The Almighty Buck

Netflix Fights Attempt To Make Streaming Firms Pay For ISP Network Upgrades 38

An anonymous reader quotes a report from Ars Technica: Netflix co-CEO Greg Peters spoke out against a European proposal to make streaming providers and other online firms pay for ISPs' network upgrades. "Some of our ISP partners have proposed taxing entertainment companies to subsidize their network infrastructure," Peters said in a speech Tuesday at Mobile World Congress in Barcelona (transcript). The "tax would have an adverse effect, reducing investment in content -- hurting the creative community, hurting the attractiveness of higher-priced broadband packages, and ultimately hurting consumers," he argued. [...] "ISPs claim that these taxes would only apply to Netflix. But this will inevitably change over time as broadcasters shift from linear to streaming," Peters said at MWC. Sandvine data suggests that nearly half of global Internet traffic is sent by Facebook, Amazon, Google, Apple, Netflix, and Microsoft. Online video accounts for 65 percent of all traffic, and Netflix recently passed YouTube as the top video-traffic generator.

Peters cited Nielsen data showing that "Netflix accounts for under 10 percent of total TV time" in the US and UK while "traditional local broadcasters account for over half of all TV time." Live sports account for much of that. "As broadcasters continue the shift away from linear to streaming, they will start to generate significant amounts of Internet traffic too -- even more than streamers today based on the current scope and scale of their audiences," Peters said. "Broadband customers, who drive this increased usage, already pay for the development of the network through their subscription fees. Requiring entertainment companies -- both streamers and broadcasters -- to pay more on top would mean ISPs effectively charging twice for the same infrastructure." Telcos that receive new payments wouldn't be expected to lower the prices charged to home Internet users, Peters said. "As the consumer group BEUC has pointed out, there is no suggestion these levies would be passed onto consumers in the form of 'lower prices or better infrastructure,'" he said.

Peters said Netflix's "operating margins are significantly lower than either British Telecom or Deutsche Telekom. So we could just as easily argue that network operators should compensate entertainment companies for the cost of our content -- exactly as happened under the old pay-TV model." While telcos claim companies like Netflix don't pay their "fair share," Peters pointed out that Netflix has spent a lot building its own network that reduces the amount of data sent over traditional telecom networks. "We've spent over $1 billion on Open Connect, our own content delivery network, which we offer for free to ISPs," he said. "This includes 18,000 servers with Netflix content distributed across 6,000 locations and 175 countries. So when our members press play, instead of the film or TV show being streamed from halfway around the world, it's streamed from around the corner -- increasing efficiency for operators while also ensuring a high-quality, no-lag experience for consumers." Peters also touted Netflix's encoding technology that cut bit rates in half between 2015 and 2020. While Internet traffic has increased about 30 percent a year, "ISPs have managed this increased consumer usage efficiently while their costs have remained stable," Peters said. "Regulators have highlighted this, too, calling out that infrastructure costs are not sensitive to traffic and that growing consumption will be offset by efficiency gains."
Security

Biden Administration Announces Plan To Stop Water Plant Hacks (reuters.com) 35

The Biden administration announced on Friday a new plan to improve the digital defenses of public water systems. From a report: The move comes one day after the announcement of a national cybersecurity strategy by the White House, which seeks to broadly improve industry accountability over the cybersecurity of American critical infrastructure, such as hospitals and dams. The water system plan, which recommends a series of novel rules placing more responsibility for securing water facilities at the state-level, follows several high-profile hacking incidents in recent years.

In February 2021, a cyberattack on a water treatment plant in Florida briefly increased lye levels in the water, an incident that could have been deadly if an alert worker had not detected the hack quickly. And in March 2019, a terminated employee at a Kansas-based water facility used his old computer credentials to remotely take systems offline, according to an administration official. The government is acting now because of the urgency of the threat, according to a senior U.S. Environmental Protection Agency (EPA) official. Radhika Fox, the assistant administrator in the EPA's Office of Water, said hackers had "shut down critical treatment processes" and "locked control system networks behind ransomware," underscoring the current danger. However, some experts say the new plan will not do enough to help make systems more secure.

Bug

Scientist Finds Rare Jurassic Era Bug At Arkansas Walmart, Kills It and Puts It On a Pin (cbsnews.com) 41

Longtime Slashdot reader theshowmecanuck shares a report from CBS News: A 2012 trip to a Fayetteville, Arkansas, Walmart to pick up some milk turned out to be one for the history books. A giant bug that stopped a scientist in his tracks as he walked into the store and he ended up taking home turned out to be a rare Jurassic-era flying insect. Michael Skvarla, director of Penn State University's Insect Identification Lab, found the mysterious bug -- an experience that he says he remembers "vividly."

"I was walking into Walmart to get milk and I saw this huge insect on the side of the building," he said in a press release from Penn State. "I thought it looked interesting, so I put it in my hand and did the rest of my shopping with it between my fingers. I got home, mounted it, and promptly forgot about it for almost a decade."

[I]n the fall of 2020 when he was teaching an online course on insect biodiversity and evolution, Skvarla was showing students the bug and suddenly realized it wasn't what he originally thought. He and his students then figured out what it might be -- live on a Zoom call. "We were watching what Dr. Skvarla saw under his microscope and he's talking about the features and then just kinda stops," one of his students Codey Mathis said. "We all realized together that the insect was not what it was labeled and was in fact a super-rare giant lacewing." A clear indicator of this identification was the bug's wingspan. It was about 50 millimeters -- nearly 2 inches -- a span that the team said made it clear the insect was not an antlion.
His team's molecular analysis on the bug has been published in the Proceedings of the Entomological Society of Washington.

theshowmecanuck captioned: "To be fair, he said he didn't know what it was so [he] just collected it and took it home, and then figured it out later. My thought that I added to the title was because of this quote in the story (which tickled my cynicism in humanity): "It could have been 100 years since it was even in this area -- and it's been years since it's been spotted anywhere near it..."
Software

Nearly 40% of Software Engineers Will Only Work Remotely (techtarget.com) 163

dcblogs writes: Despite the demand of employers like Apple, Amazon, Microsoft, AT&T and others, nearly 40% of software engineers preferred only remote roles, and if their employers mandated a return to the office, 21% indicated they would quit immediately, while another 49% said they would start looking for another job, according to Hired's 2023 State of Software Engineers. This report gathered its data from 68,500 software engineering candidates and a survey of more than 1,300 software engineers and 120 talent professionals. Employers open to remote workers "are able to get better-quality talent that's a better fit for the organization," said Josh Brenner, CEO of Hired, a job-matching platform for technology jobs.
Encryption

Google: Gmail Client-Side Encryption Now Publicly Available (bleepingcomputer.com) 50

Gmail client-side encryption (CSE) is now generally available for Google Workspace Enterprise Plus, Education Plus, and Education Standard customers. BleepingComputer reports: The feature was first introduced in Gmail on the web as a beta test in December 2022, after being available in Google Drive, Google Docs, Sheets, Slides, Google Meet, and Google Calendar (in beta) since last year. Once enabled, Gmail CSE ensures that any sensitive data sent as part of the email's body and attachments (including inline images) will be unreadable and encrypted before reaching Google's servers. It's also important to note that the email header (including subject, timestamps, and recipients lists) will not be encrypted. "Client-side encryption takes this encryption capability to the next level by ensuring that customers have sole control over their encryption keys -- and thus complete control over all access to their data," Googled explained.

"Starting today, users can send and receive emails or create meeting events with internal colleagues and external parties, knowing that their sensitive data (including inline images and attachments) has been encrypted before it reaches Google servers. As customers retain control over the encryption keys and the identity management service to access those keys, sensitive data is indecipherable to Google and other external entities."
Security

Dish Network Confirms Network Outage Was a Cybersecurity Breach (cnbc.com) 8

Dish Network, one of the largest television providers in the United States, confirmed on Tuesday that a previously disclosed "network outage" was the result of a cybersecurity breach that affected the company's internal communications systems and customer-facing support sites. CNBC reports: "Certain data was extracted," the company said in a statement Tuesday. The acknowledgment is an evolution from last week's earnings call, where it was described as an "internal outage." Dish Networks' website was down for multiple days beginning last week, but the company has now disclosed that "internal communications [and] customer call centers" remain affected by the breach. Dish said it had retained outside experts to assist in evaluating the problem.

The intrusion took place on the morning of Feb. 23, the same day the company reported its fourth-quarter earnings. "This morning, we experienced an internal outage that's continuing to affect our internal servers and IT telephony," Dish CEO W. Erik Carlson said at that time. "We're analyzing the root causes and any consequences of the outage, while we work to restore the affected systems as quickly as possible."
According to Bleeping Computer, the Black Basta ransomware gang is behind the attack, first breaching Boost Mobile and then the Dish corporate network.
Youtube

YouTube Video Causes Pixel Phones To Instantly Reboot (arstechnica.com) 55

An anonymous reader writes quotes a report from Ars Technica: Did you ever see that movie The Ring? People who watched a cursed, creepy video would all mysteriously die in seven days. Somehow Google seems to have re-created the tech version of that, where the creepy video is this clip of the 1979 movie Alien, and the thing that dies after watching it is a Google Pixel phone. As noted by the user 'OGPixel5" on the Google Pixel subreddit, watching this specific clip on a Google Pixel 6, 6a, or Pixel 7 will cause the phone to instantly reboot. Something about the clip is disagreeable to the phone, and it hard-crashes before it can even load a frame. Some users in the thread say cell service wouldn't work after the reboot, requiring another reboot to get it back up and running.

The leading theory floating around is that something about the format of the video (it's 4K HDR) is causing the phone to crash. It wouldn't be the first time something like this happened to an Android phone. In 2020, there was a cursed wallpaper that would crash a phone when set as the background due to a color space bug. The affected phones all use Google's Exynos-derived Tensor SoC, so don't expect non-Google phones to be affected by this. Samsung Exynos phones would be the next most-likely candidates, but we haven't seen any reports of that.
According to CNET, the issue has been addressed and a full fix will be deployed in March.
Privacy

Hackers Claim They Breached T-Mobile More Than 100 Times In 2022 (krebsonsecurity.com) 14

An anonymous reader quotes a report from KrebsOnSecurity: Three different cybercriminal groups claimed access to internal networks at communications giant T-Mobile in more than 100 separate incidents throughout 2022, new data suggests. In each case, the goal of the attackers was the same: Phish T-Mobile employees for access to internal company tools, and then convert that access into a cybercrime service that could be hired to divert any T-Mobile user's text messages and phone calls to another device. The conclusions above are based on an extensive analysis of Telegram chat logs from three distinct cybercrime groups or actors that have been identified by security researchers as particularly active in and effective at "SIM-swapping," which involves temporarily seizing control over a target's mobile phone number.

Countless websites and online services use SMS text messages for both password resets and multi-factor authentication. This means that stealing someone's phone number often can let cybercriminals hijack the target's entire digital life in short order -- including access to any financial, email and social media accounts tied to that phone number. All three SIM-swapping entities that were tracked for this story remain active in 2023, and they all conduct business in open channels on the instant messaging platform Telegram. KrebsOnSecurity is not naming those channels or groups here because they will simply migrate to more private servers if exposed publicly, and for now those servers remain a useful source of intelligence about their activities.

Each advertises their claimed access to T-Mobile systems in a similar way. At a minimum, every SIM-swapping opportunity is announced with a brief "Tmobile up!" or "Tmo up!" message to channel participants. Other information in the announcements includes the price for a single SIM-swap request, and the handle of the person who takes the payment and information about the targeted subscriber. The information required from the customer of the SIM-swapping service includes the target's phone number, and the serial number tied to the new SIM card that will be used to receive text messages and phone calls from the hijacked phone number. Initially, the goal of this project was to count how many times each entity claimed access to T-Mobile throughout 2022, by cataloging the various "Tmo up!" posts from each day and working backwards from Dec. 31, 2022. But by the time we got to claims made in the middle of May 2022, completing the rest of the year's timeline seemed unnecessary. The tally shows that in the last seven-and-a-half months of 2022, these groups collectively made SIM-swapping claims against T-Mobile on 104 separate days -- often with multiple groups claiming access on the same days.
In a written statement to KrebsOnSecurity, T-Mobile said this type of activity affects the entire wireless industry.

"And we are constantly working to fight against it," the statement reads. "We have continued to drive enhancements that further protect against unauthorized access, including enhancing multi-factor authentication controls, hardening environments, limiting access to data, apps or services, and more. We are also focused on gathering threat intelligence data, like what you have shared, to help further strengthen these ongoing efforts."
Security

US Marshals Service Suffers 'Major' Security Breach That Compromises Sensitive Information (nbcnews.com) 29

According to a spokesperson for the United States Marshals Service (USMS), the agency was hit with a ransomware attack last week that compromises sensitive information. NBC News reports: In a statement Monday, U.S. Marshals Service spokesperson Drew Wade acknowledged the breach, telling NBC News: "The affected system contains law enforcement sensitive information, including returns from legal process, administrative information, and personally identifiable information pertaining to subjects of USMS investigations, third parties, and certain USMS employees."

Wade said the incident occurred Feb. 17, when the Marshals Service "discovered a ransomware and data exfiltration event affecting a stand-alone USMS system." The system was disconnected from the network, and the Justice Department began a forensic investigation, Wade said. He added that on Wednesday, after the agency briefed senior department officials, "those officials determined that it constitutes a major incident." The investigation is ongoing, Wade said.

A senior law enforcement official familiar with the incident said the breach did not involve the database involving the Witness Security Program, commonly known as the witness protection program. The official said no one in the witness protection program is in danger because of the breach. Nevertheless, the official said, the incident is significant, affecting law enforcement sensitive information pertaining to the subjects of Marshals Service investigations. The official said the agency has been able to develop a workaround so it is able to continue operations and efforts to track down fugitives.

Security

LastPass Says Home Computer of DevOps Engineer Was Hacked (securityweek.com) 64

wiredmikey shares a report from SecurityWeek: Password management software firm LastPass says one of its DevOps engineers had a personal home computer hacked and implanted with keylogging malware as part of a sustained cyberattack that exfiltrated corporate data from the cloud storage resources. LastPass on Monday fessed up a "second attack" where an unnamed threat actor combined data stolen from an August breach with information available from a third-party data breach, and a vulnerability in a third-party media software package to launch a coordinated attack. [...]

LastPass worked with incident response experts at Mandiant to perform forensics and found that a DevOps engineer's home computer was targeted to get around security mitigations. The attackers exploited a remote code execution vulnerability in a third-party media software package and planted keylogger malware on the employee's personal computer. "The threat actor was able to capture the employee's master password as it was entered, after the employee authenticated with MFA, and gain access to the DevOps engineer's LastPass corporate vault," the company said. "The threat actor then exported the native corporate vault entries and content of shared folders, which contained encrypted secure notes with access and decryption keys needed to access the AWS S3 LastPass production backups, other cloud-based storage resources, and some related critical database backups," LastPass confirmed.
LastPass originally disclosed the breach in August 2022 and warned that "some source code and technical information were stolen."

SecurityWeek adds: "In January 2023, the company said the breach was far worse than originally reported and included the theft of account usernames, salted and hashed passwords, a portion of Multi-Factor Authentication (MFA) settings, as well as some product settings and licensing information."
Security

LinkedIn Scammers Step Up Sophistication of Online Attacks (ft.com) 22

LinkedIn has been hit by a rise in sophisticated recruitment scams, as fraudsters seek to take advantage of the trend towards remote working and widespread lay-offs across the tech sector. From a report: Jobseekers on the world's largest professional network are being defrauded out of money after taking part in fake recruitment processes set up by scammers who pose as employers, before obtaining personal and financial information. "There's certainly an increase in the sophistication of the attacks and the cleverness," Oscar Rodriguez, vice-president of product management at LinkedIn told the Financial Times "We see websites being set up, we see phone numbers with a seemingly professional operator picking up the phone and answering on the company's behalf. We see a move to more sophisticated deception," he added.

The warning comes as the Microsoft-owned social media company said it has sought to block tens of millions of fake accounts in recent months, while US regulators warn of an increase in jobs-related cons. Last month, cyber security company Zscaler revealed a scam that targeted jobseekers and a dozen US companies, where fraudsters approached people through LinkedIn's direct messaging feature InMail. Scammers identified businesses that were already hiring, including enterprise software company Zuora, software developer Intellectsoft and Zscaler itself. They then created "lookalike" websites with similar job ads and, via LinkedIn's InMail feature, invited jobseekers to enter personal information into the websites, before conducting remote interviews via Skype.

Chrome

Google Chrome's Improved Page Zoom Should Help Make the Mobile Web More Accessible (theverge.com) 19

Google Chrome's giving its page zoom feature a boost, which should make it more helpful for people who have difficulty reading the smaller screen on a phone. From a report: With the improved feature, you can increase the size of text, images, videos, and interactive controls on mobile web pages by up to 300 percent while preserving their original formatting. While the feature hasn't yet become available for all Chrome users, you can access it now if you download the Chrome beta on your phone or tablet. To enable the feature, tap the three dots icon in the top right corner of the browser, hit Settings > Accessibility, and then adjust the zoom level to your liking. Google will save this preference for all the sites you browse so you won't have to keep tweaking it, and will even bypass the ones that try to block zoom features. Previously, Google only allowed users to adjust text scaling options up to 200 percent.
Bug

Security Researchers Warn of a 'New Class' of Apple Bugs (techcrunch.com) 30

Since the earliest versions of the iPhone, "The ability to dynamically execute code was nearly completely removed," write security researchers at Trellix, "creating a powerful barrier for exploits which would need to find a way around these mitigations to run a malicious program. As macOS has continually adopted more features of iOS it has also come to enforce code signing more strictly.

"The Trellix Advanced Research Center vulnerability team has discovered a large new class of bugs that allow bypassing code signing to execute arbitrary code in the context of several platform applications, leading to escalation of privileges and sandbox escape on both macOS and iOS.... The vulnerabilities range from medium to high severity with CVSS scores between 5.1 and 7.1. These issues could be used by malicious applications and exploits to gain access to sensitive information such as a user's messages, location data, call history, and photos."

Computer Weekly explains that the vulnerability bypasses strengthened code-signing mitigations put in place by Apple on its developer tool NSPredicate after the infamous ForcedEntry exploit used by Israeli spyware manufacturer NSO Group: So far, the team has found multiple vulnerabilities within the new class of bugs, the first and most significant of which exists in a process designed to catalogue data about behaviour on Apple devices. If an attacker has achieved code execution capability in a process with the right entitlements, they could then use NSPredicate to execute code with the process's full privilege, gaining access to the victim's data.

Emmitt and his team also found other issues that could enable attackers with appropriate privileges to install arbitrary applications on a victim's device, access and read sensitive information, and even wipe a victim's device. Ultimately, all of the new bugs carry a similar level of impact to ForcedEntry.

Senior vulnerability researcher Austin Emmitt said the vulnerabilities constituted a "significant breach" of the macOS and iOS security models, which rely on individual applications having fine-grain access to the subset of resources needed, and querying services with more privileges to get anything else.

"The key thing here is the vulnerabilities break Apple's security model at a fundamental level," Trellix's director of vulnerability research told Wired — though there's some additional context: Apple has fixed the bugs the company found, and there is no evidence they were exploited.... Crucially, any attacker trying to exploit these bugs would require an initial foothold into someone's device. They would need to have found a way in before being able to abuse the NSPredicate system. (The existence of a vulnerability doesn't mean that it has been exploited.)

Apple patched the NSPredicate vulnerabilities Trellix found in its macOS 13.2 and iOS 16.3 software updates, which were released in January. Apple has also issued CVEs for the vulnerabilities that were discovered: CVE-2023-23530 and CVE-2023-23531. Since Apple addressed these vulnerabilities, it has also released newer versions of macOS and iOS. These included security fixes for a bug that was being exploited on people's devices.

TechCrunch explores its severity: While Trellix has seen no evidence to suggest that these vulnerabilities have been actively exploited, the cybersecurity company tells TechCrunch that its research shows that iOS and macOS are "not inherently more secure" than other operating systems....

Will Strafach, a security researcher and founder of the Guardian firewall app, described the vulnerabilities as "pretty clever," but warned that there is little the average user can do about these threats, "besides staying vigilant about installing security updates." And iOS and macOS security researcher Wojciech ReguÅa told TechCrunch that while the vulnerabilities could be significant, in the absence of exploits, more details are needed to determine how big this attack surface is.

Jamf's Michael Covington said that Apple's code-signing measures were "never intended to be a silver bullet or a lone solution" for protecting device data. "The vulnerabilities, though noteworthy, show how layered defenses are so critical to maintaining good security posture," Covington said.

AI

Survey Claims Some Companies are Already Replacing Workers With ChatGPT (yahoo.com) 142

An anonymous reader quotes an article from Fortune: Earlier this month, job advice platform Resumebuilder.com surveyed 1,000 business leaders who either use or plan to use ChatGPT. It found that nearly half of their companies have implemented the chatbot. And roughly half of this cohort say ChatGPT has already replaced workers at their companies....

Business leaders already using ChatGPT told ResumeBuilders.com their companies already use ChatGPT for a variety of reasons, including 66% for writing code, 58% for copywriting and content creation, 57% for customer support, and 52% for meeting summaries and other documents. In the hiring process, 77% of companies using ChatGPT say they use it to help write job descriptions, 66% to draft interview requisitions, and 65% to respond to applications.

Overall, most business leaders are impressed by ChatGPT's work," ResumeBuilder.com wrote in a news release. "Fifty-five percent say the quality of work produced by ChatGPT is 'excellent,' while 34% say it's 'very good....'" Nearly all of the companies using ChatGPT said they've saved money using the tool, with 48% saying they've saved more than $50,000 and 11% saying they've saved more than $100,000....

Of the companies ResumeBuilder.com identified as businesses using the chatbot, 93% say they plan to expand their use of ChatGPT, and 90% of executives say ChatGPT experience is beneficial for job seekers — if it hasn't already replaced their jobs.

Programming

Ask Slashdot: What's the Best Podcast About Computer Science? 37

Long-time Slashdot reader destinyland writes: They say "always be learning" — but do podcasts actually help? I've been trying to find podcasts that discuss programming, and I've enjoyed Lex Fridman's interviews with language creators like Guido van Rossum, Chris Lattner, and Brendan Eich (plus his long interviews with Donald Knuth). Then I discovered that GitHub, Red Hat, Stack Overflow, and the Linux Foundation all have their own podcast.

There's a developer podcast called "Corecursive" that I like with the tagline "the stories behind the code," plus a whole slew of (sometimes language-specific) podcasts at Changelog (including an interview with Brian Kernighan). And it seems like there's an entirely different universe of content on YouTube — like the retired Microsoft engineer doing "Dave's Garage," Software Engineering Daily, and the various documentaries by Honeypot.io. Computerphile has also scored various interviews with Brian Kernighan, and if you search YouTube enough you'll find stray interviews with Steve Wozniak.

But I wanted to ask Slashdot's readers: Do you listen to podcasts about computer science? And if so, which ones? (Because I'm always stumbling across new programming podcasts, which makes me worry about what else I've been missing out on.) Maybe I should also ask if you ever watch coding livestreams on Twitch — although that gets into the more general question of just how much content we consume that's related to our profession.

Fascinating discussions, or continuing work-related education? (And do podcasts really help keep your skills fresh? Are coding livestreams on Twitch just a waste of time?) Most importantly, does anyone have a favorite geek podcast that they're listening to? Share your own experience and opinions in the comments...

What's the best podcast about computer science?
IT

10,000 Dogs are Registered for Workplace Visits at Amazon (aboutamazon.com) 64

Long-time Slashdot reader theodp writes: In what might be mistaken for an early April Fools' joke, one month after Amazon confirmed it would layoff 18,000+ employees, Amazon News last week put out a whimsical story about 10,000+ of its employees' dogs who are registered to "work" at corporate offices as part of Amazon's Dogs at Work program. "This unique program," Amazon explains," pulls out all the stops to make sure dogs have everything they need for a successful work day, including decked out dog parks, unlimited treats from the reception desk, and regular events where dogs and their owners can get to know their colleagues."

Amazon employees also received a back-to-the office edict last week from CEO Andy Jassy, who cited the need for "serendipitous interactions" between team members, which Amazon has at times suggested would be facilitated if its employees' dogs return to the workplace, too. "The dog-friendly policy also contributes to the company's culture of collaboration," Amazon reported last year. "Dogs in the workplace are an unexpected mechanism for connection, an Amazon manager added. "I see employees meeting each other in our lobbies or elevators every day because of their dogs."

Amazon News offers profiles of "11 Amazing Pups" who didn't need obedience school to be convinced to return to the office, including Murray and Ripley. "Working from home certainly has its perks," Amazon reports, "but Murray LOVES coming into the office. He gets to see his favorite colleagues-both human and canine-and brighten everyone's day." And "Ripley starts each workday with a greeting from her best friend Lisa at the Culver Studios gate. From there, she promptly reports for duty, doling out kisses to anyone who needs a little pick-me-up."

Iphone

Thieves Spy on iPhone Owners' Passcodes, Then Steal Their Phones and Money (9to5mac.com) 84

After an iPhone was stolen, $10,000 vanished from the owner's bank account — and they were locked out of their Apple account's photos, contacts and notes. The thieves "stole thousands of dollars through Apple Pay" and "opened an Apple Card to make fraudulent charges," writes 9 to 5 Mac, citing a report from the Wall Street Journal. These thieves often work in groups with one distracting a victim while another records over a shoulder as they enter their passcode. Others have been known to even befriend victims, asking them to open social media or other apps on their iPhones so they can watch and memorize the passcode before stealing it. A 12-person crime ring in Minnesota was recently taken down after targeting iPhones like this in bars. Almost $300,000 was stolen from 40 victims by this group before they were caught.
The Journal adds that "similar stories are piling up in police stations around the country," while one of their article's authors has tweeted Apple's official response. "We sympathize with users who have had this experience and we take all attacks on our users very seriously, no matter how rare.... We will continue to advance the protections to help keep user accounts secure."

The reporter suggests alphanumeric passwords are harder to steal, while MacRumors offers some other simple fixes. "Use Face ID or Touch ID as much as possible when in public to prevent thieves from spying... In situations where entering the passcode is necessary, users can hold their hands over their screen to hide passcode entry."
Google

To Cut Costs Google Asks Some Employees to Share a Desk, Work Alternate Days (cnbc.com) 109

More than a quarter of Google's full-time workforce is in its cloud unit, reports CNBC. And now Google is asking cloud employees and partners "to share their desks and alternate days with their desk mates starting next quarter, citing 'real estate efficiency.'" The new desk-sharing model will apply to Google Cloud's five largest U.S. locations — Kirkland, Washington; New York City; San Francisco; Seattle; and Sunnyvale, California — and is happening so the company "can continue to invest in Cloud's growth," according to an internal FAQ recently shared with cloud employees and viewed by CNBC. Some buildings will be vacated as a result, the document noted.

"Most Googlers will now share a desk with one other Googler," the internal document stated, noting they expect employees to come in on alternate days so they're not at the same desk on the same day. "Through the matching process, they will agree on a basic desk setup and establish norms with their desk partner and teams to ensure a positive experience in the new shared environment." The FAQ says employees may come in on other days, but if they're in on an unassigned day, they will use "overflow drop-in space."

Internally, leadership has given the new seating arrangement a title: "Cloud Office Evolution" or "CLOE," which it describes as "combining the best of pre-pandemic collaboration with the flexibility" of hybrid work. The new workspace plan is not a temporary pilot, the document noted. "This will ultimately lead to more efficient use of our space," it said.

A Google spokesperson said they'd conducted pilot programs and surveys "to explore different hybrid work models," CNBC reports, with the results showing employees "value guaranteed in-person collaboration when they are in the office, as well as the option to work from home a few days each week." So they've devised their new system to combine "the best of pre-pandemic collaboration with the flexibility and focus we've all come to appreciate from remote work, while also allowing us to use our spaces more efficiently."

The article points out that Google Cloud is currently not profitable, and "is still losing hundreds of millions of dollars every quarter — $480 million in the fourth quarter, although that was nearly half of the loss a year prior."

An internal FAQ warns that affected employees are now expected to have "conversations about how they will or will not decorate the space, store personal items, and tidiness expectations."

Thanks to Slashdot reader RUs1729 for sharing the story.
Open Source

At Least One Open Source Vulnerability Found In 84% of Code Bases, Report Finds (csoonline.com) 33

L.Kynes shares a report from CSO Online: At a time when almost all software contains open source code, at least one known open source vulnerability was detected in 84% of all commercial and proprietary code bases examined by researchers at application security company Synopsys. In addition, 48% of all code bases analyzed by Synopsys researchers contained high-risk vulnerabilities, which are those that have been actively exploited, already have documented proof-of-concept exploits, or are classified as remote code execution vulnerabilities. The vulnerability data -- along with information on open source license compliance -- was included in Synopsys' 2023 Open Source Security and Risk Analysis (OSSRA) report (PDF), put together by the company's Cybersecurity Research Center (CyRC). "Of the 1,703 codebases that Synopsys audited in 2022, 96% of them contained open source," adds L.Kynes, citing the report. "Aerospace, aviation, automotive, transportation, logistics; EdTech; and Internet of Things are three of the 17 industry sectors included in the report that had open source in 100% of their audited codebases. In the remaining verticals, over 92% of the codebases contained open source."
Security

TELUS Investigating Leak of Stolen Source Code, Employee Data (bleepingcomputer.com) 7

Canada's second-largest telecom, TELUS is investigating a potential data breach after a threat actor shared samples online of what appears to be employee data. BleepingComputer reports: The threat actor subsequently posted screenshots that apparently show private source code repositories and payroll records held by the company. TELUS has so far not found evidence of corporate or retail customer data being stolen and continues to monitor the potential incident. On February 17, a threat actor put up what they claim to be TELUS' employee list (comprising names and email addresses) for sale on a data breach forum. "TELUS employes [sic] from a very recent breach. We have over 76K unique emails and on top of this, we have internal information associated with each employee scraped from Telus' API," states the forum post.

While BleepingComputer has been unable to confirm the veracity of threat actor's claims just yet, the small sample set posted by the seller does have valid names and email addresses corresponding to present-day TELUS employees, particularly software developers and technical staff. By Tuesday, February 21, the same threat actor had created another forum post -- this time offering to sell TELUS' private GitHub repositories, source code, as well as the company's payroll records. The seller further boasts that the stolen source code contains the company's "sim-swap-api" that will purportedly enable adversaries to carry out SIM swap attacks.

Slashdot Top Deals