that the [original] verdict was legally flawed and factually unwarranted. We look forward to filing our own motion to set aside the jury's verdict and, if necessary, filing an appeal that will allow us to put this litigation behind us," the virtual reality company stated. -
ZeniMax Files Injunction To Stop Oculus From Selling VR Headsets (gamespot.com)
ZeniMax, the parent company of Fallout and Skyrim developer Bethesda, has filed for an injunction against virtual-reality company Oculus over the recent stolen technology case. The company had accused Oculus of stealing VR-related code, and was subsequently awarded $500 million by a Dallas court earlier this month. ZeniMax has now filed additional papers against Oculus, requesting that Oculus' products using the stolen code be removed from sale. GameSpot reports: Specifically, ZeniMax is seeking to block sales of its mobile and PC developer kits, as well as technology allowing the integration of Oculus Rift with development engines Unreal and Unity, reports Law360. If the injunction isn't granted, ZeniMax wants a share of "revenues derived from products incorporating its intellectual properties," suggesting a 20 percent cut for at least 10 years. ZeniMax argues the previous settlement of $500 million is "insufficient incentive for [Oculus] to cease infringing." Oculus, meanwhile, says that "ZeniMax's motion does not change the fact that the [original] verdict was legally flawed and factually unwarranted. We look forward to filing our own motion to set aside the jury's verdict and, if necessary, filing an appeal that will allow us to put this litigation behind us," the virtual reality company stated. -
World's Largest Spam Botnet Adds DDoS Feature (bleepingcomputer.com)
An anonymous reader writes from a report via BleepingComputer: Necurs, the world's largest spam botnet with nearly five million infected bots, of which one million are active each day, has added a new module that can be used for launching DDoS attacks. The sheer size of the Necurs botnet, even in its worst days, dwarfs all of today's IoT botnets. The largest IoT botnet ever observed was Mirai Botnet #14 that managed to rack up around 400,000 bots towards the end of 2016 (albeit the owner of that botnet has now been arrested). If this new feature were to ever be used, a Necurs DDoS attack would easily break every DDoS record there is. Fortunately, no such attack has been seen until now. Until now, the Necurs botnet has been seen spreading the Dridex banking trojan and the Locky ransomware. According to industry experts, there's a low chance we'd see the Necurs botnet engage in DDoS attacks because the criminal group behind the botnet is already making too much money to risk exposing their full infrastructure in DDoS attacks. -
World's Largest Spam Botnet Adds DDoS Feature (bleepingcomputer.com)
An anonymous reader writes from a report via BleepingComputer: Necurs, the world's largest spam botnet with nearly five million infected bots, of which one million are active each day, has added a new module that can be used for launching DDoS attacks. The sheer size of the Necurs botnet, even in its worst days, dwarfs all of today's IoT botnets. The largest IoT botnet ever observed was Mirai Botnet #14 that managed to rack up around 400,000 bots towards the end of 2016 (albeit the owner of that botnet has now been arrested). If this new feature were to ever be used, a Necurs DDoS attack would easily break every DDoS record there is. Fortunately, no such attack has been seen until now. Until now, the Necurs botnet has been seen spreading the Dridex banking trojan and the Locky ransomware. According to industry experts, there's a low chance we'd see the Necurs botnet engage in DDoS attacks because the criminal group behind the botnet is already making too much money to risk exposing their full infrastructure in DDoS attacks. -
FCC To Halt Rule That Protects Your Private Data From Security Breaches (arstechnica.com)
According to Ars Technica, "The Federal Communications Commission plans to halt implementation of a privacy rule that requires ISPs to protect the security of its customers' personal information." From the report: The data security rule is part of a broader privacy rulemaking implemented under former Chairman Tom Wheeler but opposed by the FCC's new Republican majority. The privacy order's data security obligations are scheduled to take effect on March 2, but Chairman Ajit Pai wants to prevent that from happening. The data security rule requires ISPs and phone companies to take "reasonable" steps to protect customers' information -- such as Social Security numbers, financial and health information, and Web browsing data -- from theft and data breaches. The rule would be blocked even if a majority of commissioners supported keeping them in place, because the FCC's Wireline Competition Bureau can make the decision on its own. That "full commission vote on the pending petitions" could wipe out the entire privacy rulemaking, not just the data security section, in response to petitions filed by trade groups representing ISPs. That vote has not yet been scheduled. The most well-known portion of the privacy order requires ISPs to get opt-in consent from consumers before sharing Web browsing data and other private information with advertisers and other third parties. The opt-in rule is supposed to take effect December 4, 2017, unless the FCC or Congress eliminates it before then. Pai has said that ISPs shouldn't face stricter rules than online providers like Google and Facebook, which are regulated separately by the Federal Trade Commission. Pai wants a "technology-neutral privacy framework for the online world" based on the FTC's standards. According to today's FCC statement, the data security rule "is not consistent with the FTC's privacy standards." -
Founder of India's $4 Smartphone Firm Arrested on Allegations of Fraud (reuters.com)
Remember the $4 smartphone from India? Yeah, things haven't really materialized. Reuters reports: The founder of an Indian tech firm that shot to prominence by offering a $4 smartphone has been arrested on allegations of fraud, after a handset dealer accused the company of not refunding him for an unfulfilled order, the police said. Mohit Goel, the founder of Ringing Bells, was arrested Thursday afternoon in Uttar Pradesh and will be produced in court later on Friday, said Rahul Srivastav, a police spokesman from the northern Indian state. Goel and his company made headlines last year with the "Freedom" smartphone, which was priced at 251 rupees ($3.77), attracting strong demand but also widespread scepticism and scrutiny from regulators even in price-conscious India, where cheap smartphones are big sellers. The founder was arrested after a dealer said he had paid 3 million Indian rupees for an order of handsets but had received only a fraction of the order. He further said some of the phones received were defective, according to the police. -
Cloudflare Leaks Sensitive User Data Across the Web (theregister.co.uk)
ShaunC writes: In a bug that's been christened "Cloudbleed," Cloudflare disclosed today that some of their products accidentally exposed private user information from a number of websites. Similar to 2014's Heartbleed, Cloudflare's problem involved a buffer overrun that allowed uninitialized memory contents to leak into normal web traffic. Tavis Ormandy, of Google's Project Zero, discovered the flaw last week. Affected sites include Uber, Fitbit, and OK Cupid, as well as unnamed services for hotel booking and password management. Cloudflare says the bug has been fixed, and Google has purged affected pages from its search index and cache. Further reading: The Register, Ars Technica -
World's Only Sample of Metallic Hydrogen Has Been Lost (ibtimes.co.uk)
New submitter drunkdrone quotes a report from International Business Times: A piece of rare meta poised to revolutionize modern technology and take humans into deep space has been lost in a laboratory mishap. The first and only sample of metallic hydrogen ever created on earth was the rarest material on the planet when it was developed by Harvard scientists in January this year, and had been dubbed "the holy grail of high pressure physics." The metal was created by subjecting liquid hydrogen to pressures greater that those at the center of the Earth. At this point, the molecular hydrogen breaks down and becomes an atomic solid. Scientists theorized that metallic hydrogen -- when used as a superconductor -- could have a transformative effect on modern electronics and revolutionize medicine, energy and transportation, as well as herald in a new age of consumer gadgets. Sadly, an attempt to study the properties of metallic hydrogen appears to have ended in catastrophe after one of the two diamonds being used like a vice to hold the tiny sample was obliterated. The metal was being held between two diamonds at a pressure of around 71.7 million pounds per square inch -- more than a third greater than at the Earth's core. According to The Independent, one of these diamonds shattered while the sample was being measured with a laser, and the metal was lost in the process. -
Cellebrite Can Now Unlock Apple iPhone 6, 6 Plus (cyberscoop.com)
Patrick O'Neill writes: A year after the battle between the FBI and Apple over unlocking an iPhone 5c used by a shooter in the San Bernardino terrorist attack, smartphone cracking company Cellebrite announced it can now unlock the iPhone 6 and 6 Plus for customers at rates ranging from $1,500 to $250,000. The company's newest products also extract and analyze data from a wide range of popular apps including all of the most popular secure messengers around. From the Cyberscoop report: "Cellebrite's ability to break into the iPhone 6 and 6 Plus comes in their latest line of product releases. The newest Cellebrite product, UFED 6.0, boasts dozens of new and improved features including the ability to extract data from 51 Samsung Android devices including the Galaxy S7 and Galaxy S7 Edge, the latest flagship models for Android's most popular brand, as well as the new high-end Google Pixel Android devices." -
Microsoft Creates Skype Lite Especially For India (cnet.com)
There's a new Skype app in town, and it is made just for India. According to a report on CNET: Microsoft is the latest US tech giant to help keep Indians connected. Skype Lite is a new version of the company's popular video and voice-calling app that's "built in India." Skype Lite functions much like its big brother Skype, but it's designed to work well on low-speed, 2G networks, which are still prevalent in India and many developing nations. It uses less data and battery power than the fully fledged app, and at 13MB it's around a third of the download size. Skype Lite, available for Android, also uses India's controversial Aadhaar biometric authentication. -
Inside Uber's Aggressive, Unrestrained Workplace Culture (cnbc.com)
Excerpts from Mike Isaac's report for the New York Times: Interviews with more than 30 current and former Uber employees, as well as reviews of internal emails, chat logs and tape-recorded meetings, paint a picture of an often unrestrained workplace culture. Among the most egregious accusations from employees, who either witnessed or were subject to incidents and who asked to remain anonymous because of confidentiality agreements and fear of retaliation: One Uber manager groped female co-workers' breasts at a company retreat in Las Vegas. A director shouted a homophobic slur at a subordinate during a heated confrontation in a meeting. Another manager threatened to beat an underperforming employee's head in with a baseball bat. Until this week, this culture was only whispered about in Silicon Valley. Then on Sunday, Susan Fowler, an engineer who left Uber in December, published a blog post about her time at the company. [...] One group appeared immune to internal scrutiny, the current and former employees said. Called the A-Team and composed of a small group of executives who were personally close to Mr. Kalanick, its members were shielded from much accountability over their actions. One member of the A-Team was Emil Michael, senior vice president for business, who was caught up in a public scandal over comments he made in 2014 about digging into the private lives of journalists who opposed the company. Mr. Kalanick defended Mr. Michael, saying he believed Mr. Michael could learn from his mistakes. -
Microsoft Research Developing An AI To Put Coders Out of a Job (mspoweruser.com)
jmcbain writes: Are you a software programmer who voted in a recent Slashdot poll that a robot/AI would never take your job? Unfortunately, you're wrong. Microsoft, in collaboration with the University of Cambridge, is developing such an AI. This software "can turn your descriptions into working code in seconds," reports MSPoweruser. "Called DeepCoder, the software can take requirements by the developer, search through a massive database of code snippets and deliver working code in seconds, a significant advance in the state of the art in program synthesis." New Scientist describes program synthesis as "creating new programs by piecing together lines of code taken from existing software -- just like a programmer might. Given a list of inputs and outputs for each code fragment, DeepCoder learned which pieces of code were needed to achieve the desired result overall." The original research paper can be read here. -
Tesla Posts Earnings Loss But Claims Model 3 Production Will Start In July (bgr.com)
An anonymous Slashdot reader shares a report from BGR: Tesla on Wednesday released its earnings report (PDF) for the company's recent fourth quarter. When the dust settled, Tesla posted revenue of $2.28 billion and a loss of 69 cents per share. By way of contrast, Tesla during the same quarter a year-ago posted a loss of $0.87 per share on the back of $1.75 billion in revenue. Notably, Tesla notes that its cumulative 2016 revenue checked in at $7 billion, a 73% increase from 2015. As far as the Model 3 is concerned, Tesla's press release relays that the company is still on track to begin production in July ahead of volume production in September.
Tesla notes in its press release: "Our Model 3 program is on track to start limited vehicle production in July and to steadily ramp production to exceed 5,000 vehicles per week at some point in the fourth quarter and 10,000 vehicles per week at some point in 2018. To support accelerating vehicle deliveries and maintain our industry-leading customer satisfaction, we are expanding our retail, Supercharger, and service functions. Model 3 vehicle development, supply chain and manufacturing are on track to support volume deliveries in the second half of 2017. In early February, we began building Model 3 prototypes as part of our ongoing testing of the vehicle design and manufacturing processes. Initial crash test results have been positive, and all Model 3-related sourcing is on plan to support the start of production in July. Installation of Model 3 manufacturing equipment is underway in Fremont and at Gigafactory 1, where in January, we began production of battery cells for energy storage products, which have the same form-factor as the cells that will be used in Model 3." -
Apple's New Spaceship Campus Gets a Name, Lifts Off In April (arstechnica.com)
An anonymous reader quotes a report from Ars Technica: Apple has been building its giant new "spaceship" campus in the company's hometown of Cupertino, California, since December of 2013, and since then fans have paid obsessive attention to the structure. It gets buzzed by drones constantly, and the most popular YouTube videos of the building in progress have amassed well over half-a-million views apiece. The company announced today that the campus will be open to employees starting in April and that the building and environs now have a name: Apple Park. Apple says that moving the 12,000 employees who will work at the campus will take more than six months, and landscaping and construction on some buildings won't be done until the summer. The new campus mostly replaces the university-style Infinite Loop campus Apple has used since 1993, though Apple has said that it will also be keeping the older buildings. The new campus' cost has been estimated at around $5 billion. Apple will also be naming one space on the new campus after its founder and former CEO -- the Steve Jobs Theater will replace the current Town Hall event space that Apple sometimes uses for company meetings and product announcements, and it will open "later this year." The new space will be much larger (it will seat 1,000, compared to roughly 300 for the Town Hall), and the larger space will presumably allow Apple to launch more of its products on its campus rather than having to rent expensive event space in downtown San Francisco. The company is also moving its Worldwide Developers Conference closer to home this year -- it will return to San Jose after many years at the Moscone Center in San Francisco. -
Valve's Gabe Newell Says Only 30 SteamVR Apps Have Made $250,000+ (roadtovr.com)
New submitter rentarno writes: According to Valve President, Gabe Newell, only 30 virtual-reality apps on Steam (of some 1,000) have made more than $250,000. But that isn't stopping the company from throwing the bulk of their weight behind virtual reality; Valve recently confirmed that it's working on 3 full VR games. Valve still believes in a huge future for VR, even while things are slow to start. It'll take work to find and make the content that's great for VR, Newell says. "We got Half-Life 2 and Team Fortress running in VR. It was kind of a novelty, purely a development milestone. There was absolutely nothing compelling about them. Nobody's going to buy a VR system so they can watch movies. You have to aspire and be optimistic that the unique characteristics of VR will cause you to discover a bunch of stuff that isn't possible on any of the existing platforms." How do you view the VR industry in early 2017? Do you think it shows promise or will eventually fail like 3D TV? -
Samsung To Sell Refurbished Galaxy Note 7 With a Smaller Battery, Says Report (androidauthority.com)
According to a report via The Korean Economic Daily, Samsung is said to be putting refurbished Galaxy Note 7 handsets on sale with new batteries following the cancellation of the device late last year. The speculation suggests the smartphones could be relaunched this June. Android Authority reports: Samsung is said to be swapping the Note 7's 3,500 mAh batteries with a "3,000 to 3,200 mAh" batteries, according to The Korean Economic Daily's sources, predominately for sale in emerging markets such as India and Vietnam. The move is said to be part of Samsung's plan to recover costs from the initial device recall and avoid environmental penalties from the estimated 2.5 million or so Galaxy Note 7s it would have to dispose of. Samsung hasn't made any official announcements in this vein, but before the battery investigation concluded, a spokesperson did tell us that the company was: "Reviewing possible options that can minimize the environmental impact of the recall." Shifting refurbished units would certainly be one way to achieve that. -
Samsung To Sell Refurbished Galaxy Note 7 With a Smaller Battery, Says Report (androidauthority.com)
According to a report via The Korean Economic Daily, Samsung is said to be putting refurbished Galaxy Note 7 handsets on sale with new batteries following the cancellation of the device late last year. The speculation suggests the smartphones could be relaunched this June. Android Authority reports: Samsung is said to be swapping the Note 7's 3,500 mAh batteries with a "3,000 to 3,200 mAh" batteries, according to The Korean Economic Daily's sources, predominately for sale in emerging markets such as India and Vietnam. The move is said to be part of Samsung's plan to recover costs from the initial device recall and avoid environmental penalties from the estimated 2.5 million or so Galaxy Note 7s it would have to dispose of. Samsung hasn't made any official announcements in this vein, but before the battery investigation concluded, a spokesperson did tell us that the company was: "Reviewing possible options that can minimize the environmental impact of the recall." Shifting refurbished units would certainly be one way to achieve that. -
'We Won't Block Pirate Bay,' Swedish Telecoms Giant Says (torrentfreak.com)
Last week, a Swedish Patent and Market Court of Appeal ordered The Pirate Bay and streaming portal Swefilmer to be blocked by internet service provider Bredbandsbolaget for the next three years. The order was not well supported by other internet service providers in Sweden, as it appears they don't like the idea of becoming copyright policemen. TorrentFreak reports: Last week ISP Bahnhof absolutely slammed the decision to block The Pirate Bay, describing the effort as signaling the "death throes" of the copyright industry. It even hinted that it may offer some kind of technical solution to customers who are prevented from accessing the site. For those familiar with Bahnhof's stance over the years, this response didn't come as a surprise. The ISP is traditionally pro-freedom and has gone out of its way to make life difficult for copyright enforcers of all kinds. However, as one of the leading telecoms companies in Sweden and neighboring Norway, ISP Telia is more moderate. Nevertheless, it too says it has no intention of blocking The Pirate Bay, unless it is forced to do so by law. "No, we will not block if we are not forced to do so by a court," a company press officer said this morning. Telia says that the decision last week from the Patent and Market Court affects only Bredbandsbolaget, indicating that a fresh legal process will be required to get it to respond. That eventuality appears to be understood by the rightsholders but they're keeping their options open. -
Wyden To Introduce Bill To Prohibit Warrantless Phone Searches At Border (onthewire.io)
Trailrunner7 quotes a report from On the Wire: A senator from Oregon who has a long track record of involvement on security and privacy issues says he plans to introduce a bill soon that would prevent border agents from forcing Americans returning to the country to unlock their phones without a warrant. Sen. Ron Wyden said in a letter to the secretary of the Department of Homeland Security that he is concerned about reports that Customs and Border Patrol agents are pressuring returning Americans into handing over their phone PINs or using their fingerprints to unlock their phones. DHS Secretary John Kelly has said that he's considering the idea of asking visitors for the login data for their various social media accounts, information that typically would require a warrant to obtain. "Circumventing the normal protection for such private information is simply unacceptable," Wyden said in the letter, sent Monday. "There are well-established procedures governing how law enforcement agencies may obtain data from social media companies and email providers. The process typically requires that the government obtain a search warrant or other court order, and then ask the service provider to turn over the user's data." -
Kim Dotcom Can Be Extradited, Rules A New Zealand Court (reuters.com)
Kim Dotcom -- and Megaupload's programmers Mathias Ortmann and Bram van der Kolk, as well as its advertising manager Finn Batato -- could soon be in a U.S. courtroom. A New Zealand judge just ruled they can all be extradited to the U.S. An anonymous reader quotes Reuters: The Auckland High Court upheld the decision by a lower court in 2015 on 13 counts, including allegations of conspiracy to commit racketeering, copyright infringement, money laundering and wire fraud, although it described that decision as "flawed" in several areas. Dotcom's lawyer Ron Mansfield said in a statement the decision was "extremely disappointing" and that Dotcom would appeal to New Zealand's Court of Appeal.
U.S. authorities say Dotcom and three co-accused Megaupload executives cost film studios and record companies more than $500 million and generated more than $175 million by encouraging paying users to store and share copyrighted material. High Court judge Murray Gilbert said that there was no crime for copyright in New Zealand law that would justify extradition but that the Megaupload-founder could be sent to the United States to face allegations of fraud.
"I'm no longer getting extradited for copyright," Dotcom commented on Twitter. "We won on that. I'm now getting extradited for a law that doesn't even apply. -
ZDNet: Linux 'Takes The World' While Windows Dominates The Desktop (zdnet.com)
ZDNet editor-in-chief Steve Ranger writes that desktop dominance is less important with today's cloud-based apps running independent of operating system, arguing that the desktop is now "just one computing platform among many." An anonymous reader quotes his report: Linux on the desktop has about a 2% market share today and is viewed by many as complicated and obscure. Meanwhile, Windows sails on serenely, currently running on 90% of PCs in use... That's probably OK because Linux won the smartphone war and is doing pretty well on the cloud and Internet of Things battlefields too.
There's a four-in-five chance that there's a Linux-powered smartphone in your pocket (Android is based on the Linux kernel) and plenty of IoT devices are Linux-powered too, even if you don't necessarily notice it. Devices like the Raspberry Pi, running a vast array of different flavours of Linux, are creating an enthusiastic community of makers and giving startups a low-cost way to power new types of devices. Much of the public cloud is running on Linux in one form or another, too; even Microsoft has warmed up to open-source software. -
Serious Computer Glitches Can Be Caused By Cosmic Rays (computerworld.com)
The Los Alamos National Lab wrote in 2012 that "For over 20 years the military, the commercial aerospace industry, and the computer industry have known that high-energy neutrons streaming through our atmosphere can cause computer errors." Now an anonymous reader quotes Computerworld: When your computer crashes or phone freezes, don't be so quick to blame the manufacturer. Cosmic rays -- or rather the electrically charged particles they generate -- may be your real foe. While harmless to living organisms, a small number of these particles have enough energy to interfere with the operation of the microelectronic circuitry in our personal devices... particles alter an individual bit of data stored in a chip's memory. Consequences can be as trivial as altering a single pixel in a photograph or as serious as bringing down a passenger jet.
A "single-event upset" was also blamed for an electronic voting error in Schaerbeekm, Belgium, back in 2003. A bit flip in the electronic voting machine added 4,096 extra votes to one candidate. The issue was noticed only because the machine gave the candidate more votes than were possible. "This is a really big problem, but it is mostly invisible to the public," said Bharat Bhuva. Bhuva is a member of Vanderbilt University's Radiation Effects Research Group, established in 1987 to study the effects of radiation on electronic systems.
Cisco has been researching cosmic radiation since 2001, and in September briefly cited cosmic rays as a possible explanation for partial data losses that customer's were experiencing with their ASR 9000 routers. -
Google Discloses An Unpatched Windows Bug (Again) (bleepingcomputer.com)
An anonymous reader writes: "For the second time in three months, Google engineers have disclosed a bug in the Windows OS without Microsoft having released a fix before Google's announcement," reports BleepingComputer. "The bug in question affects the Windows GDI (Graphics Device Interface) (gdi32.dll)..." According to Google, the issue allows an attacker to read the content of the user's memory using malicious EMF files. The bad news is that the EMF file can be hidden in other documents, such as DOCX, and can be exploited via Office, IE, or Office Online, among many.
"According to a bug report filed by Google's Project Zero team, the bug was initially part of a larger collection of issues discovered in March 2016, and fixed in June 2016, via Microsoft's security bulletin MS16-074. Mateusz Jurczyk, the Google engineer who found the first bugs, says the MS16-074 patches were insufficient, and some of the issues he reported continued to remain vulnerable." He later resubmitted the bugs in November 2016. The 90-days deadline for fixing the bugs expired last week, and the Google researcher disclosed the bug to the public after Microsoft delayed February's security updates to next month's Patch Tuesday, for March 15.
Microsoft has described Google's announcements of unpatched Windows bugs as "disappointing". -
Self-Driving Car Speed Race Ends With A Crash (electrek.co)
An anonymous reader writes:On a professional track in Buenos Aires, fans watched the first Formula E auto race with self-driving electric cars. "Roborace's two test vehicles battled it out on the circuit at a reasonably quick 115MPH," reports Engadget, "but one of the cars crashed after it took a turn too aggressively. The racing league was quick to tout the safety advantages of crashing autonomous cars ('no drivers were harmed'), but it's clear that the tech is still rough around the edges." Electrek is reporting that the cars "still have a cabin for a driver but neither car's cabin was occupied during the event." The ultimate goal is to have several teams racing the exact same self-driving car, while letting each team customize its car's driving software.
An Argentinian journalist shared footage of the race cars on Twitter, and apparently at one point a dog wandered out in front of an oncoming race car. But the real question is how the fans are going to feel about watching a speed race between cars with no drivers? -
Krebs: 'Men Who Sent SWAT Team, Heroin to My Home Sentenced' (krebsonsecurity.com)
An anonymous reader quotes KrebsOnSecurity: On Thursday, a Ukrainian man who hatched a plan in 2013 to send heroin to my home and then call the cops when the drugs arrived was sentenced to 41 months in prison for unrelated cybercrime charges. Separately, a 19-year-old American who admitted to being part of a hacker group that sent a heavily-armed police force to my home in 2013 was sentenced to three years probation.
Sergey Vovnenko, a.k.a. "Fly," "Flycracker" and "MUXACC1," pleaded guilty last year to aggravated identity theft and conspiracy to commit wire fraud. Prosecutors said Vovnenko operated a network of more than 13,000 hacked computers, using them to harvest credit card numbers and other sensitive information... A judge in New Jersey sentenced Vovnenko to 41 months in prison, three years of supervised released and ordered him to pay restitution of $83,368.
Separately, a judge in Washington, D.C. handed down a sentence of three year's probation to Eric Taylor, a hacker probably better known by his handle "Cosmo the God." Taylor was among several men involved in making a false report to my local police department at the time about a supposed hostage situation at our Virginia home. In response, a heavily-armed police force surrounded my home and put me in handcuffs at gunpoint before the police realized it was all a dangerous hoax known as "swatting"... Taylor and his co-conspirators were able to dox so many celebrities and public officials because they hacked a Russian identity theft service called ssndob[dot]ru. That service in turn relied upon compromised user accounts at data broker giant LexisNexis to pull personal and financial data on millions of Americans. -
Krebs: 'Men Who Sent SWAT Team, Heroin to My Home Sentenced' (krebsonsecurity.com)
An anonymous reader quotes KrebsOnSecurity: On Thursday, a Ukrainian man who hatched a plan in 2013 to send heroin to my home and then call the cops when the drugs arrived was sentenced to 41 months in prison for unrelated cybercrime charges. Separately, a 19-year-old American who admitted to being part of a hacker group that sent a heavily-armed police force to my home in 2013 was sentenced to three years probation.
Sergey Vovnenko, a.k.a. "Fly," "Flycracker" and "MUXACC1," pleaded guilty last year to aggravated identity theft and conspiracy to commit wire fraud. Prosecutors said Vovnenko operated a network of more than 13,000 hacked computers, using them to harvest credit card numbers and other sensitive information... A judge in New Jersey sentenced Vovnenko to 41 months in prison, three years of supervised released and ordered him to pay restitution of $83,368.
Separately, a judge in Washington, D.C. handed down a sentence of three year's probation to Eric Taylor, a hacker probably better known by his handle "Cosmo the God." Taylor was among several men involved in making a false report to my local police department at the time about a supposed hostage situation at our Virginia home. In response, a heavily-armed police force surrounded my home and put me in handcuffs at gunpoint before the police realized it was all a dangerous hoax known as "swatting"... Taylor and his co-conspirators were able to dox so many celebrities and public officials because they hacked a Russian identity theft service called ssndob[dot]ru. That service in turn relied upon compromised user accounts at data broker giant LexisNexis to pull personal and financial data on millions of Americans. -
Alaska Gets 'Artificial Aurora' As HAARP Antenna Array Listens Again (hackaday.com)
Freshly Exhumed quotes Hackaday: The famous HAARP antenna array is to be brought back into service for experiments by the University of Alaska. Built in the 1990s for the US Air Force's High Frequency Active Auroral Research Program, the array is a 40-acre site containing a phased array of 180 high-frequency antennas and their associated high-power transmitters. Its purpose is to conduct research on charged particles in the upper atmosphere, but that hasn't stopped an array of bizarre conspiracy theories.
A university space physics researcher will actually create an artificial aurora starting Sunday (and continuing through Wednesday) to study how yjr atmosphere affects satellite-to-ground communications, and "observers throughout Alaska will have an opportunity to photograph the phenomenon," according to the University. "Under the right conditions, people can also listen to HAARP radio transmissions from virtually anywhere in the world using an inexpensive shortwave radio." -
Techdirt Asks Judge To Dismiss Another Lawsuit By That Guy Who Didn't Invent Email (arstechnica.com)
Three months ago Shiva Ayyadurai won a $750,000 settlement from Gawker (after they'd already gone bankrupt). He'd argued Gawker defamed him by mocking Ayyadurai's claim he'd invented email, and now he's also suing Techdirt founder Michael Masnick -- who is not bankrupt, and is fighting back. Long-time Slashdot reader walterbyrd quotes Ars Technica: In his motion, Masnick claims that Ayyadurai "is seeking to use the muzzle of a defamation action to silence those who question his claim to historical fame." He continues, "The 14 articles and 84 allegedly defamatory statements catalogued in the complaint all say essentially the same thing: that Defendants believe that because the critical elements of electronic mail were developed long before Ayyadurai's 1978 computer program, his claim to be the 'inventor of e-mail' is false"...
The motion skims the history of e-mail and points out that the well-known fields of e-mail messages, like "to," "from," "cc," "subject," "message," and "bcc," were used in ARPANET e-mail messages for years before Ayyadurai made his "EMAIL" program. Ayyadurai focuses on statements calling him a "fake," a "liar," or a "fraud" putting forth "bogus" claims. Masnick counters that such phrases are "rhetorical hyperbole" meant to express opinions and reminds the court that "[t]he law provides no redress for harsh name-calling."
The motion calls the lawsuit "a misbegotten effort to stifle historical debate, silence criticism, and chill others from continuing to question Ayyadurai's grandiose claims." Ray Tomlinson has been dead for less than a year, but in this fascinating 1998 article recalled testing the early email protocols in 1971, remembering that "Most likely the first message was QWERTYIOP." -
Techdirt Asks Judge To Dismiss Another Lawsuit By That Guy Who Didn't Invent Email (arstechnica.com)
Three months ago Shiva Ayyadurai won a $750,000 settlement from Gawker (after they'd already gone bankrupt). He'd argued Gawker defamed him by mocking Ayyadurai's claim he'd invented email, and now he's also suing Techdirt founder Michael Masnick -- who is not bankrupt, and is fighting back. Long-time Slashdot reader walterbyrd quotes Ars Technica: In his motion, Masnick claims that Ayyadurai "is seeking to use the muzzle of a defamation action to silence those who question his claim to historical fame." He continues, "The 14 articles and 84 allegedly defamatory statements catalogued in the complaint all say essentially the same thing: that Defendants believe that because the critical elements of electronic mail were developed long before Ayyadurai's 1978 computer program, his claim to be the 'inventor of e-mail' is false"...
The motion skims the history of e-mail and points out that the well-known fields of e-mail messages, like "to," "from," "cc," "subject," "message," and "bcc," were used in ARPANET e-mail messages for years before Ayyadurai made his "EMAIL" program. Ayyadurai focuses on statements calling him a "fake," a "liar," or a "fraud" putting forth "bogus" claims. Masnick counters that such phrases are "rhetorical hyperbole" meant to express opinions and reminds the court that "[t]he law provides no redress for harsh name-calling."
The motion calls the lawsuit "a misbegotten effort to stifle historical debate, silence criticism, and chill others from continuing to question Ayyadurai's grandiose claims." Ray Tomlinson has been dead for less than a year, but in this fascinating 1998 article recalled testing the early email protocols in 1971, remembering that "Most likely the first message was QWERTYIOP."