IOS

iOS 15 Messages Bug Causes Saved Photos to Be Deleted (macrumors.com) 37

A serious bug in the iOS 15 Messages app can cause some saved photos to be deleted, according to multiple complaints reported by MacRumors readers and Twitter users. From the report: If you save a photo from a Messages thread and then go on to delete that thread, the next time an iCloud Backup is performed, the photo will disappear. Even though the image is saved to your personal iCloud Photo Library, it appears to still be linked to the Messages app in "iOS 15," and saving it does not persist through the deletion of the thread and an "iCloud" backup. This is a concern because most users keep the "iCloud" Backup feature enabled and it's something that happens automatically. If you're someone who regularly deletes message threads, if there's a photo that you want to keep, you won't be able to keep it with "iCloud" Backup turned on.

To replicate this bug, the following steps must be taken:
1. Save a photo from a Messages conversation to your Camera Roll.
2. Check to see that the photo has been saved.
3. Delete the Messages conversation the photo came from. The photo will still be in your "iCloud Photo Library" at this point.
4. Perform an "iCloud" Backup, and the photo disappears.

Android

New GriftHorse Malware Infects More Than 10 Million Android Phones (therecord.media) 30

Security researchers have found a massive malware operation that has infected more than 10 million Android smartphones across more than 70 countries since at least November 2020 and is making millions of dollars for its operators on a monthly basis. The Record reports: Discovered by mobile security firm Zimperium, the new GriftHorse malware has been distributed via benign-looking apps uploaded on the official Google Play Store and on third-party Android app stores. If users install any of these malicious apps, GriftHorse starts peppering users with popups and notifications that offer various prizes and special offers. Users who tap on these notifications are redirected to an online page where they are asked to confirm their phone number in order to access the offer. But, in reality, users are subscribing themselves to premium SMS services that charge over $35 per month, money that are later redirected into the GriftHorse operators' pockets.

Zimperium researchers Aazim Yaswant & Nipun Gupta, who have been tracking the GriftHorse malware for months, described it as "one of the most widespread campaigns the zLabs threat research team has witnessed in 2021." Based on what they've seen until now, the researchers estimated that the GriftHorse gang is currently making between $1.5 million to $4 million per month from their scheme.

Security

Apple AirTag Bug Enables 'Good Samaritan' Attack (krebsonsecurity.com) 29

An anonymous reader quotes a report from Krebs On Security: The new $30 AirTag tracking device from Apple has a feature that allows anyone who finds one of these tiny location beacons to scan it with a mobile phone and discover its owner's phone number if the AirTag has been set to lost mode. But according to new research, this same feature can be abused to redirect the Good Samaritan to an iCloud phishing page -- or to any other malicious website. The AirTag's "Lost Mode" lets users alert Apple when an AirTag is missing. Setting it to Lost Mode generates a unique URL at https://found.apple.com/ and allows the user to enter a personal message and contact phone number. Anyone who finds the AirTag and scans it with an Apple or Android phone will immediately see that unique Apple URL with the owner's message.

When scanned, an AirTag in Lost Mode will present a short message asking the finder to call the owner at at their specified phone number. This information pops up without asking the finder to log in or provide any personal information. But your average Good Samaritan might not know this. That's important because Apple's Lost Mode doesn't currently stop users from injecting arbitrary computer code into its phone number field -- such as code that causes the Good Samaritan's device to visit a phony Apple iCloud login page. The vulnerability was discovered and reported to Apple by Bobby Rauch, a security consultant and penetration tester based in Boston. Rauch told KrebsOnSecurity the AirTag weakness makes the devices cheap and possibly very effective physical trojan horses.

China

German IT Security Watchdog Examines Xiaomi Mobile Phone (reuters.com) 16

Germany's federal cybersecurity watchdog, the BSI, is conducting a technical examination of a mobile phone manufactured by China's Xiaomi, a spokesperson for the interior ministry told Reuters on Wednesday. From the report: The spokesperson did not provide further details on what kind of examination the agency was carrying out. Lithanua's state cybersecurity body said last week that Xiaomi phones had a built-in ability to detect and censor terms such as "Free Tibet," "Long live Taiwan independence" or "democracy movement." Xiaomi said on Monday it was engaging a third-party expert to assess the allegations by Lithuania that its smartphones carry built-in censorship capabilities.
Security

Russian Authorities Arrest Cybersecurity Giant Group-IB's CEO on Treason Charges (techcrunch.com) 30

Russian authorities have arrested and detained Ilya Sachkov, the co-founder and chief executive of Group-IB -- one of the biggest cybersecurity companies in the country -- on charges of treason. From a report: Details about Sachkov's detention remain unclear but it was reported by Russian media as authorities searched the company's offices, reports Reuters. State news agency Tass said Sachkov, who was arrested on Tuesday, was charged with allegedly transferring classified information to an unnamed foreign government, claims that Sachkov denied, according to the report. Group-IB confirmed the arrest of its CEO, but a spokesperson for Group-IB did not comment beyond a statement on the company's website, which said the company is examining the Moscow court's decision and that it is "confident" in Sachkov's innocence. Sachkov, 35, founded Group-IB in 2003. The company, now headquartered in Singapore, helps companies and governments investigate cyberattacks and online fraud, and has customers ranging from Interpol to Russian banks and defense companies.
Windows

Microsoft Knew of Exchange Autodiscover Flaw Five Years Ago (theregister.com) 22

Thomas Claburn writes via The Register: Microsoft Exchange clients like Outlook have been supplying unprotected user credentials if you ask in a particular way since at least 2016. Though aware of this, Microsoft's advice continues to be that customers should communicate only with servers they trust. On August 10, 2016, Marco van Beek, managing director at UK-based IT consultancy Supporting Role, emailed the Microsoft Security Response Center to disclose an Autodiscover exploit that worked with multiple email clients, including Microsoft Outlook. "Basically, I have discovered that it is extremely easy to get access to Exchange (and therefore Active Directory) user passwords in plain text," he wrote. "It doesn't necessarily require any breach of corporate security, and at its most secure, is only as secure as file level access to the corporate website." His proof-of-concept exploit code, which affected Outlook (both Mac and PC), default email apps for Android and iOS, Apple Mail for Mac OS X, and others, consisted of 11 lines of PHP, though he insisted the exploit probably could have been reduced to three lines.

Microsoft acknowledged on August 11, 2016, that it had reproduced the issue in van Beek's report. Then on August 30, 2016, the Windows titan responded to van Beek by saying the report doesn't describe a genuine vulnerability: "Our security engineers and product team have reviewed this report and determined that it is not a security issue to be serviced as part of our monthly Patch Tuesday process. 'Never accept an SSL certificate without a matching host name' is already recommended for clients in the doc cited by your report: [link]. Before you send a request to a candidate, make sure it is trustworthy. Remember that you're sending the user's credentials, so it's important to make sure that you're only sharing them with a server you can trust. At a minimum, you should verify: That the endpoint is an HTTPS endpoint. Client applications should not authenticate or send data to a non-SSL endpoint. That the SSL certificate presented by the server is valid and from a trusted authority."

"This response casually forgets to consider that a hacked web server still retains a perfectly valid certificate -- it just happens to use that trusted tunnel to serve up problems," said van Beek. "Also, I have only found one Exchange client so far which actually checks the hostname against the certificate, which is Microsoft's own test tool." Van Beek said he thought it was incredible that Microsoft confirmed the behavior he reported within hours but does not consider it to be a problem. He suggested three mitigations: changing the order of operations so that DNS gets checked first; never accepting an SSL certificate without a matching host name; and reviewing why and when clients respond to authentication requests.
When asked if the company plans to take any steps to address credential exposure and whether it believes its guidance adequately addresses the problem, a Microsoft spokesperson said: "We are continuing to investigate the specific scenario shared by the researcher."
Security

NSA, CISA Publish Guide for Securing VPN Servers (therecord.media) 31

The National Security Agency (NSA) and the Cybersecurity and Infrastructure Security Agency (CISA) have published today technical guidance on properly securing VPN servers used by organizations to allow employees remote access to internal networks. From a report: The NSA said it put together the nine-page guide [PDF] after "multiple nation-state advanced persistent threat (APT) actors" weaponized vulnerabilities in common VPN servers as a way to breach organizations. "Exploitation of these CVEs [vulnerabilities] can enable a malicious actor to steal credentials, remotely execute code, weaken encrypted traffic's cryptography, hijack encrypted traffic sessions, and read sensitive data from the device," the NSA said today in a press release announcing the guide's publication. "If successful, these effects usually lead to further malicious access and could result in a large-scale compromise to the corporate network," the agency added.
IT

1Password Adds Its Own 'Hide My Email' Feature (theverge.com) 36

1Password is launching a new feature to let users create unique email aliases for logins, much like Apple's iCloud Plus Hide My Email function. From a report: 1Password is partnering with Fastmail to bring its masked email feature to the password manager, giving all users the option of hiding their email addresses from apps and services. "Your email address is your online identity," explains Bron Gondwana, CEO of Fastmail. "If your credentials are compromised in a data breach, having a randomly generated email address adds a second line of defense because it can't be associated with your primary email address, and therefore, your identity." This new masked email feature will be ideal for registering accounts for temporary purposes, like a free Wi-Fi network. But they can also be used to hide your personal email address from any app or service as the aliases don't expire unless a 1Password user manually deletes them.
Businesses

Cloudflare Is Taking a Shot at Email Security (wired.com) 46

Cloudflare, the internet infrastructure company, already has its fingers in a lot of customer security pots, from DDoS protection to browser isolation to a mobile VPN. Now the company is taking on a classic web foe: email. From a report: On Monday, Cloudflare is announcing a pair of email safety and security offerings that it views as a first step toward catching more targeted phishing attacks, reducing the effectiveness of address spoofing, and mitigating the fallout if a user does click a malicious link. The features, which the company will offer for free, are mainly geared toward small business and corporate customers. And they're made for use on top of any email hosting a customer already has, whether it's provided by Google's Gmail, Microsoft 365, Yahoo, or even relics like AOL. Cloudflare CEO Matthew Prince says that from its founding in 2009, the company very intentionally avoided going anywhere near the thorny problem of email. But he adds that email security issues are unrelenting, so it has become necessary.

"I think what I had assumed is that hosting providers like Google and Microsoft and Yahoo were going to solve this issue, so we weren't sure there was anything for us to do in the space," Prince says. "But what's become clear over the course of the last two years is that email security is still not a solved issue." Prince says that Cloudflare employees have been "astonished by how many targeted threats were getting through Google Workspace," the company's email provider. That's not for lack of progress by Google or the other big providers on anti-spam and anti-malware efforts, he adds. But with so many types of email threats to deal with at once, strategically crafted phishing messages still slip through. So Cloudflare decided to build additional defense tools that both the company itself as well as its customers could use.

Encryption

With HTTPS Everywhere, EFF Begins Plans to Eventually Deprecate 'HTTPS Everywhere' Extension (therecord.media) 48

The Record reports: The Electronic Frontier Foundation said it is preparing to retire the famous HTTPS Everywhere browser extension after HTTPS adoption has picked up and after several web browsers have introduced HTTPS-only modes." "After the end of this year, the extension will be in 'maintenance mode' for 2022," said Alexis Hancock, Director of Engineering at the EFF. Maintenance mode means the extension will receive minor bug fixes next year but no new features or further development.

No official end-of-life date has been decided, a date after which no updates will be provided for the extension whatsoever.

Launched in June 2010, the HTTPS Everywhere browser extension is one of the most successful browser extensions ever released. The extension worked by automatically switching web connections from HTTP to HTTPS if websites had an HTTPS option available. At the time it was released, it helped upgrade site connections to HTTPS when users clicked on HTTP links or typed domains in their browser without specifying the "https://" prefix. The extension reached cult status among privacy advocates and was integrated into the Tor Browser and, after that, in many other privacy-conscious browsers. But since 2010, HTTPS is not a fringe technology anymore. Currently, around 86.6% of all internet sites support HTTPS connections. Browser makers such as Chrome and Mozilla previously reported that HTTPS traffic usually accounts for 90% to 95% of their daily connections.

From EFF's announcement: The goal of HTTPS Everywhere was always to become redundant. That would mean we'd achieved our larger goal: a world where HTTPS is so broadly available and accessible that users no longer need an extra browser extension to get it. Now that world is closer than ever, with mainstream browsers offering native support for an HTTPS-only mode.

With these simple settings available, EFF is preparing to deprecate the HTTPS Everywhere web extension as we look to new frontiers of secure protocols like SSL/TLS... We know many different kinds of users have this tool installed, and want to give our partners and users the needed time to transition.

The announcement also promises to inform users of browser-native HTTPS-only options before the day when the extension reaches its final sunsetting — and ends with instructions for how to activate the native HTTPS-only features in Firefox, Chrome, Edge, and Safari, "and celebrate with us that HTTPS is truly everywhere for users."
The Internet

VoIP.ms Battles Week-Long Sustained DDoS-for-Ransom Attack (bleepingcomputer.com) 37

Slashdot reader Striek writes: VoIP.ms, a Canadian VoIP provider [also serving the US], has been under a sustained, and presumably massive DDoS attack which started on the September 16th, 2021. The attack has been disruptive enough to be covered by major media outlets, including Hacker News, ZDNet, Ars Technica, BleepingComputer, CTV News, and The Toronto Star.

They have so far refused to pay a ransom demand, which has grown from 1 bitcoin at the outset ($45,000 USD at that time), to 100 bitcoin now, or $45 million. Similar attacks have occurred recently on several UK based VOiP providers.

With DDoS attacks against VOiP infrastructure difficult to defend against — or at least more difficult than your bog-standard denial of service, this may be setting a worrying trend.

Bleeping Computer reported Monday that the attack was "severely disrupting the company's operation: As customers configured their VoIP equipment to connect to the company's domain name, the DDoS attack disrupted telephony services, preventing them from receiving or making phone calls. As DNS was no longer working, the company advised customers to modify their HOSTS file to point the domain at their IP address to bypass DNS resolution. However, this just led the threat actors to perform DDoS attacks directly at that IP address as well.

To mitigate the attacks, VoIP.ms moved their website and DNS servers to Cloudflare, and while they reported some success, the company's site and VoIP infrastructure still have issues due to the continued denial-of-service attack.

ZDNet has been following the story: In an update on Wednesday, VoIP.ms apologized to customers and confirmed it was still being targeted by what it described as a 'ransom DDoS attack' . VoIP.ms says it has over 80,000 customers in 125 countries.
And in addition, this afternoon the company's Twitter account announced that "Our main U.S. upstream carrier is currently experiencing major issues on their network affecting inbound and outbound calls and messaging to US numbers. We have already been in contact with their senior leadership team and they are on it along with their whole NOC."
Microsoft

Microsoft Rushes To Register Autodiscover Domains Leaking Credentials (bleepingcomputer.com) 20

Microsoft is rushing to register Internet domains used to steal Windows credentials sent from faulty implementations of the Microsoft Exchange Autodiscover protocol. BleepingComputer reports: On Monday, Guardicore's Amit Serper released new research about how the issue caused the exposure of close to 100,000 unique Windows and email credentials. When users configure their Exchange accounts on email clients, the app will attempt to authenticate to various Autodiscover URLs associated with Microsoft Exchange servers for their organization. If a successful authentication occurs, the Exchange server will send back settings that the mail client should use. However, many mail clients, including some versions of Microsoft Outlook and Office 365, incorrectly implement the Autodiscover protocol causing them to try and authenticate to third-party autodiscover.[tld] URLs that are not related to a user's organization. Examples of such domains include autodiscover.com, autodiscover.uk, and autodiscover.de. Threat actors could register autodiscover.[tld] domains and begin collecting the leaked Windows and email credentials for attacks against the organization. In response to Serper's report, Microsoft issued the following statement: "We are actively investigating and will take appropriate steps to protect customers. We are committed to coordinated vulnerability disclosure, an industry standard, collaborative approach that reduces unnecessary risk for customers before issues are made public. Unfortunately, this issue was not reported to us before the researcher marketing team presented it to the media, so we learned of the claims today."

"Since then, Microsoft has been rushing to register any autodiscover.[tld] domains it can find to prevent them from being used to steal Windows credentials," adds BleepingComputer. "At the time of this writing, [...] Microsoft registered at least 68 domains related to Autodiscover."
Security

ExpressVPN Employees Complain About Ex-Spy's Top Role At Company (reuters.com) 28

An anonymous reader quotes a report from Reuters: When a senior executive at virtual private network company ExpressVPN admitted to working on behalf of a foreign intelligence service to hack American machines last week, it stunned employees at his new company, according to interviews and electronic records. What ExpressVPN said after the U.S. Justice Department's deferred prosecution agreement disturbed some employees further. The company had known about Dan Gericke's history as a mercenary hacker for the United Arab Emirates. The VPN provider said it had no problem with the former intelligence operative protecting the privacy of its customers. In fact, the company had repeatedly given Gericke more responsibility at ExpressVPN even as the FBI investigation of his conduct pressed toward its conclusion.

Gericke was named chief technology officer in August, according to an internal email at the time, and remains in the post. Shortly after the court filings showed Gericke and two other former U.S. intelligence operators agreeing to pay a fine and give up any future classified work, he emailed his colleagues at ExpressVPN. "I can imagine that this kind of news is surprising or even uncomfortable," Gericke wrote in the message obtained by Reuters, then assured them that he had used his skills to protect consumers from threats to their security and privacy.

When senior company executives during a regular online question-and-answer session last Friday with employees accepted queries about Gericke's deal and then discussed the sale announced days earlier of the company to British-Israeli digital security software provider Kape Technologies PLC, the workforce vented its anger. One employee wrote anonymously on an internal chat board: "This episode has eroded consumer's trust in our brand, regardless of the facts. How do we intend to rebuild our reputation?" Asked about the controversy, ExpressVPN said in a statement that the exchange was part of a regular monthly session between management and employees. "As a company, we value openness, dialogue and transparency -which includes robust debate and incisive questioning," the company said. It said it had not known of the federal investigation or the details of Gericke's work in UAE, and it said that country's surveillance campaign was "completely antithetical to our mission."

At ExpressVPN's session with leaders Friday, the second-most supported question also concerned him. "As an individual I have a problem accepting that Dan was hired despite disclosing past actions. These actions are not small thing we can easily forget or accept. Don't they go against all the things XV stands for?" that person asked. To Reuters, the company responded: "It's only through clear commitment and contributions to our mission that Daniel has been able to earn senior leadership roles within the company and the full confidence of our co-founders."

IT

UK Airports Briefly Snarled By Border Force Software Outage (bloomberg.com) 6

A software outage temporarily affected the U.K. Border Force's automated entry gates, slowing arrivals at airports across the country. From a report: Hubs in London Heathrow and Manchester reported issues before the Home Office said the problem was resolved. "We're aware of a systems failure impacting the e-gates, which are staffed & operated by Border Force," Heathrow said in a tweet. "This issue is impacting a number of ports of entry." Travelers reported long lines at Heathrow, with documentary filmmaker Louis Theroux describing a "human logjam" at the nation's largest airport.
IOS

Researcher Dumps Three iOS Zero-days After Apple Failed To Fix Issues for Months (therecord.media) 64

A security researcher has published details about three iOS zero-day vulnerabilities, claiming that Apple has failed to patch the issues, which they first reported to the company earlier this year. From a report: Going by the pseudonym of Illusion of Chaos, the researcher has published their findings on Russian blogging platform Habr and has released proof-of-concept code for each vulnerability on GitHub. This includes:

1. A vulnerability in the Gamed daemon that can grant access to user data such as AppleID emails, names, auth token, and grant file system access.

2. A vulnerability in the nehelper daemon that can be used from within an app to learn what other apps are installed on a device.

3. An additional vulnerability in the nehelper daemon can also be used from within an app to gain access to a device's WiFi information.

Security

Hackers Breached Computer Network At Key US Port But Did Not Disrupt Operations (cnn.com) 17

Suspected foreign government-backed hackers last month breached a computer network at one of the largest ports on the US Gulf Coast, but early detection of the incident meant the intruders weren't in a position to disrupt shipping operations, according to a Coast Guard analysis of the incident obtained by CNN and a public statement from a senior US cybersecurity official. CNN reports: The incident at the Port of Houston is an example of the interest that foreign spies have in surveilling key US maritime ports, and it comes as US officials are trying to fortify critical infrastructure from such intrusions. "If the compromise had not been detected, the attacker would have had unrestricted remote access to the [IT] network" by using stolen log-in credentials, reads the US Coast Guard Cyber Command's analysis of the report, which is unclassified and marked "For Official Use Only." "With this unrestricted access, the attacker would have had numerous options to deliver further effects that could impact port operations." The Port of Houston is a 25-mile-long complex through which 247 million tons of cargo move each year, according to its website.

In the case of the Port of Houston, the unidentified hackers broke into a web server somewhere at the complex using a previously unidentified vulnerability in password management software at 2:38 p.m. UTC on August 19, according to the Coast Guard report. The intruders then planted malicious code on the server, which allowed further access to the IT system. Beginning about 90 minutes after the initial breach, the hackers stole all of the log-in credentials for a type of Microsoft software that organizations use to manage passwords and access to their networks, according to the report. Minutes later, cybersecurity staff at the port isolated the hacked server, "cutting off unauthorized access to the network," the advisory said.

It's unclear who was behind the breach, which appears to be part of a broader espionage campaign. When asked about the incident at a Senate hearing on Thursday, US Cybersecurity and Infrastructure Security Agency Director Jen Easterly said she believed a foreign government-backed hacking group was responsible. Attribution of cyberattacks "can always be complicated," Easterly told the Senate Homeland Security and Governmental Affairs Committee. "At this point in time, I would have to get back with my colleagues, but I do think it is a nation-state actor."

Security

2021 Has Broken the Record For Zero-Day Hacking Attacks (technologyreview.com) 17

According to multiple databases, researchers, and cybersecurity companies who spoke to MIT Technology Review, 2021 has had the highest number of zero-day exploits on record. "At least 66 zero-days have been found in use this year, according to databases such as the 0-day tracking project -- almost double the total for 2020, and more than in any other year on record," the report says. From the report: One contributing factor in the higher rate of reported zero-days is the rapid global proliferation of hacking tools. Powerful groups are all pouring heaps of cash into zero-days to use for themselves -- and they're reaping the rewards. At the top of the food chain are the government-sponsored hackers. China alone is suspected to be responsible for nine zero-days this year, says Jared Semrau, a director of vulnerability and exploitation at the American cybersecurity firm FireEye Mandiant. The US and its allies clearly possess some of the most sophisticated hacking capabilities, and there is rising talk of using those tools more aggressively.

Attackers are exploiting the same types of software vulnerabilities over and over again, because companies often miss the forest for the trees. And cybercriminals, too, have used zero-day attacks to make money in recent years, finding flaws in software that allow them to run valuable ransomware schemes. "Financially motivated actors are more sophisticated than ever," Semrau says. "One-third of the zero-days we've tracked recently can be traced directly back to financially motivated actors. So they're playing a significant role in this increase which I don't think many people are giving credit for."

While there may be an increasing number of people developing or buying zero-days, the record number reported isn't necessarily a bad thing. In fact, some experts say it might be mostly good news. No one we spoke to believes that the total number of zero-day attacks more than doubled in such a short period of time -- just the number that have been caught. That suggests defenders are becoming better at catching hackers in the act. You can look at the data, such as Google's zero-day spreadsheet, which tracks nearly a decade of significant hacks that were caught in the wild. One change the trend may reflect is that there's more money available for defense, not least from larger bug bounties and rewards put forward by tech companies for the discovery of new zero-day vulnerabilities. But there are also better tools. Defenders have clearly gone from being able to catch only relatively simple attacks to detecting more complex hacks, says Mark Dowd, founder of Azimuth Security. "I think this denotes an escalation in the ability to detect more sophisticated attacks," he says.
Further reading: Emergency Software Patches Are on the Rise
Education

Today's Students Don't Understand the Basics of Computer Operations (theverge.com) 493

DesScorp writes:

A new article in The Verge reports that professors are increasingly seeing the rise of a generation that can't understand even the basic fundamentals of how computers and operating systems work. The very concept of things like directories, folders, and even what a file is seem to baffle a generation that was raised on Google and smartphones, and have no concept of what storage is or how it works. To this generation, all your "stuff" just goes someplace where stuff is kept. Physics professor Catherine Garland was stunned to find that her students couldn't grasp the concept of organized file storage:

"She asked each student where they'd saved their project. Could they be on the desktop? Perhaps in the shared drive? But over and over, she was met with confusion. "What are you talking about?" multiple students inquired. Not only did they not know where their files were saved -- they didn't understand the question.

Gradually, Garland came to the same realization that many of her fellow educators have reached in the past four years: the concept of file folders and directories, essential to previous generations' understanding of computers, is gibberish to many modern students.

The new generation of students sees storage as a "giant laundry basket", where everything is just thrown in, and you go get what you need when you need it. One professor now incorporates an additional two hour lecture and demo in their subject just to teach new students how things like directories work in computer systems. Teachers worry that students will be ill-prepared for professional environments, especially STEM fields, that require rigid organization to keep volumes of data organized. But some professors seem to think that they'll eventually have to surrender to how the young do things.


Youtube

YouTube Tests Video Downloads for Your Desktop Browser (theverge.com) 37

YouTube is testing an official way to download videos on your desktop web browser. From a report: If you want to see if you're eligible for the test, which runs through October 19th, check out YouTube's experimental features page, which lists tests available for Premium subscribers. If you're opted-in and on a supported browser ("the latest versions of Chrome, Edge, or Opera," according to Google), when you're watching a video, you should see an option to download the video under the player. When you click it, YouTube will download the video, which you can then watch from the Downloads section that's accessible from the hamburger menu on the left side of the screen.
IT

Catalogue of Errors Led To $1.36 Billion of State Pension Underpayments (bbc.com) 36

Repeated human errors made for years were to blame for a scandal which led to more than 1bn pound of state pensions not being paid, a report has concluded. BBC: The National Audit Office (NAO) said 134,000 pensioners, mostly women, were underpaid pensions because outdated computer systems led to mistakes. Among them was 74-year-old Irene Wise, who said women like her were "short-changed" for years. The government said everyone would receive what they were owed. However, the report raises huge questions for the Department for Work and Pensions (DWP) over the way the state pension system functions and the mistakes that led to such a massive shortfall in payments. Reacting to the report, Meg Hillier, who chairs the Public Accounts Committee, said: "This is not the first widespread error we have seen in the DWP in recent years. Correcting these errors comes at great cost to the taxpayer. "The DWP must provide urgent redress to those affected and take real action to prevent similar errors in future."

The problem relates to the "old" state pension system where married women who had a poor pension in their own right could claim a 60% basic state pension based on their husband's record of contributions. A review is taking place to trace those affected by systemic failures to award these pension rises, stretching back to 1985. But only some women are being fully paid. Others will only be able to claim for 12 months of missed payments. The DWP is expecting to pay the affected pensioners it can trace a total of 1.05bn pound, at an average of 8,900 pound per pensioner affected. That exercise will cost the taxpayer 25m pound in staff costs and will not be completed until the end of 2023. An estimated 40,000 affected women have already died.

Slashdot Top Deals