Cloud

US Plans More Regulations to Improve Cloud Security (politico.com) 12

Politico reports: Governments and businesses have spent two decades rushing to the cloud — trusting some of their most sensitive data to tech giants that promised near-limitless storage, powerful software and the knowhow to keep it safe.

Now the White House worries that the cloud is becoming a huge security vulnerability.

So it's embarking on the nation's first comprehensive plan to regulate the security practices of cloud providers like Amazon, Microsoft, Google and Oracle, whose servers provide data storage and computing power for customers ranging from mom-and-pop businesses to the Pentagon and CIA.... Among other steps, the Biden administration recently said it will require cloud providers to verify the identity of their users to prevent foreign hackers from renting space on U.S. cloud servers (implementing an idea first introduced in a Trump administration executive order). And last week the administration warned in its national cybersecurity strategy that more cloud regulations are coming — saying it plans to identify and close regulatory gaps over the industry....

So far, cloud providers have haven't done enough to prevent criminal and nation-state hackers from abusing their services to stage attacks within the U.S., officials argued, pointing in particular to the 2020 SolarWinds espionage campaign, in which Russian spooks avoided detection in part by renting servers from Amazon and GoDaddy. For months, they used those to slip unnoticed into at least nine federal agencies and 100 companies. That risk is only growing, said Rob Knake, the deputy national cyber director for strategy and budget. Foreign hackers have become more adept at "spinning up and rapidly spinning down" new servers, he said — in effect, moving so quickly from one rented service to the next that new leads dry up for U.S. law enforcement faster than it can trace them down.

On top of that, U.S. officials express significant frustration that cloud providers often up-charge customers to add security protections — both taking advantage of the need for such measures and leaving a security hole when companies decide not to spend the extra money. That practice complicated the federal investigations into the SolarWinds attack, because the agencies that fell victim to the Russian hacking campaign had not paid extra for Microsoft's enhanced data-logging features.... Part of what makes that difficult is that neither the government nor companies using cloud providers fully know what security protections cloud providers have in place. In a study last month on the U.S. financial sector's use of cloud services, the Treasury Department found that cloud companies provided "insufficient transparency to support due diligence and monitoring" and U.S. banks could not "fully understand the risks associated with cloud services."

Data Storage

Backblaze Finds SSDs Are More Reliable Than HDDs 51

williamyf writes: The fine folks at Backblaze have published their first ever report that includes their SSD fleet. To the surprise of no one, SSDs are more more reliable (0.98% AFR) than HDDs (1.64% AFR). The surprising thing thing was how small the difference is (0.66% AFR).

A TL;DR article by well regarded storage reporter Chris Mellor is here. Also worthy of note: S.M.A.R.T. attribute usage among SSD makers is neither standardized, nor very smart:

"Klein notes that the SMART (Self-Monitoring, Analysis, and Reporting Technology) used for drive state reporting is applied inconsistently by manufacturers. "Terms like wear leveling, endurance, lifetime used, life used, LBAs [Logical Block Address] written, LBAs read, and so on are used inconsistently between manufacturers, often using different SMART attributes, and sometimes they are not recorded at all."

That means you can't use such SMART statistics to make valid comparisons between the drives. "Come on, manufacturers. Standardize your SMART numbers."
Encryption

WhatsApp Would Not Remove End-To-End Encryption For UK Law, Says Chief (theguardian.com) 47

An anonymous reader quotes a report from The Guardian: WhatsApp would refuse to comply with requirements in the online safety bill that attempted to outlaw end-to-end encryption, the chat app's boss has said, casting the future of the service in the UK in doubt. Speaking during a UK visit in which he will meet legislators to discuss the government's flagship internet regulation, Will Cathcart, Meta's head of WhatsApp, described the bill as the most concerning piece of legislation currently being discussed in the western world.

He said: "It's a remarkable thing to think about. There isn't a way to change it in just one part of the world. Some countries have chosen to block it: that's the reality of shipping a secure product. We've recently been blocked in Iran, for example. But we've never seen a liberal democracy do that. "The reality is, our users all around the world want security," said Cathcart. "Ninety-eight per cent of our users are outside the UK. They do not want us to lower the security of the product, and just as a straightforward matter, it would be an odd choice for us to choose to lower the security of the product in a way that would affect those 98% of users."

The UK government already has the power to demand the removal of encryption thanks to the 2016 investigatory powers act, but WhatsApp has never received a legal demand to do so, Cathcart said. The online safety bill is a concerning expansion of that power, because of the "grey area" in the legislation. Under the bill, the government or Ofcom could require WhatsApp to apply content moderation policies that would be impossible to comply with without removing end-to-end encryption. If the company refused to do, it could face fines of up to 4% of its parent company Meta's annual turnover -- unless it pulled out of the UK market entirely.

Security

Data Breach Hits 'Hundreds' of Lawmakers And Staff On Capitol Hill (nbcnews.com) 24

A top House official said that a "significant data breach" at the health insurance marketplace for Washington, D.C., on Tuesday potentially exposed personal identifiable information of hundreds of lawmakers and staff. NBC News reports: In a letter obtained by NBC News, Chief Administrative Officer Catherine L. Szpindor said Wednesday that the U.S. Capitol Police and the FBI had alerted her to a data breach at DC Health Link, the Affordable Care Act online marketplace that administers health care plans for members of Congress and certain Capitol Hill staff. "Currently, I do not know the size and scope of the breach, but have been informed by the Federal Bureau of Investigation (FBI) that account information and [personally identifiable information] of hundreds of Member and House staff were stolen," Szpindor said. "I expect to have access to the list of impacted enrollees later today and will notify you directly if your information was compromised." Szpindor added that it did not appear that House lawmakers were "the specific target of the attack" on DC Health Link.

Out of an "abundance of caution," Szpindor said, lawmakers may opt to freeze family credit at three major credit bureaus, Equifax, Experian and Transunion. The data breach has also affected Senate offices, according to an email sent to Senate offices Wednesday afternoon that said the Senate Sergeant at Arms was informed by law enforcement about a data breach. The notice said that the "data included the full names, date of enrollment, relationship (self, spouse, child), and email address, but no other Personally Identifiable Information (PII)."

Bug

Nvidia Driver Bug Might Make Your CPU Work Harder After You Close Your Game (arstechnica.com) 13

An anonymous reader shares a report: Nvidia released a new driver update for its GeForce graphics cards that, among other things, introduced a new Video Super Resolution upscaling technology that could make low-resolution videos look better on high-resolution screens. But the driver (version 531.18) also apparently came with a bug that caused high CPU usage on some PCs after running and then closing a game. Nvidia has released a driver hotfix (version 531.26) that acknowledges and should fix the issue, which was apparently being caused by an undisclosed bug in the "Nvidia Container," a process that exists mostly to contain other processes that come with Nvidia's drivers. It also fixes a "random bugcheck" issue that may affect some older laptops with GeForce 1000-series or MX250 and MX350 GPUs.
Security

ECB To Test Banks for Cyber Resilience (reuters.com) 3

The European Central Bank plans to test the cyber resilience of the euro zone's top banks after a sharp rise in cyberattacks, including after Russia's invasion of Ukraine, ECB supervisory chief Andrea Enria told a Lithuanian newspaper. From a report: "Next year we are launching a thematic stress test on cyber resilience, which will try to test how banks are able to respond to and recover from a successful cyberattack," Enria told Verslo zinios. The ECB has long been warning banks to be alert for cyberattacks from Russia after the European Union passed a long series of sanctions against Moscow over its invasion of Ukraine. "There has been a significant increase in cyberattacks," Enria said. "We cannot apportion this to any specific source, but it is a fact that the number of these attacks has increased since the war started." Enria said that part of the problem is that banks are outsourcing some of their critical IT infrastructure to outside providers or other entities in their group.
IT

Raspberry Pi Lets You Have Your Own Global Shutter Camera For $50 (engadget.com) 41

Global shutter sensors with no skew or distortion have been promised as the future of cameras for years now, but so far only a handful of products with that tech have made it to market. Now, Raspberry Pi is offering a 1.6-megapixel global shutter camera module to hobbyists for $50, providing a platform for machine vision, hobbyist shooting and more. From a report: The Raspberry Pi Global Shutter Camera uses a 6.3mm Sony IMX296 sensor, and requires a Raspberry Pi board with a CSI camera connector. Like other global shutter sensors, it works by pairing each pixel with an analog storage element, so that light signals can be captured and stored by all pixels simultaneously. By comparison, regular CMOS sensors read and store the light captured by pixels from top to bottom and left to right. That can cause diagonal skew on fast moving subjects, or very weird distortion on rotating objects like propellers.
Canada

Canada's Tax Revenue Agency Tries To ToS Itself Out of Hacking Liability (substack.com) 55

schwit1 shares an excerpt from a Substack article, written by former cybersecurity reporter Catalin Cimpanu: The Canada Revenue Agency (CRA), the tax department of Canada, recently updated its terms and conditions to force taxpayers to agree that CRA is not liable if their personal information is stolen while using the My Account online service portal -- which, ironically, all Canadians must use when doing their taxes and/or running their business. The CRA's terms of use assert the agency is not liable because they have "taken all reasonable steps to ensure the security of this Web site."

Excerpt from the CRA terms statement: "10. The Canada Revenue Agency has taken all reasonable steps to ensure the security of this Web site. We have used sophisticated encryption technology and incorporated other procedures to protect your personal information at all times. However, the Internet is a public network and there is the remote possibility of data security violations. In the event of such occurrences, the Canada Revenue Agency is not responsible for any damages you may experience as a result."

Unfortunately, that is not true. After reviewing the HTTP responses from the CRA My Account login page, it's clear the agency has not configured even some of the most basic security features. For example, security protections for their cookies are not configured, nor are all the recommended security headers used. Not only is that not "all reasonable steps," but the CRA is missing the very basics for securing online web applications.

The terms of use also state that users are not allowed to use "any script, robot, spider, Web crawler, screen scraper, automated query program or other automated device or any manual process to monitor or copy the content contained in any online services." Looking at the HTTP response headers using web browser developer tools doesn't breach the terms of services, but the CRA must be well aware that internet users perform scans like this all the time. And it's not the legitimate My Account users who are likely to be the culprits. Unfortunately for Canadians, threat actors don't read terms of use pages. A statement like this doesn't protect anyone, except CRA, from being held responsible for failing to properly secure Canadian citizens' personal data.

China

FBI Chief Says TikTok 'Screams' of US National Security Concerns (reuters.com) 97

China's government could use TikTok to control data on millions of American users, FBI Director Christopher Wray told a U.S. Senate hearing on Wednesday, saying the Chinese-owned video app "screams" of security concerns. Reuters reports: Wray told a Senate Intelligence Committee hearing on worldwide threats to U.S. security that the Chinese government could also use TikTok to control software on millions of devices and drive narratives to divide Americans over Taiwan or other issues. "Yes, and I would make the point on that last one, in particular, that we're not sure that we would see many of the outward signs of it happening if it was happening," Wray said of concerns China could feed misinformation to users. "This is a tool that is ultimately within the control of the Chinese government - and it, to me, it screams out with national security concerns," Wray said. Yesterday, the White House said it backed a bill in Congress to give the Biden administration new powers to ban TikTok and other foreign technologies that could pose security threats.
Security

Acer Confirms Breach After Hacker Offers To Sell Stolen Data (securityweek.com) 6

wiredmikey writes: Electronics giant Acer has confirmed getting hacked after a hacker offered to sell 160 Gb of files allegedly stolen from the company's systems. "We have recently detected an incident of unauthorized access to one of our document servers for repair technicians. While our investigation is ongoing, there is currently no indication that any consumer data was stored on that server," Acer told SecurityWeek in an emailed statement. Acer issued the statement after a hacker announced on a popular cybercrime forum that he is selling more than 2,800 files totaling 160 Gb for an unspecified amount of Monero cryptocurrency. The cybercriminal claims the files include confidential slides, staff manuals, confidential product documentation, binary files, information on backend infrastructure, disk images, replacement digital product keys, and BIOS-related information.
The Military

US Air Force Awards $75.5 Million Contract For World's Largest Wireless Ad-Hoc Network (interestingengineering.com) 19

An anonymous reader quotes a report from InterestingEngineering: The U.S. Air Force's Global Strike Command awarded a new $75.5 million contract to New York-based firm Persistent Systems. The aim is to build a unified security system for 400 operational Minuteman III intercontinental-range nuclear missile silos secured in remote areas throughout the U.S. It will be the world's largest wireless ad-hoc network, helping secure the U.S.'s nuclear arsenal amid growing concerns over global nuclear security.

Persistent Systems will roll out its Infrastructure-based Regional Operation Network (IRON) offering across three Air Force bases as part of the Regional Operating Picture (ROP) program. According to the company, the new security network will cover an area of 25,000 square miles (64,750 sq km), making it the world's largest wireless ad-hoc network. The IRON offering is an easy-to-deploy Integrated MANET Antenna System on fixed towers and poles. It will allow the U.S. Air Force to connect 75 operation centers and more than 1,000 Security Force vehicles. The ROP program will allow constant communication to an Operations Center via the towers. Meanwhile, the personnel at that Operations Center will know the exact location of any Security Forces on a digital map. Both will be able to share critical data seamlessly.

Security

European Police, FBI Bust International Cybercrime Gang (apnews.com) 12

German police said Monday they have disrupted a ransomware cybercrime gang tied to Russia that has been blackmailing large companies and institutions for years, raking in millions of euros. From a report: Working with law enforcement partners including Europol, the FBI and authorities in Ukraine, police in Duesseldorf said they were able to identify 11 individuals linked to a group that has operated in various guises since at least 2010. The gang allegedly behind the ransomware, known as DoppelPaymer, appears tied to Evil Corp, a Russia-based syndicate engaged in online bank theft well before ransomware became a global scourge. Among its most prominent victims were Britain's National Health Service and Duesseldorf University Hospital, whose computers were infected with DoppelPaymer in 2020. A woman who needed urgent treatment died after she had to be taken to another city for treatment.

Ransomware is the world's most disruptive cybercrime. Gangs mostly based in Russia break into networks and steal sensitive information before activating malware that scrambles data. The criminals demand payment in exchange for decryption keys and a promise not to dump the stolen data online. In a 2020 alert, the FBI said DoppelPaymer had been used since late 2019 to target critical industries worldwide including healthcare, emergency services and education, with six- and seven-figure ransoms routinely demanded.

Security

Unkillable UEFI Malware Bypassing Secure Boot Enabled By Unpatchable Windows Flaw (arstechnica.com) 115

Researchers have announced a major cybersecurity find -- the world's first-known instance of real-world malware that can hijack a computer's boot process even when Secure Boot and other advanced protections are enabled and running on fully updated versions of Windows. From a report: Dubbed BlackLotus, the malware is what's known as a UEFI bootkit. These sophisticated pieces of malware hijack the UEFI -- short for Unified Extensible Firmware Interface -- the low-level and complex chain of firmware responsible for booting up virtually every modern computer. As the mechanism that bridges a PC's device firmware with its operating system, the UEFI is an OS in its own right. It's located in an SPI-connected flash storage chip soldered onto the computer motherboard, making it difficult to inspect or patch. Because the UEFI is the first thing to run when a computer is turned on, it influences the OS, security apps, and all other software that follows. These traits make the UEFI the perfect place to run malware. When successful, UEFI bootkits disable OS security mechanisms and ensure that a computer remains infected with stealthy malware that runs at the kernel mode or user mode, even after the operating system is reinstalled or a hard drive is replaced.

As appealing as it is to threat actors to install nearly invisible and unremovable malware that has kernel-level access, there are a few formidable hurdles standing in their way. One is the requirement that they first hack the device and gain administrator system rights, either by exploiting one or more vulnerabilities in the OS or apps or by tricking a user into installing trojanized software. Only after this high bar is cleared can the threat actor attempt an installation of the bootkit. The second thing standing in the way of UEFI attacks is UEFI Secure Boot, an industry-wide standard that uses cryptographic signatures to ensure that each piece of software used during startup is trusted by a computer's manufacturer. Secure Boot is designed to create a chain of trust that will prevent attackers from replacing the intended bootup firmware with malicious firmware. If a single firmware link in that chain isn't recognized, Secure Boot will prevent the device from starting.

Microsoft

Microsoft Makes Outlook for Mac Free To Use (theverge.com) 47

Microsoft is making Outlook for Mac free to use today. From a report: Outlook is now available free in Apple's App Store, and you no longer need a Microsoft 365 subscription or Office license to use it. It's a surprise move that coincides with Microsoft's push to make its Windows desktop Outlook email client more web-powered. Outlook for Mac includes support for Outlook.com accounts, Gmail, iCloud, Yahoo, and any email provider that has IMAP support. Microsoft redesigned its Mac email client in 2020, with a user interface that's optimized for Apple's latest macOS design changes.
Games

Russian Game Developer Bans and Doxes 6,700 Cheaters (techcrunch.com) 91

An anonymous reader shares a report: Cheaters are an annoying part of almost every online video game. And banning them has become an important routine for game developers and publishers to keep their users happy. The publisher of Escape from Tarkov, a game developed by the Russian company Battlestate Games, has added an unusual twist to the routine: naming and shaming the cheaters. In the last week, Battlestate Games said it banned 6,700 cheaters, and it published all their nicknames on publicly available spreadsheets. "We want honest players to see the nicknames of cheaters to know that justice has been served and the cheater who killed them in a raid has been punished and banned," Battlestate Games' spokesperson Dmitri Ogorodnikov told TechCrunch.
Microsoft

Microsoft Edge is Getting a Video Upscaler To Make Blurry Old Videos Look Better (tomshardware.com) 39

Microsoft has unveiled Video Super Resolution (VSR) -- an "experimental" video upscaling feature for its Edge web browser that uses machine learning to increase the resolution of low-quality video. From a report: Announced on the Edge Insiders blog, Microsoft's VSR technology can "remove blocky compression artifacts" and improve text clarity for videos on platforms such as YouTube. The feature is still in testing and availability is currently restricted to half of the users running the Canary channel of Edge in Microsoft's Insider program. If you want to try it for yourself, there are a few stipulations: Microsoft VSR will only work on video resolutions of 720p or lower (provided both the height and width of the video exceeds 192 pixels), and the video itself can't be protected with digital rights management (DRM) technology like PlayReady or Widevine, which makes frames inaccessible to the browser for processing. That particular restriction could impact what content you can upscale with the feature, as most popular streaming platforms like Netflix, Hulu, and HBO Max all leverage DRM tech for copyright protection. Unlike Nvidia's RTX Super Resolution, Microsoft's Video Super Resolution feature supports both Nvidia and AMD GPUs.
United States

US Fed Reserve Zoom Conference Canceled After 'Porn-Bombing' (pcmag.com) 75

A Federal Reserve Zoom event with more than 220 people was canceled after a user hijacked proceedings and displayed pornographic content, Reuters reports. From a report: The hijack left Fed Governor Christopher Waller unable to deliver his opening remarks because graphic images from a call participant named "Dan" began to pop up on the screen. In a statement to Reuters, Brent Tjarks, executive director of the Mid-Size Bank Coalition of America (MBCA), which hosted the Zoom event, said: "We were a victim of a teleconference or Zoom hijacking and we are trying to understand what we need to do going forward to prevent this from ever happening again. It is an incident we deeply regret. We have had various programs and this is something that we have never had happen to us." Tjarks adds that he suspects a security switch for the Zoom event that would have muted users and prevented them from sharing their screens was incorrectly set, though he could not confirm. The MBCA, whose roughly 100 members include banks with between $10 billion and $100 billion in assets, made the decision to cancel the event minutes after it was scheduled to commence, citing "technical difficulties."
IT

Washington Post Urges Funding Office-to-Apartment Conversions as Downtown Workers Stay Home (dailyprogress.com) 172

"Cities across the nation face a dilemma," writes the Washington Post's editoral board," warning local leaders to respond to "the urgency and scale of the downtown crisis in many major metro areas..."

"Downtown office buildings are empty as workers prefer to stay home." Nearly all local leaders agree part of the solution is an office-to-apartment conversion boom. Cities have started rolling out tax incentives to encourage developers to begin this transformation. This strategy is straight out of the playbook that revived center city Philadelphia and Lower Manhattan in the past quarter century. But there's a problem: City leaders aren't doing enough...

Consider the nation's capital city. Downtown D.C. is more than 90 percent commercial buildings. The vibrancy and workers are largely gone. Crime and grime are increasing, while property tax revenue is quickly decreasing as building values plummet. Mayor Muriel E. Bowser (D) has put out an ambitious "Comeback Plan" that calls for 15,000 new residents living downtown by 2028. To make that a reality, the city needs developers to convert roughly 7 million square feet of office space to apartments and condos. Her team estimates about 1 million square feet is on track for conversion so far. There's a long way to go. The situation is similar in Chicago, San Francisco, New York and Atlanta, among other cities....

The longer cities wait to get conversions underway, the more tax values drop and crime goes up, and the more people see no value in living in the heart of the city — or even visiting. One way or another, cities are going to pay. D.C. is already staring at $464 million in lower revenue for 2024 to 2026 mainly due to lower commercial property taxes downtown. San Francisco is facing a $728 million shortfall over the next two fiscal years for similar reasons. Buildings constructed in the 1980s, 1990s and early 2000s are quickly becoming distressed. It's far better to invest now than to spend years overseeing stagnation and decline. As D.C.'s Chief Financial Officer Glen Lee warned, this is "a serious long-term risk to the District's economy and its tax base."

The sooner these buildings can convert to residential, the sooner the city can generate some tax revenue again from an area that once brought in hefty commercial property revenue. Cities will have to rely much more on residential income tax revenue from downtowns.

Security

Ask Slashdot: Can You Use an Unsafe Computer Safely? 183

"I think the answer is no, but there are some clever people around here," writes long-time Slashdot reader shanen, "so...

"Is there any firewall or router or some other device that can adequately protect an old and no longer supported computer?" I have at least two of those that come to mind, and I might use them more often if there was a safe way to connect them to the Internet.

The specifics probably matter, though that's like opening a can of worms, but... One is a little old machine running an old and no longer supported version of Linux. Another is a Windows XP box that's too customized at a low level to run Linux.

But the big concern involves a couple of old boxes that are only alive now because Windows 10 saved them from the end-of-service of Windows 7. Right now it looks like they might outlive Windows 10, too, but two of them are not suitable for Windows 11. Plus my spouse has an old Windows 8 box now running under 10...

What happens when you combine missed security updates with internet connectivity? Share your best thoughts in the comments.

Can you use an unsafe computer safely?
IT

Amazon Employees Are Fighting on Slack About Returning to the Office (entrepreneur.com) 142

An anonymous reader shares this report from Entrepreneur: Amazon employees are fighting it out about the company's planned return to the office in Slack channels, according to Insider. First, employees created a Slack channel to fight against the policy. Then, a pro-office return group was formed, the outlet reported....

Per CNBC, "remote advocacy" became a common Slack channel status. However, some people who welcomed a return to office life fought back, Insider reported. Over 700 people joined a pro-return-to-office group. Its description says employees need to "Think Big" about the return to office policy. (By comparison, the pro-working remotely channel has around 28,000 members.)

"I look forward to the prospect of seeing more of my coworkers in the office," one person reportedly wrote in the channel. Another said that the company should try out the four-day workweek and swap out the remote-flexible schedule. Another message links to a 2021 article in the Harvard Business Review called: "Why You May Actually Want to Go Back to the Office."

Slashdot Top Deals